> For the complete documentation index, see [llms.txt](https://framework.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://framework.aic.io/company-operating-manual/security-compliance-and-data.md).

# Security, Compliance and Data

### Purpose

Security is part of delivery from the start.

The security operating model ensures that people, systems, data, suppliers, and customer environments are protected.

### Security Principles

* Apply least privilege.
* Classify information before sharing.
* Use approved tools and repositories.
* Keep access traceable.
* Record security decisions.
* Review supplier access.
* Manage vulnerabilities.
* Treat customer data with appropriate care.
* Escalate incidents quickly.

### Security Responsibilities

Security responsibilities should be defined for:

* delivery team
* technical lead
* security lead
* customer security contact
* supplier security contact
* system owner
* data owner
