5
5CEOs on CircaOS

Operational policies

What we've documented.

These four policies are the documentation baseline for the SOC 2 Trust Service Criteria we're actively closing on. Each is a live document, versioned, reviewed on a stated cadence, and available under NDA to prospects doing a security review.

Full security posture at /security. Trust Center at /trust. Sub-processor list at /sub-processors.

Information Security Policy

1.0 · 2026-07-18

Top-level security posture · principles · controls summary. Parent to the other three.

Source: docs/policies/information-security-policy.md in the cogos-api repo. Available on request under NDA.

Access Control Policy

1.0 · 2026-07-18

Who gets access to what · MFA everywhere · onboarding + offboarding · quarterly access review cadence.

Source: docs/policies/access-control-policy.md in the cogos-api repo. Available on request under NDA.

Change Management Policy

1.0 · 2026-07-18

How changes reach production · deploy gates · rollback discipline · prohibited ad-hoc edits.

Source: docs/policies/change-management-policy.md in the cogos-api repo. Available on request under NDA.

Incident Response Policy

1.0 · 2026-07-18

Severity levels · detection sources · notification obligations · postmortem template.

Source: docs/policies/incident-response-policy.md in the cogos-api repo. Available on request under NDA.

Request a policy pack

Enterprise procurement or security-review teams: email support@5ceos.com with subject “Policy Pack Request · [Company]”. We’ll send the four policies + control-architecture mapping to your security framework (SIG Lite · CAIQ · custom form) within 3 business days.

Under NDA. Non-customer redistribution prohibited per the response letter.