Work-A-Beez Security Policy

Version: 1.0 · Effective Date: July 23, 2026 · Last Updated: July 23, 2026

1. Purpose

This Security Policy describes the administrative, technical, and physical safeguards implemented by Linton Business Solutions, LLC ("LBS") to protect the confidentiality, integrity, and availability of the Work-A-Beez Software-as-a-Service ("Service").

This document is intended to:

This Security Policy should be read together with the:

2. Scope

This Security Policy applies to all systems, personnel, contractors, technologies, and third-party services used to deliver the Work-A-Beez platform, including:

The policy applies to all employees, contractors, consultants, and authorized third parties with access to Work-A-Beez systems.

3. Security Principles

Work-A-Beez's security program is built upon the following principles:

Confidentiality. Customer information is accessible only to authorized individuals with a legitimate business need.

Integrity. Customer data should remain complete, accurate, and protected against unauthorized modification.

Availability. Systems should remain available to authorized users through resilient infrastructure, monitoring, backups, and recovery planning.

Least Privilege. Users receive only the minimum permissions necessary to perform their responsibilities.

Defense in Depth. Multiple layers of administrative, technical, and operational safeguards are used to reduce risk.

Continuous Improvement. Security controls are reviewed and enhanced as technology, threats, and regulatory expectations evolve.

4. Shared Responsibility Model

Security is a shared responsibility between LBS and each Customer.

LBS Responsibilities. LBS is responsible for:

Customer Responsibilities. Customers are responsible for:

5. Security Governance

LBS maintains a security governance program intended to support risk management and operational resilience. Security governance activities include:

Security responsibilities may be assigned to designated personnel, service providers, or qualified contractors depending on organizational needs.

6. Information Classification

Work-A-Beez classifies information according to its sensitivity to ensure appropriate protection.

Public. Information approved for public release, including marketing materials, public documentation, and published product information.

Internal. Operational information intended for internal business use that is not publicly available.

Confidential. Information requiring protection due to business sensitivity, including customer contracts, pricing, internal procedures, and non-public technical documentation.

Restricted. The highest classification, applied to information that could result in significant harm if disclosed, including:

Restricted information receives the highest level of protection.

7. Risk Management

LBS maintains a risk-based approach to information security. Security risks are evaluated based on factors such as:

Risk treatment strategies may include mitigation through technical controls, administrative safeguards, operational procedures, risk transfer through insurance or contractual arrangements, or acceptance of low-impact risks where appropriate.

Security priorities are reviewed periodically as business operations and technology evolve.

8. Security Responsibilities

All personnel with access to Work-A-Beez systems are expected to:

Managers and administrators are responsible for ensuring that appropriate access rights are granted, reviewed, and revoked in a timely manner.

9. Policy Compliance

Failure to comply with this Security Policy may result in removal of system access, corrective action, contract termination, legal action where appropriate, or referral to law enforcement when required.

LBS reserves the right to update security controls and operational procedures to address evolving threats and changing regulatory requirements.

10. Policy Review

This Security Policy will be reviewed periodically and may be updated to reflect changes in technology, new platform features, emerging cybersecurity threats, customer requirements, industry best practices, or applicable legal or regulatory changes.

The most current version of this Security Policy will supersede all previous versions.

11. Identity and Access Management (IAM)

Linton Business Solutions, LLC ("LBS") maintains an Identity and Access Management (IAM) program designed to ensure that only authorized individuals have access to Work-A-Beez systems and Customer Data. Identity management objectives include:

All users are assigned unique user accounts. Shared administrator accounts are discouraged except where operationally necessary and subject to appropriate controls.

12. Authentication

Work-A-Beez requires users to authenticate before accessing protected resources. Authentication controls may include:

Authentication mechanisms are periodically reviewed and updated to align with evolving security standards.

13. Password Policy

Work-A-Beez encourages Customers to adopt strong password practices. Recommended password requirements include:

Passwords are never stored in plain text. Password hashes are generated using industry-standard cryptographic algorithms. LBS personnel cannot retrieve Customer passwords.

14. Multi-Factor Authentication (MFA)

Where supported by the platform, administrator accounts should enable Multi-Factor Authentication (MFA). MFA significantly reduces the likelihood of unauthorized access resulting from compromised credentials.

Supported authentication methods may include authenticator applications, time-based one-time passwords (TOTP), hardware security keys, or other approved authentication mechanisms.

LBS reserves the right to require MFA for certain administrative or high-risk accounts.

15. Authorization

Authorization decisions are based upon user role, assigned permissions, Customer configuration, organizational hierarchy, and business requirements.

Role-Based Access Control (RBAC) is used to limit access to information necessary for each user's responsibilities. Examples of roles include:

Customers are responsible for assigning appropriate roles to their users.

16. Session Security

Work-A-Beez implements session management controls designed to reduce unauthorized access risks. These controls may include:

Users should log out after completing their work, especially when using shared devices.

17. Encryption

Data in Transit. Communications between users and the platform are protected using Transport Layer Security (TLS). Encrypted communications help protect against interception while data is transmitted over public networks.

Data at Rest. Where commercially appropriate, sensitive information stored within Work-A-Beez is encrypted using modern cryptographic standards. Encryption may apply to:

18. Cryptographic Key Management

Encryption keys and authentication secrets are managed using secure administrative procedures. Key management practices may include restricted administrative access, secure storage, periodic rotation where appropriate, separation of duties, and protection against unauthorized disclosure.

Cryptographic materials are treated as Restricted Information.

19. Network Security

LBS maintains network security controls intended to protect Work-A-Beez infrastructure. Security measures may include:

Network architecture is periodically reviewed as the platform evolves.

20. Infrastructure Security

Production infrastructure is hosted using commercially recognized cloud infrastructure providers. Infrastructure security practices may include:

LBS continually evaluates infrastructure security improvements as technology advances.

21. Secure Software Development Lifecycle (SSDLC)

Security is integrated throughout the software development lifecycle. Development practices may include:

Developers are encouraged to follow established secure development principles throughout the product lifecycle.

22. Vulnerability Management

LBS maintains procedures for identifying and addressing software vulnerabilities. Activities may include dependency scanning, security advisories, vendor notifications, security updates, vulnerability prioritization, and timely remediation based on risk.

Critical vulnerabilities are prioritized according to business impact and exploitability.

23. Patch Management

Operating systems, frameworks, third-party libraries, and platform components are periodically updated to address known security issues. Patch priorities consider the severity of the vulnerability, availability of exploits, operational impact, and vendor recommendations.

Emergency patches may be deployed outside normal maintenance schedules when necessary to protect the Service.

24. Logging and Audit Trails

Work-A-Beez maintains system logging intended to support security monitoring, operational troubleshooting, incident investigations, compliance activities, and system diagnostics. Logs may include:

Access to logs is restricted to authorized personnel.

25. Security Monitoring

LBS performs ongoing monitoring designed to identify potential security events affecting the platform. Monitoring activities may include infrastructure health monitoring, application monitoring, error monitoring, authentication monitoring, availability monitoring, resource utilization monitoring, and security alert review.

Monitoring helps identify unusual activity and supports timely incident response.

26. Change Management

Changes affecting production systems follow controlled deployment procedures intended to reduce operational risk. Change management practices may include documentation of significant changes, testing prior to deployment, rollback planning, version tracking, production approvals where appropriate, and post-deployment verification.

Emergency changes may be implemented when necessary to address security vulnerabilities or service disruptions.

27. Security by Design

Work-A-Beez is developed using a security-by-design philosophy that seeks to incorporate security considerations throughout product planning, design, development, deployment, and ongoing maintenance. Examples include least-privilege access, defense-in-depth architecture, multi-tenant isolation, secure authentication, secure defaults, data minimization, audit logging, encryption, and continuous improvement.

Security is treated as an ongoing operational process rather than a one-time implementation.

28. Security Incident Response

Linton Business Solutions, LLC ("LBS") maintains an Incident Response Program designed to identify, contain, investigate, remediate, and recover from cybersecurity incidents affecting the Work-A-Beez platform. The primary objectives of the program are to protect Customer Data, minimize service disruption, preserve evidence where appropriate, restore normal operations efficiently, and meet applicable legal and contractual obligations.

The Incident Response lifecycle generally includes:

Preparation. Security policies and procedures, employee awareness, monitoring systems, response tools, and communication plans.

Identification. Potential incidents may be identified through automated monitoring, security alerts, customer reports, vendor notifications, employee observations, or third-party security researchers.

Containment. Where appropriate, LBS may isolate affected systems, restrict user access, disable compromised credentials, block malicious traffic, or suspend affected services.

Eradication. LBS will work to eliminate the root cause of confirmed security incidents, which may include removing malicious software, applying security patches, updating configurations, rotating credentials, or strengthening security controls.

Recovery. Recovery activities may include restoring systems from backups, validating system integrity, monitoring for recurring activity, and returning systems to production.

Post-Incident Review. Following significant incidents, LBS may conduct a post-incident review to document lessons learned, improve security controls, update procedures, and reduce future risk.

29. Customer Notification

If LBS confirms a Security Incident affecting Customer Personal Data under its control, LBS will notify affected Customers without undue delay, consistent with applicable law and contractual obligations. Notification may include the nature of the incident, categories of affected information, steps taken to contain the incident, recommended Customer actions, and contact information for follow-up.

Notification does not constitute an admission of fault or liability.

30. Business Continuity

LBS maintains business continuity practices designed to support continued operations during significant disruptions. Planning considers events such as cloud service interruptions, power outages, internet disruptions, severe weather, cybersecurity incidents, personnel disruptions, and other operational emergencies.

Business continuity strategies are reviewed periodically and updated as operational requirements evolve.

31. Disaster Recovery

Work-A-Beez maintains disaster recovery capabilities intended to restore critical services following major operational failures. Disaster recovery planning may include backup restoration procedures, infrastructure rebuilding, cloud resource provisioning, configuration recovery, system validation, and communication procedures.

Recovery priorities are based on business impact and operational requirements.

32. Backup and Restoration

Customer information is backed up using commercially reasonable procedures designed to support recovery from data loss or system failure. Backup practices may include automated backups, encrypted backup storage, geographic redundancy where supported by infrastructure providers, periodic verification of backup integrity, and controlled restoration procedures.

Backups are intended for disaster recovery and operational resilience and are not a substitute for Customer-maintained recordkeeping obligations.

33. Vendor Risk Management

LBS relies on selected third-party service providers to deliver components of the Work-A-Beez platform. Vendor evaluation may consider security capabilities, reliability, regulatory compliance, privacy practices, operational maturity, and business continuity capabilities.

LBS periodically reviews vendor relationships and may replace providers as business requirements evolve.

34. Physical Security

Where Work-A-Beez infrastructure is hosted by commercial cloud providers, physical security is primarily managed by those providers. Physical safeguards may include controlled facility access, visitor management, video surveillance, environmental monitoring, fire suppression systems, redundant power, climate control, and physical intrusion detection.

LBS maintains reasonable physical safeguards for any company-managed equipment used in platform administration.

35. Employee Security

Personnel with access to Customer information are expected to maintain confidentiality, protect authentication credentials, follow security procedures, report suspected incidents promptly, use approved systems responsibly, and access Customer information only when required for legitimate business purposes.

Access rights are reviewed periodically and removed when no longer required.

36. Security Awareness

LBS promotes a culture of security awareness among personnel. Security education may include password security, phishing awareness, social engineering prevention, data handling requirements, incident reporting, Acceptable Use requirements, and privacy obligations.

Training content may evolve to address emerging cybersecurity threats.

37. Penetration Testing and Security Assessments

LBS may conduct security assessments appropriate to the size and maturity of the platform, including vulnerability assessments, application security reviews, infrastructure reviews, dependency analysis, configuration reviews, and penetration testing by qualified personnel or third-party specialists.

Assessment frequency and scope are determined based on operational needs, platform changes, and identified risks.

38. Compliance

Work-A-Beez's security program is designed to support commercially reasonable compliance with applicable contractual and legal obligations. LBS continually evaluates security practices against recognized industry standards and may enhance its security program over time.

Publication of this Security Policy does not constitute certification under any specific compliance framework unless expressly stated by LBS.

39. Customer Security Responsibilities

Customers play an essential role in protecting their own environments. Customers should:

Security remains a shared responsibility between LBS and each Customer.

40. Responsible Vulnerability Disclosure

LBS appreciates responsible reporting of legitimate security vulnerabilities. Individuals who believe they have discovered a security issue affecting Work-A-Beez are encouraged to report it privately to LBS. Reports should include sufficient information to allow reproduction and investigation of the issue.

LBS requests that researchers avoid disrupting production systems, avoid accessing Customer Data, and avoid public disclosure until the issue has been investigated and addressed where appropriate.

LBS will make commercially reasonable efforts to acknowledge and evaluate legitimate reports.

41. Security Contact

Security-related questions or reports may be directed to:

Linton Business Solutions, LLC
Work-A-Beez Security Office
616 FM 1960 Road West
Houston, Texas 77090
United States
Email: info@lbsconnect.net
General Support: info@lbsconnect.net
Privacy: info@lbsconnect.net
Website: www.workabeez.net

42. Policy Maintenance

This Security Policy may be updated periodically to reflect changes in technology, emerging cybersecurity threats, regulatory developments, operational improvements, customer feedback, or platform enhancements.

The current version will be published through Work-A-Beez's official customer documentation.

43. Questions

Customers with questions regarding this Security Policy or Work-A-Beez's information security program are encouraged to contact LBS using the contact information provided above.

44. Acknowledgment

By using the Work-A-Beez platform, Customers acknowledge that they have reviewed this Security Policy and understand the shared security responsibilities associated with using a cloud-based workforce management service.

Appendix A – Security Controls Summary

The following summarizes the core security controls implemented by Work-A-Beez:

Administrative Controls

Technical Controls

Operational Controls

Last updated: July 24, 2026