BUILD • ADVANCE • MANAGE • SCALEA Tone INT Company ↗
360 BAM

BUILD • ADVANCE • MANAGE • SCALE

Information Security Policy

How 360 BAM manages access, financial data security, system integrity and incident response.

Information Security Program

This Information Security Policy establishes the administrative and technical practices used by 360 BAM LLC, doing business as 360 Brand Advancement & Management, to protect confidential business, client, financial, and system information.

Effective: September 20, 2026

Security Governance

The Managing Member serves as the organization’s information-security contact and is responsible for security oversight, access authorization, incident review, and maintenance of security procedures.

Access Control

Administrative and financial systems are restricted to authorized users. Access is granted based on legitimate operational responsibilities and should be removed or modified when no longer required.

Administrative banking, accounting, and financial-integration functions require authenticated system access.

Authentication and Credentials

Passwords, API keys, secrets, access tokens, and other sensitive credentials must not be intentionally published or embedded in publicly accessible website content.

Financial-institution authentication is performed through authorized providers such as Plaid and participating financial institutions. CEO Command Center does not intentionally store online-banking usernames or passwords.

Encryption and Financial Data

Public-facing 360 BAM web systems use HTTPS. Sensitive integration credentials are maintained server-side.

Plaid access tokens used by CEO Command Center are maintained using encrypted protected storage, and access to connected financial information is restricted to authorized business purposes.

Data Minimization

360 BAM seeks to collect and retain only information reasonably necessary to provide services, operate business systems, maintain records, and satisfy legitimate accounting, tax, contractual, legal, security, audit, and compliance requirements.

Secure Development and Change Control

Material production changes should be reviewed and backed up when practical before implementation. New financial and business-system integrations are tested before production use.

Security-sensitive configuration values are maintained outside publicly accessible page content whenever reasonably possible.

System Integrity and Malware Response

360 BAM monitors its managed systems for unauthorized files, malicious modifications, unauthorized administrative access, suspicious sessions, and other indicators of compromise.

When suspicious activity is identified, response actions may include preserving evidence, restricting access, terminating sessions, quarantining suspicious files, restoring verified software, reviewing administrative users, rotating credentials, and validating system integrity.

Incident Response

Suspected unauthorized access, data exposure, malicious content, or system compromise is investigated promptly. Appropriate remediation and notification steps are taken based on the nature and scope of the incident and applicable obligations.

Third-Party Providers

Third-party providers that process confidential information are selected based on operational need and are expected to maintain reasonable security practices. Financial-account connectivity may be provided through Plaid rather than direct collection of financial-institution credentials.

Retention and Disposal

Sensitive information is retained only for legitimate business, accounting, tax, contractual, legal, audit, security, and compliance purposes. Information no longer required should be securely deleted or rendered inaccessible when practical and legally permitted.

Review

This policy is reviewed periodically and when material changes are made to systems that handle sensitive client, financial, or business information.

Information Security Contact

Antonio Barnes
Managing Member / Information Security Contact
360 BAM LLC
Email: Tone@360bam.com