Information Security Program
This Information Security Policy establishes the administrative and technical practices used by 360 BAM LLC, doing business as 360 Brand Advancement & Management, to protect confidential business, client, financial, and system information.
Effective: September 20, 2026
Security Governance
The Managing Member serves as the organization’s information-security contact and is responsible for security oversight, access authorization, incident review, and maintenance of security procedures.
Access Control
Administrative and financial systems are restricted to authorized users. Access is granted based on legitimate operational responsibilities and should be removed or modified when no longer required.
Administrative banking, accounting, and financial-integration functions require authenticated system access.
Authentication and Credentials
Passwords, API keys, secrets, access tokens, and other sensitive credentials must not be intentionally published or embedded in publicly accessible website content.
Financial-institution authentication is performed through authorized providers such as Plaid and participating financial institutions. CEO Command Center does not intentionally store online-banking usernames or passwords.
Encryption and Financial Data
Public-facing 360 BAM web systems use HTTPS. Sensitive integration credentials are maintained server-side.
Plaid access tokens used by CEO Command Center are maintained using encrypted protected storage, and access to connected financial information is restricted to authorized business purposes.
Data Minimization
360 BAM seeks to collect and retain only information reasonably necessary to provide services, operate business systems, maintain records, and satisfy legitimate accounting, tax, contractual, legal, security, audit, and compliance requirements.
Secure Development and Change Control
Material production changes should be reviewed and backed up when practical before implementation. New financial and business-system integrations are tested before production use.
Security-sensitive configuration values are maintained outside publicly accessible page content whenever reasonably possible.
System Integrity and Malware Response
360 BAM monitors its managed systems for unauthorized files, malicious modifications, unauthorized administrative access, suspicious sessions, and other indicators of compromise.
When suspicious activity is identified, response actions may include preserving evidence, restricting access, terminating sessions, quarantining suspicious files, restoring verified software, reviewing administrative users, rotating credentials, and validating system integrity.
Incident Response
Suspected unauthorized access, data exposure, malicious content, or system compromise is investigated promptly. Appropriate remediation and notification steps are taken based on the nature and scope of the incident and applicable obligations.
Third-Party Providers
Third-party providers that process confidential information are selected based on operational need and are expected to maintain reasonable security practices. Financial-account connectivity may be provided through Plaid rather than direct collection of financial-institution credentials.
Retention and Disposal
Sensitive information is retained only for legitimate business, accounting, tax, contractual, legal, audit, security, and compliance purposes. Information no longer required should be securely deleted or rendered inaccessible when practical and legally permitted.
Review
This policy is reviewed periodically and when material changes are made to systems that handle sensitive client, financial, or business information.
Information Security Contact
Antonio Barnes
Managing Member / Information Security Contact
360 BAM LLC
Email: Tone@360bam.com
