All Policies

Access Review & Audit Policy

Effective Date: April 23, 2026

1. Purpose

This policy establishes procedures for periodic access reviews and audits to ensure that access to VaultKeeper systems remains appropriate, authorized, and aligned with the principle of least privilege.

2. Review Schedule

SystemReview FrequencyReviewer
Firebase Console accessQuarterlyOwner/Admin
Cloudflare Dashboard accessQuarterlyOwner/Admin
Plaid Dashboard accessQuarterlyOwner/Admin
Teller Dashboard accessQuarterlyOwner/Admin
GitHub repository accessQuarterlyOwner/Admin
Cloudflare Workers secretsSemi-annuallyOwner/Admin
Firebase Security RulesSemi-annuallyOwner/Admin
API keys and tokensSemi-annuallyOwner/Admin

3. Review Procedures

Each access review includes the following steps:

4. Audit Scope

Access audits cover:

5. Audit Logging

The following logs are maintained and reviewed:

6. Findings and Remediation

Issues identified during access reviews are addressed as follows:

7. Compliance Records

Access review records are retained for a minimum of 2 years and include: review date, reviewer, systems reviewed, findings, and actions taken.

8. Policy Review

This policy is reviewed at least annually.