peopleVersion 1SOC2ISO27001
Acceptable Use Policy
What personnel may and may not do with Rex Black systems, data, and identity.
Acceptable Use Policy
1. Purpose
Defines what personnel may and may not do with Rex Black systems and data. Sets the behavioral baseline every employee and contractor acknowledges at onboarding.
2. Scope
All personnel, all Rex Black systems, all personal devices used for
Rex Black work (see 014-remote-work-policy.md and
025-endpoint-security-policy.md).
3. Acceptable use
Personnel MAY:
- Use Rex Black systems and data to perform their assigned duties.
- Use Rex Black email and communication tools for incidental personal use that does not interfere with work, consume material resources, or embarrass the company.
- Install job-required software from reputable vendors on Rex Black-issued or BYOD devices that meet endpoint standards.
- Use generative-AI tools consistent with the AI Acceptable Use
Policy (
026-ai-acceptable-use-policy.md).
4. Prohibited use
Personnel MAY NOT:
- Share authentication credentials with anyone, inside or outside Rex Black, under any circumstance.
- Store client data, proprietary source code, or controlled unclassified information on personal cloud storage (personal Dropbox, Google Drive, iCloud) or unapproved SaaS.
- Disable, bypass, or attempt to circumvent any security control , including MFA, screen locks, disk encryption, endpoint agents, and VPN requirements.
- Connect Rex Black systems to unapproved networks for the purpose of transferring Rex Black or client data (public Wi-Fi is fine with VPN; untrusted tethered devices are not).
- Transmit, store, or process client data in generative-AI tools that
are not listed in the subprocessor register
(
registers/subprocessors.md). - Engage in any activity that violates U.S. law, export controls (ITAR/EAR), or the contractual terms of a client engagement.
- Represent themselves as speaking on behalf of Rex Black in public forums (press, social media) without authorization from the CEO.
- Use Rex Black resources to send unsolicited bulk mail, mine cryptocurrency, run a side business, or host unrelated services.
5. Privacy expectations
Rex Black retains the right to monitor systems it owns or contracts for legitimate security and operational purposes, consistent with applicable law. Personnel should have no expectation of privacy on Rex Black-owned accounts.
Personnel retain ordinary expectations of privacy on personal accounts and personal devices, except to the extent those accounts or devices process Rex Black or client data, in which case the data itself is subject to inspection.
6. Acknowledgement
Every employee and contractor acknowledges this policy at onboarding
and annually thereafter. Acknowledgements are logged in the audit log
with actor email, policy version, and timestamp, and are archived
under compliance/acknowledgements/ per the Retention Policy
(010-data-retention-and-disposal-policy.md).
7. Enforcement & exceptions
Violations are handled per the HR Security Policy. Material or intentional violations may result in termination and civil or criminal referral. Exceptions require the CEO's written approval.
8. References
002-access-control-policy.md014-remote-work-policy.md026-ai-acceptable-use-policy.mdregisters/subprocessors.md
9. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.