Finducation™

EZBudget™

Endpoint Security Policy

Workstation and production endpoint protections for a sole-operator, serverless application environment.

Document ID: EZB-END-001
Version: 1.1
Effective Date: July 22, 2026
Last Review Date: July 22, 2026
Owner: Deseo Developers LLC — Sole Operator
Applies To: The sole operator's workstation(s) and production hosting endpoints

1. Policy Statement

Deseo Developers LLC is operated by a sole proprietor / solopreneur with no employees or contractors. Endpoint security therefore applies to the operator's development workstation(s) and to production systems hosted on managed serverless platforms (Netlify and Supabase). There are no self-managed production server fleets and no multi-user device fleet to administer.

2. Production Endpoints

  • Production application hosting is provided by Netlify (static assets and serverless functions).
  • Authentication and database services are provided by Supabase.
  • Malware and host protection for underlying platform hosts is managed by those providers as part of their infrastructure security programs.
  • Application-layer protections include authentication gates, security headers, rate limiting / abuse controls on public forms, and least-privilege secrets management.

3. Operator Workstation Requirements

The sole operator's workstation used for development and production access must maintain:

  • OS automatic security updates enabled (Windows Update, macOS Software Update, or equivalent).
  • Built-in malware / antivirus protection enabled and kept current — for Windows, Microsoft Defender (real-time protection on); for macOS, XProtect/Gatekeeper and any enabled system security features.
  • Full-disk encryption enabled where supported (BitLocker, FileVault, or equivalent).
  • Screen lock with password/PIN after short idle timeout.
  • Untrusted software installation avoided; browser and development tools kept reasonably current.

4. Access to Production Consoles

  • Netlify, Supabase, GitHub, Stripe, and Plaid dashboard access requires MFA per the Critical Systems MFA Policy (EZB-MFA-002).
  • Production secrets are not stored in plaintext on local disks outside approved secret managers / environment stores.
  • If the operator's device is lost or compromised, access credentials are rotated immediately (see Incident Response Policy, EZB-IR-001).

5. Malicious Code Controls

  • OS malware protection remains enabled while performing production work.
  • Suspicious attachments, macros, and untrusted installers are not opened on workstations used for production access.
  • Repository and Terms of Service prohibit upload/distribution of malware through the application.

6. Tooling Reality (Sole Operator)

Deseo Developers LLC does not operate a commercial multi-endpoint EDR fleet (e.g., CrowdStrike). Endpoint protection for the sole operator is provided by OS-native security tooling (Microsoft Defender or equivalent). That tool is the EDR/antivirus control in scope for partner questionnaires that request an endpoint security screenshot.

7. Periodic Review

  • This policy is reviewed at least annually by the sole operator.
  • Workstation protections are confirmed as part of the annual security self-review.

8. Related Documents

  • Critical Systems Multi-Factor Authentication Policy (EZB-MFA-002)
  • Access Control Policy (EZB-ACM-001)
  • Vulnerability Management Policy (EZB-VUL-001)
  • Incident Response Policy (EZB-IR-001)

9. Approval

Approved By: Deseo Developers LLC — Sole Operator / Authorized Representative

Date: July 22, 2026

Contact: contact@deseodevelopers.com