name: security-policies description: Apollo.io security policies — password requirements, 2FA, data classification, phishing, and compliance obligations
Security Policies
Authentication Requirements
- Passwords: Minimum [FILL: 12 characters], must use a password manager ([FILL: 1Password/other])
- 2FA/MFA: Required on all Apollo accounts and any tool that supports it
- SSO: Use Okta SSO whenever available — do not create separate logins
- Shared credentials: Prohibited. Every person gets their own account.
Data Classification
| Level | Definition | Examples | Handling |
|---|---|---|---|
| Public | Approved for external sharing | Marketing copy, public docs | No restrictions |
| Internal | For Apollo employees only | This plugin, internal wikis | Don't share externally |
| Confidential | Sensitive business data | Customer data, financial records | Need-to-know access only |
| Restricted | Highest sensitivity | PII, credentials, legal matters | Strict access controls + logging |
Acceptable Use
- Company devices are for work use — limited personal use is acceptable
- Do not install unapproved software on company devices: [FILL: process to request software]
- No storage of company data on personal devices or unapproved cloud storage
- VPN required when accessing [FILL: production systems, internal tools]
Phishing
- If you receive a suspicious email: Do not click links — report via [FILL: PhishAlarm button / forward to security@apollo.io]
- If you clicked a phishing link: Immediately notify #security-incident — no judgment, act fast
- Phishing simulations: Apollo runs periodic tests — treat them as real
Compliance
- SOC 2 Type II: Apollo is certified — [FILL: scope, renewal date]
- GDPR / CCPA: Customer data handling requirements — see [FILL: data handling policy link]
- Annual security training: Required for all employees, due [FILL: date]
- Acceptable use policy: [FILL: link to full policy]
Reporting a Security Concern
- Active incident (breach, ransomware, account compromise): #security-incident immediately
- Vulnerability found: Report via [FILL: security@ or bug bounty program]
- Policy question: #security
Contacts
- #security — policy questions, security reviews
- #security-incident — active security events (use 24/7)
- Security lead: [FILL: name]