Access Control Policy
Effective September 15, 2026 | Last Updated September 15, 2026 | Version 1.0
1. Purpose
This Access Control Policy ("Policy") describes the principles and controls Ollify LLC ("Ollify," "we," "us," or "our") applies to govern access to the Ollify platform, its underlying infrastructure, and Customer Data. This Policy is published for the benefit of customers and prospective customers evaluating Ollify's security practices and is incorporated by reference into Ollify's Information Security Policy, available at ollify.app/legal/information-security-policy.
UPDATES TO THIS POLICY
This Policy is reviewed at least annually. Material changes will be posted at ollify.app/legal/access-control-policy and communicated via email or in-app notification at least thirty (30) days before taking effect. A change is material if it weakens the protections or reduces the frequency or scope of the practices described in this Policy; clarifications, reorganization, or changes that strengthen these protections are not material.
2. Guiding Principles
Ollify governs access to its systems and your data according to the following principles:
Least Privilege: Personnel are granted only the minimum access necessary to perform their job function.
Need to Know: Access to Customer Data is limited to personnel with a legitimate business purpose, such as providing support you have requested.
Default Deny: Access is denied by default and must be explicitly requested, justified, and approved.
Accountability: All access is logged and attributable to a specific individual — shared or anonymous accounts are not used to access production systems or Customer Data.
3. Internal Access to Customer Data
3.1 Limited Personnel Access. Access to Customer Data by Ollify personnel is strictly limited to individuals who require it to operate, maintain, or support the Service. Common reasons Ollify personnel may access Customer Data include:
Responding to a customer support request
Investigating and resolving a technical issue or service incident
Performing security monitoring or incident response
Complying with a legal obligation
3.2 Authorization and Logging. All access to Customer Data by Ollify personnel is:
Authorized based on documented business need and role
Subject to multi-factor authentication (MFA) requirements
Logged, including the individual, the data accessed, and the reason for access
Reviewed periodically to confirm continued appropriateness
4. Authentication Requirements
4.1 Customer Account Authentication. Ollify supports the following authentication controls for customer accounts:
Password requirements enforcing minimum length and complexity
Passwords are stored using industry-standard hashing algorithms and are never stored in plaintext
Multi-factor authentication (MFA) for customer accounts is not available as of this Effective Date. Ollify may introduce MFA for customer accounts in a future release. Sign-in is protected today by rate limiting, account lockout on repeated failed attempts, and server-side session revocation
Failed login attempts are rate-limited to protect against brute-force attacks
Failed login attempts do not reveal whether an account exists, protecting against account enumeration
Sessions automatically time out after a period of inactivity
4.2 Ollify Internal Authentication. Ollify personnel accessing production systems or administrative tools are required to use multi-factor authentication without exception. Privileged or administrative access (such as cloud infrastructure administration) is subject to additional controls described in Ollify's Information Security Policy.
5. Customer Administrative Controls
Ollify provides account administrators with tools to manage access within their own organization:
Role-based access controls allow administrators to assign appropriate permission levels to users
Administrators can add, modify, and remove user accounts at any time
Administrators can review active user accounts and their assigned permission levels
Administrators are responsible for promptly removing access for users who no longer require it (e.g., departed employees)
CUSTOMER RESPONSIBILITY
You are responsible for managing access within your own Ollify account, including assigning appropriate roles to your users, using strong unique passwords, and promptly revoking access when a user no longer requires it. MFA will become part of this responsibility once it is available for customer accounts. Ollify cannot independently determine when your organization's personnel changes warrant an access change — this is your responsibility as the account administrator.
6. Provisioning and Deprovisioning
Ollify follows a documented process for granting and removing access to its own systems and infrastructure:
New access requires documented business justification and approval prior to provisioning
Access is provisioned according to the principle of least privilege
Access is reviewed on a periodic basis to confirm continued business need
Access is revoked promptly upon personnel separation or role change — production and administrative access is removed the same business day, or the next business day if the separation occurs after normal business hours
7. Privileged Access
Access to Ollify's production infrastructure, source code, and administrative systems is treated as privileged access and subject to enhanced controls:
Multi-factor authentication is mandatory without exception
Privileged access is granted only to personnel with a clear operational need
Activity performed under privileged access is logged and auditable
Privileged access is reviewed on a periodic basis
8. Monitoring and Audit
Ollify monitors access to its systems and Customer Data on an ongoing basis:
Access and authentication events are logged
Logs are protected against unauthorized modification. Application and system logs are retained for a minimum of ninety (90) days, and platform audit logs for seven hundred thirty (730) days
Anomalous access patterns trigger review under Ollify's incident response procedures
Access logs may be made available to customers in connection with a security review, subject to reasonable advance notice and applicable confidentiality terms
9. Related Policies
This Policy works together with the following Ollify policies, all available at ollify.app/legal:
Policy | Covers |
Information Security Policy | Infrastructure, encryption, incident response, and overall security program |
Acceptable Use Policy | Permitted and prohibited uses of the Ollify platform |
Privacy Policy | How Ollify collects, uses, and protects personal information |
Data Processing Agreement (DPA) | Data protection terms for processing Customer Data |
10. Contact
For questions about this Policy or to request information about Ollify's access control practices, contact:
Topic | Contact |
Security and access control questions | security@ollify.app |
Privacy and data questions | privacy@ollify.app |
General support | support@ollify.app |
Mailing address | Ollify LLC, 901 N State St. STE N, Jackson, MS 39202 |