vStream Digital Media / ShineVR

Physical Security Policy

Last updated: 03/06/25

Definitions

TermDefinition
Companymeans vStream Digital Media
ShineVRmeans the ShineVR product developed and operated by vStream Digital Media
GDPRmeans the General Data Protection Regulation
Responsible Personmeans Andrés Pitt, CTO
Data CentreSpecialized building housing computer systems and associated components such as telecommunications and storage systems, including environmental controls and security devices
Physical Access ControlSecurity measures restricting physical entry to facilities, rooms, or equipment
Company PremisesvStream Digital Media office at 37 Leeson Close, Dublin 2, D02 H344, Ireland
Production DataLive customer data, including ShineVR trial data and healthcare information
Biometric AuthenticationAuthentication based on unique physical characteristics (fingerprints, facial recognition, iris scans)
Environmental ControlsSystems managing temperature, humidity, fire suppression, and power supply for IT infrastructure

1. Policy Statement

vStream Digital Media operates a cloud-first infrastructure model with no customer or production data hosted at Company premises. All customer data, ShineVR trial data, and production systems reside exclusively on Google Cloud Platform infrastructure in European data centres.

This Physical Security Policy establishes requirements for two distinct security environments:

  1. Data Centre Physical Security: Complete reliance on Google Cloud Platform's comprehensive physical security controls for data centres housing production systems and customer data
  2. Company Office Physical Security: Basic physical security measures for employee workspace at Company premises in Dublin, Ireland

The Company maintains no data centre facilities and does not manage physical security for production infrastructure. All data centre physical security is provided by Google Cloud Platform in their certified facilities in the Netherlands and Belgium.

2. Purpose

The purpose of this policy is to:

3. Scope

This policy applies to:

3.1 Data Centre Facilities (Google Cloud Platform)

3.2 Company Office Premises

3.3 Personnel

Important Context: The Company operates from a small office with controlled access. No customer data, production data, or ShineVR trial data is stored at Company premises. All production systems are cloud-hosted.

4. Data Centre Physical Security (Google Cloud Platform)

4.1 Cloud-First Model

Complete Reliance on Google Cloud Platform:

Company's Role:

4.2 Google Cloud Data Centre Physical Security Controls

The following physical security controls are documented by Google Cloud Platform as implemented at their data centres. This information is derived from Google Cloud's official security documentation and should be verified against current Google Cloud security whitepapers and compliance reports.

Perimeter Security: Data centres located in nondescript buildings; physical barriers and controlled entry points; 24/7 perimeter monitoring; vehicle access controls and inspection; separate delivery and visitor entrances.

Access Control: Multi-factor authentication for facility access; biometric authentication systems; security badges with photo identification; escort requirements for visitors; access granted on need-to-enter basis only; regular access review and revocation for terminated personnel.

Surveillance and Monitoring: 24/7 video surveillance of data centre areas; security operations centre monitoring; intrusion detection systems; alarm systems for unauthorized access attempts; video footage retained for security investigations.

Physical Security Personnel: Trained security guards on-site 24/7; security guard screening and background checks; regular security patrols; incident response procedures; coordination with local law enforcement.

Environmental Controls: Redundant power supplies with backup generators; Uninterruptible Power Supply (UPS) systems; climate control systems; fire detection and suppression systems; water leak detection; natural disaster protection measures.

Hardware Security and Decommissioning: Server racks locked and access-controlled; asset tracking and inventory management; secure hardware decommissioning procedures including multi-step data sanitization, cryptographic erasure, degaussing, and physical destruction of storage media; documented chain of custody; no customer access to physical servers.

4.3 Google Cloud Security Certifications

Google Cloud maintains comprehensive security certifications:

4.4 Company Responsibilities for Cloud Physical Security

What vStream Does: Select and contract with certified cloud provider; define data residency requirements (EU only); review Google Cloud security certifications annually; monitor Google Cloud security notifications; maintain documentation of Google Cloud security controls for audits; provide customers with evidence of data centre security.

What vStream Does Not Do: Manage or operate data centre physical security; conduct physical security audits of Google Cloud data centres; maintain physical access to data centre facilities; dispose of data centre hardware; implement physical environmental controls.

5. Company Office Physical Security

5.1 Office Context and Risk Profile

Office Environment: Small office with controlled building access; limited employee count; shared office building with building security; no customer data or production data stored on premises; no servers or production infrastructure at office. Office used primarily for employee workspace, meetings and collaboration, and development on laptops accessing cloud resources.

Security Risk Assessment: Low risk to customer data (no customer data at premises); medium risk to Company assets (laptops, equipment); low risk to business continuity (cloud-based systems enable remote work); physical security important for employee safety and asset protection.

5.2 Building Access Control

Building Security: Office located in multi-tenant building; building access controlled by landlord/building management; building security includes reception desk during business hours, access card system for after-hours entry, and CCTV in common areas.

Company Office Access: Office door locked when unattended; keys issued to permanent employees only; key return upon employee termination; visitors must be escorted by employee; visitor log maintained.

After-Hours Access: Building access card required for after-hours entry; employees notified of building access card procedures; lost or stolen access cards reported immediately; access cards deactivated upon employee termination.

5.3 Visitor Management

Visitor Procedures: All visitors must be pre-arranged with employee host; visitors check in with employee host; visitor log maintained including visitor name and company, purpose of visit, date and time in/out, and employee host name; visitors escorted at all times; no visitor access to employee workstations or Company systems; visitors use segregated guest wireless network if implemented; confidential information secured before visitor meetings.

5.4 Clear Desk and Clear Screen Policy

Clear Desk Requirements: Sensitive documents secured in locked drawers when not in use; confidential printouts not left unattended on printers; whiteboards with confidential information erased after meetings; secure disposal of confidential documents (shredding); no customer data printed.

Clear Screen Requirements: Computers automatically lock after 5 minutes of inactivity; employees lock screens when leaving desk; password-protected screensavers enabled; monitors positioned to prevent unauthorized viewing.

5.5 Equipment and Asset Security

Company-Owned Equipment: IT hardware asset register maintained including asset type and model, serial number, assignment to employee, location, acquisition date, and status.

Laptop and Device Security: Laptops locked to desks with cable locks; laptops secured in locked drawers or taken home; Company devices encrypted; lost or stolen devices reported immediately; remote wipe capability enabled.

Peripheral Security: External hard drives and USB drives encrypted; removable media not used for Company data; unused equipment stored in locked cabinets; equipment surplus securely stored until disposal.

5.6 Office Environmental Controls

Basic Environmental Protection: Fire extinguishers present and inspected; smoke detectors installed; emergency exit routes clearly marked; emergency evacuation procedures displayed; first aid kit available; no specialized environmental controls required.

6. Hardware Disposal And Decommissioning

6.1 Company-Owned Device Disposal

Disposal Process for Company Devices: Device returned to CTO or designated IT personnel; device wiped using secure data erasure methods; for Google Workspace devices, factory reset and Google account removal; data backed up to Google Drive before wiping if required.

Data Erasure: Full disk encryption keys destroyed; operating system reinstall or factory reset; multiple-pass data overwrite if encryption keys cannot be destroyed; verification of successful data erasure; documentation of data erasure in disposal log.

Physical Disposal: Wiped devices donated to charity, sold, or recycled; if device cannot be wiped, physical destruction of storage media; certificate of disposal obtained from disposal vendor if applicable; asset register updated with disposal date and method.

6.2 Data Centre Hardware Disposal (Google Cloud)

vStream does not physically dispose of data centre hardware. All production infrastructure hosted on Google Cloud Platform. Google Cloud manages hardware lifecycle including decommissioning: multi-step data sanitization, cryptographic erasure, degaussing, physical destruction of storage media, chain of custody documentation, and zero-touch decommissioning.

6.3 Removable Media Disposal

Company does not use removable media for production data. If removable media used: encrypt all data, wipe before disposal using secure erasure tools, physically destroy media containing sensitive information, and document disposal. All backups stored in Google Cloud Storage (no physical backup media).

7. Mobile Device Management

7.1 Company Device Security

Company does not currently issue mobile phones to employees. If Company-issued mobile devices used in future: device encryption mandatory; screen lock with PIN/biometric authentication required; remote wipe capability enabled; lost or stolen device reporting procedures; device tracking enabled.

7.2 Personal Device Security (BYOD)

Employees use personal devices for work (primarily mobile phones). BYOD Policy establishes security requirements for personal devices: device encryption enabled; screen lock with strong passcode/biometric; anti-malware software installed; operating system kept updated; separation of work and personal data.

8. Physical Security Incidents

8.1 Incident Types

Lost or stolen Company device; unauthorized physical access to office; theft of Company property; physical damage to equipment; security violation (propped door, lost keys, etc.); visitor policy violation; environmental incident (fire, flood, power outage).

8.2 Incident Reporting

All physical security incidents reported immediately to CTO; lost or stolen devices reported within 1 hour of discovery; after-hours incidents call CTO directly at (086) 788 6570; document incident details.

8.3 Incident Response

Lost or Stolen Device Response:

  1. Employee reports to CTO immediately
  2. CTO initiates remote wipe via Google Workspace (if Company device)
  3. Account passwords changed (if account credentials on device)
  4. Monitoring for unauthorized access to Company systems
  5. Police report filed (if appropriate)
  6. Insurance claim filed (if applicable)
  7. Incident documented in incident register
  8. Post-incident review to prevent recurrence

9. Business Continuity And Disaster Recovery

9.1 Physical Disaster Impact

Office Disaster Scenarios: Fire, flood, or other physical damage to office; extended power outage; building access denial; equipment theft or destruction.

Impact Assessment: Customer data impact: none (no customer data at office); production systems impact: none (cloud-hosted); business operations impact: minimal (remote work capable); employee safety: primary concern.

9.2 Business Continuity Measures

All employees equipped with laptops for remote work; all Company data stored in Google Drive; production systems accessed via cloud; communication via Google Workspace; no dependency on physical office for business operations. Recovery Time Objective (RTO): Immediate (remote work). Recovery Point Objective (RPO): Zero (all data in cloud).

10. Asset Management

10.1 IT Hardware Asset Register

Asset register contents include asset identification (asset type, make and model, serial number, asset tag), asset assignment (assigned employee, assignment date, location), and asset lifecycle (acquisition date and cost, warranty, disposal date and method, current status). Asset register updated within 5 working days of changes; annual comprehensive asset inventory audit.

10.2 Software Asset Management

Software licenses tracked separately from hardware assets; Google Workspace licenses assigned per user; development tools and software licenses documented; cloud service subscriptions tracked; regular review of software licenses for cost optimization.

11. Training And Awareness

11.1 Physical Security Training

All new employees receive physical security awareness during induction covering office access procedures, visitor management, clear desk/clear screen policies, device security, lost/stolen device reporting, and emergency procedures. Annual refresher training for all staff.

12. Compliance And Regulatory Requirements

12.1 GDPR Physical Security

GDPR Article 32 requires physical security measures appropriate to risk. No personal data stored at Company premises (all data in cloud); Google Cloud provides appropriate physical security; device encryption protects personal data on employee devices; secure disposal ensures personal data irrecoverable.

12.2 ISO 27001 Physical Security Controls

ISO 27001 Annex A.11 covers secure areas (office access control, visitor management) and equipment security (asset management, secure disposal). Compliance monitored via Google Cloud Security Command Centre for data centres; office security documented and auditable.

13. Roles And Responsibilities

RoleResponsibilities
CTO (Responsible Person)Overall physical security policy ownership; Google Cloud physical security verification; office security oversight; asset register management; physical security incident response; policy review and updates; approval of equipment disposal
All EmployeesComply with office access procedures; follow clear desk/clear screen policy; secure Company equipment; report lost/stolen devices; escort visitors; report physical security incidents; participate in emergency drills; follow asset management procedures
Building ManagementBuilding access control; CCTV in common areas; emergency systems; environmental controls (HVAC, fire suppression); building security patrols

14. Policy Review And Maintenance

Annual policy review by CTO. Review triggered by significant physical security incidents, changes to office location, changes to Google Cloud provider or data centre locations, new regulatory requirements, customer security requirement changes, or results of asset audits. All updates require CTO approval; changes communicated to all staff within 10 working days.

15. Exceptions

15.1 Exception Process

Exceptions requested in writing to CTO; business justification required; risk assessment documented; compensating controls identified; time-limited exceptions preferred; permanent exceptions require CEO approval.

16. Related Policies And Documents

This policy should be read in conjunction with:

17. Contact Information

Data Protection Officer / Chief Technology Officer: Andrés Pitt Email: andres@vstream.ie Phone: (086) 788 6570 Available 24/7 for P1 physical security incidents.

Company Address: vStream Digital Media, 37 Leeson Close, Dublin 2, D02 H344, Ireland. Website: vstream.ie