CANCEL CULTR

Cancel Cultr — Access Control Policy

Owner: Kyle Good (sole operator)
Last reviewed: September 27, 2026
Review cadence: Quarterly, and on any material change to systems or data handling.

1. Purpose & Scope

This policy governs how access to Cancel Cultr's production systems and sensitive data is granted, controlled, authenticated, and removed. It applies to all production assets (all cloud/serverless — there are no physical or on-premise assets): the API (Cloudflare Workers), the database (Supabase / PostgreSQL), third-party processor consoles (Plaid, Twilio, Anthropic), and source control.

2. Guiding Principles

3. Access to Production Systems

4. Access to Sensitive Data (Role-Based, Deny-by-Default)

5. Authentication

6. Secrets Management

7. Provisioning & De-Provisioning

Cancel Cultr is currently operated by a single individual, so standing access is limited to one identity. Any future personnel will be granted least-privilege, role-based access with MFA required, and their access will be removed promptly upon role change or departure.

8. Access Reviews

The operator will review account access, active credentials, and third-party integrations on a quarterly basis and upon any material change, revoking access that is no longer required.

9. Revocation & Deletion

Account deletion revokes all Plaid items (removing our access to bank data) and cascades a full deletion of the user's data. Data is retained only while an account is active.

10. Scope Statement

Cancel Cultr is a single-operator, early-stage business. This policy documents access controls that are genuinely implemented and procedures the operator commits to following. It does not claim controls not yet in place (for example, centralized SSO/IAM tooling, a formal zero-trust architecture, or automated employee de-provisioning), which are not applicable at current scale and will be adopted as the business grows.