1. Purpose and scope
This policy states how BreathEasy Administrative Services LLC applies zero trust principles to BreathEasy | Ledger, the accounting application published at ledger.breatheasy.net. It is a companion to the Information Security Policy and Procedures, the Access Controls Policy, and the Data Retention and Disposal Policy, and it carries the same authority.
Zero trust means no request is trusted because of where it came from. Being inside a network, holding a session, or having signed in earlier in the day grants nothing on its own. Every request carries an identity, that identity is verified again at the point of use, and the request is allowed only for the specific records that identity owns.
The scope covers the Ledger application and its database, the marketing site, company email and domain accounts, the hosting and database platform, any financial account data received from an aggregator such as Plaid, and the laptops and mobile devices used by anyone with access to production.
This policy describes controls we actually operate. Where a control commonly found in a large enterprise does not apply to a fully managed hosting model, the policy says so plainly rather than claiming coverage we cannot evidence.