The Information Sensitivity Policy is intended to help users understand and determine what information is classified as sensitive and can be disclosed to non-employees and/or information that should not be disclosed outside of Ripple Treasury. It additionally outlines standards for communicating sensitive information with clients. Any individual copying or downloading Ripple Treasury and/or customer information onto any type of removable media is in violation of the Information Sensitivity Policy and may be subject to disciplinary action, up to and including termination of employment.
The information covered in these guidelines includes, but is not limited to electronic information, information on paper, and information shared orally or visually (such as telephone and video conferencing).
All users should familiarize themselves with the information labeling and handling guidelines. It should be noted that the sensitivity level definitions were created as guidelines and to emphasize common sense steps that can be taken to protect Ripple Treasury Confidential information. Sensitive information (such as account numbers, personally identifiable information, etc.) should be shared via encrypted communication methods only. Data should not be stored in any location that has not been approved by the Security & Compliance team.
Questions about the proper classification of a specific piece of information should be addressed to your manager. Questions about these guidelines should be addressed to the Security & Compliance team.
All Ripple Treasury information is categorized into two main classifications:
Ripple Treasury Public
Ripple Treasury Confidential
Ripple Treasury Public Information
Ripple Treasury Public information is information that has been declared public knowledge by someone with the authority to do so and can freely be given to anyone without any possible damage to Ripple Treasury. There are no restrictions on Ripple Treasury Public Information. Information available on the Ripple Treasury website, for example, is considered Public Information.
Ripple Treasury Confidential Information
Ripple Treasury Confidential information contains all other information. It is a continuum; in that it is understood that some information is more sensitive than other information and should be protected in a more secure manner. Included is information that should be protected very closely, such as trade secrets, development programs, potential acquisition targets, and other information integral to the success of our company. Also included in Ripple Treasury Confidential is information that is less critical, such as telephone directories, general corporate information, personnel information, etc., which does not require as stringent a degree of protection. By default, all Ripple Treasury documents should be labeled as Confidential with the “Ripple Treasury Confidential Information” footer included.
A subset of Ripple Treasury Confidential information is "Ripple Treasury Third Party Confidential" information. This is confidential information belonging or pertaining to another corporation which has been entrusted to Ripple Treasury by that company under non-disclosure agreements and other contracts. Examples of this type of information include everything from joint development efforts to vendor lists, customer orders, and supplier information. Information in this category ranges from extremely sensitive to information about the fact that we've connected a supplier / vendor into Ripple Treasury’s network to support our operations.
Ripple Treasury personnel are encouraged to use common sense judgment in securing Ripple Treasury Confidential information to the proper extent. If an employee is uncertain of the sensitivity of a piece of information, they should assume a high level of sensitivity and contact their manager or a member of senior management if the manager is not available.
The Sensitivity Guidelines below provide details on how to protect information at varying sensitivity levels. Use these guidelines as a reference only, as Ripple Treasury Confidential information in each column may necessitate stringent measures of protection depending upon the circumstances and the nature of the Ripple Treasury Confidential information in question.
Information Type | Guidelines |
|---|---|
Internal | Marked as confidential where applicable and includes a copyright statement. Must not be disclosed to third parties unless they have signed a confidentiality agreement or NDA. Discretion should be used when providing Internal information outside of Ripple Treasury. |
External (client provided) | Maintained as confidential, and hard copies are kept on file at Ripple Treasury. Soft copies must be marked as confidential and placed on secure servers. Communication of sensitive client provided information (such as account number) must be shared in an encrypted format. |
External PII | Maintained as confidential and stored on secure servers. Subject to GDPR restrictions. Communication of PII must be shared in an encrypted format. |
Restricted Client | Live client databases which require special treatment. Client databases are protected by both physical and logical security. Client databases are backed up via encrypted software and restorable only on a server containing decryption software. |
Restricted Ripple Treasury Information | Restricted Ripple Treasury information which is stored on separate computers and is password-protected. |
Copyright 2025 Ripple Labs Inc.
