Cybersecurity Policy

Effective Date: May 15, 2026 • Last Reviewed: May 15, 2026

This Cybersecurity Policy is published in compliance with New York Department of Financial Services Cybersecurity Regulation (23 NYCRR Part 500) and applicable provisions of the New York Insurance Law. It describes YellowBus's technical, administrative, and operational safeguards for protecting nonpublic information.

1. Scope and Applicability

This policy applies to YellowBus (operated by the company entity behind www.yllwbus.com), a lead generation marketplace for insurance products. YellowBus operates as a covered entity under NYDFS Reg. 500 to the extent it handles nonpublic information (NPI) of New York residents in connection with insurance products.

This policy governs all systems, personnel, and third-party service providers that access, process, or store nonpublic information on behalf of YellowBus.

2. Encryption Standards

2.1 Data in Transit

2.2 Data at Rest

Reg. ref: 23 NYCRR § 500.15 (Encryption of Nonpublic Information)

3. Access Controls

3.1 Principle of Least Privilege

3.2 Multi-Factor Authentication

3.3 Third-Party Access

Reg. ref: 23 NYCRR § 500.07 (Access Privileges)

4. Vulnerability Management

Reg. ref: 23 NYCRR § 500.05 (Penetration Testing and Vulnerability Assessments)

5. Incident Response Plan

5.1 Detection

Anomalous activity is detected through application error monitoring (Render log alerts), structured logging, and third-party service provider security alerts (Stripe Radar, Neon anomaly detection).

5.2 Classification

SeverityDescriptionResponse Time
CriticalActive breach of NPI, unauthorized database access, credential compromiseImmediate — within 1 hour
HighService unavailability affecting consumer data integrity, suspected data exfiltrationWithin 4 hours
MediumUnauthorized access attempts, suspicious authentication patternsWithin 24 hours
LowRoutine security events, failed login attempts below thresholdWithin 72 hours

5.3 Containment and Remediation

  1. Isolate affected systems by revoking credentials and blocking access at the infrastructure level.
  2. Preserve logs and evidence before any remediation steps.
  3. Identify root cause and scope of the incident.
  4. Apply patches or configuration changes to contain the vulnerability.
  5. Monitor for recurrence after remediation.
  6. Conduct post-incident review and update controls as warranted.

5.4 Breach Notification

In the event of a cybersecurity event involving NPI of New York residents, YellowBus will notify:

Reg. ref: 23 NYCRR § 500.17 (Notices to the Superintendent); N.Y. Gen. Bus. Law § 899-aa (SHIELD Act)

6. Data Retention and Disposal

7. Third-Party Service Provider Security

YellowBus relies on the following third-party providers that process NPI. Each maintains its own security certifications:

Reg. ref: 23 NYCRR § 500.11 (Third-Party Service Provider Security Policy)

8. Personnel Security

9. Governance and Review

This policy is reviewed annually or following any material cybersecurity event. The Chief Information Security Officer (or designated equivalent) is responsible for maintaining this policy. Policy updates are reflected in the revision date above.

10. Contact

To report a security vulnerability or incident, contact: security@yllwbus.com

For privacy-related inquiries: privacy@yllwbus.com