Security Policies: Prove They've Been Acknowledged
The IT security policy (ISP) is a fundamental document for any organization. It defines the rules and best practices that anyone with access to the information system must follow — employees, contractors, and partners alike.
But how do you prove that each recipient has actually acknowledged this policy? Simply sending it by email is not enough.
The risk
In the event of an incident, the organization must be able to demonstrate that the person concerned was aware of the rules in force. Traditional methods (email, sign-off sheets) do not provide reliable proof.
The challenge of distributing security policies
Security policies must be communicated to all staff and external stakeholders with access to the information system. In the event of an incident, the organization must be able to demonstrate that the person concerned was aware of the rules. Traditional methods do not provide reliable proof. Ackify solves this by generating a cryptographic attestation for each reading.
How Ackify secures your security policies
With Ackify, you create a document for your ISP, send the link by email to any recipient (internal or external), and get a cryptographic Ed25519 proof of each reading. The tracking dashboard lets you see who has read it and who needs a follow-up.
Send the ISP
Share the link by email to all concerned recipients.
Proof generated
Each reading generates a timestamped Ed25519 attestation.
Tracking & reminders
See who has read it and automatically follow up with those who haven't.