Authentication Management Policy

Document Owner Lou Bonvarlet, General Counsel, ScorePlay Inc.
Version 2.0
Effective Date June 2026
Last Reviewed June 2026
Next Scheduled Review June 2027 (annual, or upon material change)
Classification Internal

1. Purpose

Authentication mechanisms, such as passwords and equivalent credentials, are the primary means of protecting access to ScorePlay Inc. systems and data. Authenticators must be strongly constructed and used in a manner that prevents their compromise. Authentication is a cornerstone of ScorePlay's security framework: it ensures that only authorised users access critical systems and data.

2. Scope

This Policy applies to all passwords and other authentication methods used to access the ScorePlay Media Asset Management (MAM) platform, internal remote servers and databases, and to authentication processes for integrations, APIs, and third-party applications connected to the system.

3. Policy

  1. Access to all customer data not intended for unrestricted public access requires authentication.
  2. Passwords and other authenticators must be constructed to have a resistance to attack commensurate with the level of system or data access granted to the account.
  3. Systems must be designed and configured to protect passwords during storage and transmission.
  4. No one may require another person to share the password to an account, including as a condition of employment or to provide technical support.
  5. Different user types define different levels of permission (e.g. admin, viewer, partner).
  6. Sensitive information, such as passwords, is salted and hashed before storage.
  7. Access to customer data is restricted internally on a need-to-know basis.
  8. The ScorePlay AWS architecture runs in a private network not accessible from the internet. Only specific endpoints (such as the ScorePlay API) are accessible from the internet, and these require authentication.
  9. ScorePlay uses multi-factor authentication (MFA) for all employees accessing ScorePlay systems. Customers are also encouraged to enable MFA for their accounts where available.

4. Responsibilities