Policies generated from your business, not a template pack
First-run generates four core drafts from your sector and size. These pages are examples of other policy families the generator can produce. Publishing, PDF exports, and team sign-off unlock after you choose a plan.
Browsing all 15 policies. Search by name, code or plain-English purpose.
Information Security
Information Security Policy
The umbrella policy describing how your organisation protects the confidentiality, integrity, and availability of information. The anchor document for any ISO 27001, SOC 2, or Cyber Essentials engagement.
Access Control Policy
Defines how access to systems, data, and physical premises is granted, reviewed, and revoked. Covers joiner-mover-leaver, least privilege, MFA, and privileged access.
Acceptable Use Policy
Sets out what staff can and cannot do with company devices, networks, and information assets. Often the first policy a new joiner reads — and the one most likely to be cited in a disciplinary process.
Resilience & Response
Incident Response Policy
How your organisation identifies, contains, eradicates, recovers from, and learns from security incidents. Includes legal-notification timelines for UK GDPR, HIPAA, and other regimes.
Business Continuity & Disaster Recovery Policy
Defines how the organisation continues critical operations during disruption — from ransomware to cloud-region outage to extreme weather. Includes RTO/RPO commitments and tabletop cadence.
Data Protection & Privacy
Data Retention & Disposal Policy
How long different categories of data are kept, where they live, and how they are securely disposed of when no longer needed. The operational backbone of GDPR data-minimisation.
Privacy Notice
The customer- or employee-facing notice explaining what personal data you process, why, the lawful basis, retention, sharing, and how to exercise rights. The most commonly-audited GDPR artefact.
Data Protection Policy
The internal-facing policy that staff follow when handling personal data — distinct from the external Privacy Notice. Covers lawful basis, DPIAs, subject-access requests, breach handling, and international transfers.
Engineering & Operations
Cryptography Policy
Where, when, and how cryptography is used to protect data — including approved algorithms, key management, and certificate lifecycles. Audited explicitly under ISO 27001 A.8.24 and PCI DSS Req 3-4.
Change Management Policy
How changes to production systems are proposed, reviewed, approved, deployed, and rolled back. Foundational for SOC 2 CC8 and a perennial audit-finding magnet when not in place.
Ethics & Conduct
Anti-Bribery & Corruption Policy
Defines what bribery is, why it's prohibited, and the procedures staff must follow regarding gifts, hospitality, facilitation payments, and dealings with public officials. Required to demonstrate adequate procedures under the UK Bribery Act 2010.
Whistleblowing (Speak Up) Policy
Confidential channels for staff and third parties to report concerns about wrongdoing without fear of retaliation. Required by PIDA 1998 in the UK and best-practice everywhere.
People
Remote & Hybrid Working Policy
Operational, security, and health-and-safety expectations for staff working away from a company location. A modern essential — most organisations have one in practice but few have a properly documented version.
Equality, Diversity & Inclusion Policy
How the organisation upholds equality of opportunity, embraces diversity, and fosters inclusion. Required to align with the Equality Act 2010 and most modern procurement frameworks.
