Third-Party Software, Open Source & Digital Supply Chain Policy

Version 1.0 · Last Updated:

1. Purpose

This policy sets out Murzo Group's approach to third-party software, open source, software dependencies, cloud services, digital suppliers, vendor access, licences, and digital supply chain risk.

The purpose is to reduce the risk of insecure software, licence breaches, unsupported dependencies, unauthorised vendor access, supply chain compromise, data exposure, and business interruption.

2. Scope

This policy applies to websites, client platforms, internal tools, software libraries, plugins, APIs, scripts, cloud services, SaaS tools, code repositories, build systems, deployment tools, AI tools, analytics tools, payment tools, email tools, security tools, and technology suppliers used by or for Murzo Group.

3. Policy Position

Murzo Group will use third-party software and open source in a controlled, proportionate way. Security, licence, privacy, continuity, access, and supplier risk should be considered before software becomes business critical or handles sensitive data.

Convenience must not override security, data protection, client confidentiality, intellectual property, or operational resilience.

4. Supplier and Tool Checks

  • Check business purpose, owner, data handled, user access, security posture, support, location, and exit route
  • Check whether the supplier has appropriate terms, privacy commitments, security controls, and breach notification routes
  • Check whether the tool is suitable for client data, personal data, confidential data, regulated data, or security-sensitive information
  • Check whether integration, API, plugin, browser extension, or automation access creates excessive privilege
  • Check continuity risks where the tool is critical to trading, website operation, security, finance, communications, or customer service

5. Open Source and Dependencies

Open-source software must be used in line with its licence and security risk. Particular care is required for copy-left licences, unknown maintainers, abandoned packages, typosquatting, dependency confusion, malicious packages, and components embedded into client or commercial products.

Code copied from the internet, AI-generated code, snippets, templates, fonts, images, plugins, and libraries must not be assumed free of licence, security, or intellectual property risk.

6. Access and Change Control

Third-party access to systems, repositories, hosting, email, payment tools, analytics, client data, or production environments must be authorised, limited, monitored where appropriate, and removed when no longer needed.

Material software changes, new integrations, payment changes, authentication changes, domain changes, tracking tools, and production deployments should be controlled according to risk.

7. Incidents

Software vulnerabilities, supplier compromises, credential leaks, malicious dependencies, unauthorised access, licence claims, data exposure, or critical outages must be escalated promptly and handled alongside cybersecurity, data breach, business continuity, and customer communication procedures.

8. Evidence

Supplier, licence, security, approval, access, and incident evidence should be limited to what is needed for lawful use, security, data protection, client assurance, business continuity, insurance, or dispute handling.

9. Review

This policy will be reviewed when Murzo Group launches a new platform, adopts a critical tool, uses new AI or automation, changes hosting, or experiences a material software supply chain issue.

Murzo Group authorised signature