diff --git a/README.md b/README.md index 153f289..eddbb86 100644 --- a/README.md +++ b/README.md @@ -8,7 +8,7 @@ _Since these are our internal policies, some links to internal documents or reso This repository is the source of truth for the policies available at https://tailscale.com/security-policies/. -These policies were last reviewed on 2023-04-03. +These policies were last reviewed on 2023-07-12. ### FAQ diff --git a/change-management/index.md b/change-management/index.md index f9e023d..e81c431 100644 --- a/change-management/index.md +++ b/change-management/index.md @@ -14,7 +14,7 @@ To avoid potential security incidents, Tailscale requires change management cont Changes to code in Tailscale’s environment made by an employee or contractor must be tested and approved by another employee prior to being merged and rolled out. -Tailscale uses branch protection rules on GitHub to require a second review prior to merging code. +Tailscale uses branch protection rules on GitHub to require changes be made through a pull request with a second review prior to merging code. Exceptionally, employees can push changes without a second review where they are required to mitigate an incident. Changes pushed without prior approval are tagged and audited after the fact, within 2 business days. diff --git a/information-classification/index.md b/information-classification/index.md index c4c89e2..a6fbd54 100644 --- a/information-classification/index.md +++ b/information-classification/index.md @@ -39,7 +39,6 @@ Tailscale classifies assets into three risk categories: **Low Risk**, **Medium R