Defined responsibilities
Each role knows its decision scope and what requires review.
Governance

This page outlines Cup Code principles for accountability, information protection, risk management, and conflicts of interest.
PoliciesPrinciples
Material decisions follow documentation, review, and clear ownership.
Each role knows its decision scope and what requires review.
Access follows need and is removed when the role or need changes.
We record the decision, reason, impact, and follow-up owner.
Policies and controls are reviewed when services or risks change.
Risk management
We assess risk by impact and likelihood, then assign an owner, response, and review time.
Reliability, performance, accessibility, and service continuity.
Access, data, integrations, and report response.
Scope, responsibilities, information handling, and continuity.
Disclosure, review, and separation of decisions when needed.
Domains
Each page explains accountability, lifecycle, and evidence without exposing internal data or security secrets.
Decision layers, delegation, and separation of duties.
Versions, review, approval, and acknowledgement.
Assessment, treatment, acceptance, and control testing.
Processing register, rights, retention, and incidents.
Access, secure development, vulnerabilities, and response.
Critical services, backups, exercises, and communications.
Selection, contract, monitoring, and exit.
Disclosure, recusal, and mitigation plan.
Confidentiality, non-retaliation, and independent review.
Change, integrations, keys, and human oversight.
What we publish, redact, and correct.
Policies and channels