Skip to content

Company Policies

A living library of your organization's security policies and procedures — drafted by the ByteCode team in Notion, published on your portal with one click, and read by everyone in your organization directly inside BCP Portal. No Notion account needed to read them, no integration to set up on your side.

How it works

  1. The ByteCode team drafts and maintains your policies as pages in Notion, based on your organization's needs and the frameworks you follow (ISO 27001, SOC 2, GDPR, …).
  2. When a policy is ready, a ByteCode admin clicks Publish in the portal. That snapshots the current content as version 1 and makes it visible to everyone in your organization.
  3. Further edits happen on our side and stay invisible until an admin publishes again. Each publish creates a new version (v2, v3, …); older versions are never overwritten.
  4. Everyone reads policies on the platform, not in Notion — formatting (headings, bullet and numbered lists, checklists, tables, quotes, callouts, code blocks, images) carries over faithfully.

You don't need to run a Notion workspace or manage any integration. Your Admins on the portal only need to:

  • Track who has accepted the current version (audit log).
  • Click Publish when the ByteCode team asks them to promote a fresh draft.

Reading a policy

Open Policies from the main navigation.

  • Every published policy is listed with its current version.
  • Click a policy to read it. Use the version picker at the top to go back and read an older version — nothing is ever deleted.
  • Download PDF turns the version you're currently viewing into a PDF file, ready to attach to an email, audit request, or offline record.
  • Accept / Reaccept. When a version is marked as requiring re-acceptance (see Publishing below), each user sees an Accept button on the version they're reading. Clicking it records their acknowledgment against that specific version, timestamped — visible to admins as an audit trail. Once accepted, the button turns into a "✓ Accepted" indicator until a new version is published that requires re-acceptance.

Images and embedded files

Images placed in the source Notion page render inline on the platform — you don't need a Notion account or a public share link. The portal proxies each image through its own signed URL, refreshed on demand, so images stay behind the same login as everything else.

Drafts stay private

A policy only appears in this list once an admin publishes it for the first time. Work-in-progress drafts (which the ByteCode team is still editing) are visible only to Admins.

Publishing a new version (Admin only)

When the ByteCode team lets you know a new draft is ready, an Admin in your organization publishes it from the portal:

  1. Open Policies → find the policy → click Publish new version.
  2. A dialog asks whether this change requires re-acceptance:
    • Yes (default) — significant change (updated obligations, new policy language). Every user's previous "Accepted" state resets; they see the Accept button again the next time they open the policy.
    • No — cosmetic edit (typo fix, formatting). Existing acceptances stay valid.
  3. Confirm. The current content is snapshotted as version N+1; earlier versions remain accessible via the version picker.

Snapshots are immutable — future edits do not change already-published versions. That's the whole point: the audit log ties each user's acceptance to the exact text they read.

Sync now. At the top of the Policies list, Admins have a Sync now button. Clicking it fetches the latest list of policies from source and pulls in newly-added policies. Use this if the ByteCode team told you a new policy is on the way and you don't see it yet.

Security

  • All policy content is drafted and hosted in ByteCode's controlled Notion workspace — you don't manage credentials, tokens, or integrations on your side.
  • Only Admins in your organization can publish a new version (promote a draft) or trigger a manual sync. See Roles and Permissions.
  • Reading published policies (and downloading them as PDF) is available to every member of your organization, including the Employee role.
  • Content is scoped strictly to your organization — nothing is shared across clients.