Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Solution Architect

previous version on gdrive

A.8.4 Access to Source Code

Control Objective

Read and write access to source code, development tools and software libraries shall be appropriately managed.

Policy Statement

anDREa safeguards its proprietary intellectual property, application logic, and deployment configurations by strictly managing read and write permissions to the myDRE source code repositories. Authorization is strictly restricted to verified technical personnel and managed through centralized identity management, code reviews, and formal escrow arrangements to ensure long-term platform integrity and availability.


Source Code Access Governance

Repository security and modifications are restricted and managed through the following controls:

  • Centralized Identity Control: The primary source code for the myDRE platform is hosted natively within private GitHub repositories. Access is governed via integration with anDREa's Entra ID using a dedicated Role-Based Access Control (RBAC) group (DRE-Developers).
  • Authorized Personnel Only: Membership within the GitHub organization and the associated Entra ID group is restricted exclusively to active anDREa developers, dedicated quality assurance testers, and the Director.
  • Administrative Governance: Only authorized GitHub Organization Owners can execute system invitations. Individuals provisioned with the Owner role are formally documented within anDREa People - Asset Overview.
  • Regular Access Reviews: Repository permissions, user accounts, and write privileges are reviewed by the designated Asset Owner at least biannually, or immediately following internal role or employment changes (see A.06.05 - Responsibilities after termination or change of employment).

Source Code Continuity & Escrow Protection

To maintain long-term business continuity and protect stakeholder investments, anDREa utilizes an external backup and escrow framework:

  • Quarterly Depositions: A complete, verified snapshot of the active myDRE source code is systematically packaged and deposited with an independent Escrow Service Provider every quarter.
  • Access Isolation: Physical and logical access to the escrowed source code is managed entirely by the escrow partner. Release triggers and oversight are governed strictly by the legal agreements executed between anDREa's shareholders, the corporate board, and the escrow provider.