---
title: "Network segmentation policy"
description: "How Speak AI separates network zones so a compromise in one does not reach production data in another."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.speakai.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Network segmentation policy

**1. Purpose**<br /><br />This policy establishes security controls for network segmentation and segregation to mitigate security risks, prevent unauthorized access, and enhance data protection within Speak AI’s infrastructure.

**2. Scope**<br /><br />This policy applies to all networks, systems, and devices within Speak AI’s environment, including corporate, cloud, and third-party integrated networks.

**3. Network Segmentation Standards**

**3.1 Segmentation Principles**

- Network segmentation must be implemented to isolate sensitive systems and data from general access networks.
- Internal networks must be logically and physically separated based on risk levels, business functions, and data sensitivity.
- Guest and employee networks must be segmented from production and administrative networks.

**3.2 Access Controls & Monitoring**

- Firewall rules must restrict traffic between network segments based on business needs.
- Multi-Factor Authentication (MFA) and least privilege principles must be enforced for access to segmented networks.
- Network traffic must be monitored for anomalies, with alerts for unauthorized access attempts.

**3.3 Secure Data Flow & Connectivity**

- Data flow between network segments must be controlled via approved gateways, proxies, or firewalls.
- Remote access to segmented networks must be secured with VPN and encrypted tunnels.
- Direct external access to sensitive network segments must be prohibited unless explicitly authorized.

**3.4 Segmentation Testing & Validation**

- Regular penetration tests and vulnerability assessments must be conducted to validate network segmentation controls.
- Network segmentation policies must be reviewed at least annually and updated to address emerging threats.

**4. Compliance & Enforcement**

- All systems and applications must comply with Speak AI’s **Network Security Policy** and **Access Management Policy**.
- Non-compliance with segmentation policies will result in corrective actions, including access revocation or network redesign.

**5. References & Supporting Documents**

- Speak AI **Network Security Policy**: [/help/security/policies/network-security/](/help/security/policies/network-security/)
- Speak AI **Access Management Policy**: [/help/security/policies/access-management/](/help/security/policies/access-management/)
- Speak AI **Vulnerability Management Policy**: [/help/security/policies/vulnerability-management/](/help/security/policies/vulnerability-management/)

**6. Contact Information** <br /><br />For security concerns or policy clarifications, contact **success@speakai.co**.

***

This policy is subject to periodic review and updates to align with evolving security threats and industry best practices.

Source: https://docs.speakai.co/help/security/policies/network-segmentation/index.mdx
