Texas A&M Transportation Institute · TTI Code service policy
Acceptable Use Policy
What you may and may not do with TTI Code — the Institute's own home for
source code, shared packages, and automated builds at code.tti.tamu.edu.
Applies to everyone who signs in to the service
1. Purpose & scope
TTI Code is an official information resource of the Texas A&M Transportation Institute (a member of The Texas A&M University System). It provides self-hosted source control, shared package registries, and automated build-and-test pipelines for TTI research and operations. This policy governs all use of the service and supplements — does not replace — TAMUS and TTI information-security policy (including [TAC §202, TAMUS 29.01.03, TTI policy refs]).
2. Who may use it
- TTI faculty, staff, students, and sponsored collaborators with a valid [TAMUS NetID / approved account].
- Access is granted on a least-privilege basis — you get only the access your work requires. Repository visibility (public / internal / private) is set by repo owners.
3. Acceptable use
- Store and collaborate on code, configuration, documentation, and packages for TTI work.
- Keep credentials, tokens, and keys out of repositories; put them in the service's encrypted secrets store instead.
- Respect repository access controls and the data-classification limits below.
4. Prohibited use
- Storing data above this instance's approved classification level (see Data Classification) — including CUI, export-controlled (ITAR/EAR), or other restricted data — without explicit TTI ISO approval.
- Personal, commercial, or non-TTI use; unlawful content; circumventing access controls or security scanning.
- Committing secrets, malware, or third-party material you lack rights to.
5. Security responsibilities
- Enable multi-factor authentication. Protect personal access tokens — the long-lived keys that let scripts and tools sign in as you — and give each one the narrowest access it needs.
- Report suspected compromise to [TTI ISO contact] promptly.
6. Monitoring & privacy
This is a State of Texas information resource. Activity may be logged, scanned (including automated scans for leaked credentials and misclassified data), and reviewed for security and compliance. Users should have no expectation of privacy in their use of the service, consistent with TAMUS policy. [Confirm exact language with OGC.]
7. Enforcement & contact
Violations may result in suspension of access and referral under applicable TAMUS/TTI policy. Questions: [TTI ISO / support contact].
Document status
| Status | Draft — not approved, not in force |
|---|---|
| Version | DRAFT |
| Last updated | [date] |
| Owner | [TTI ISO] |
| Awaiting review by | TTI Information Security · TAMUS Office of General Counsel |