Skip to main content

Security and data handling

The boundary is designed before access is granted.

Security begins with the work: what information is needed, where it may move, who may reach it, which decisions remain human, and what evidence must exist at handoff. Those decisions become the engagement control record.

ForPeople conducting policy, privacy, security, or access review

FocusControls, ownership, evidence, and review paths

Before access

  1. Classify data, systems, environments, and regulatory obligations.

  2. Minimize the information and privileges required for the role.

  3. Name access, data, security, privacy, and client decision owners.

  4. Record approved regions, providers, retention, deletion, and exit conditions.

  5. Establish incident, escalation, continuity, and evidence paths.

During delivery

  • Access is role- and scope-bound, time-aware, reviewable, and removed at transfer.

  • Changes carry peer review, test evidence, approval, release, and rollback records.

  • Telemetry avoids client content by default and routes material events to named owners.

  • Restricted artifacts stay in approved environments; local copies and unmanaged transfer paths are prohibited.

  • AI assistance is bounded to approved tools and data. Principals and deterministic controls retain consequential decisions.

At handoff

The transfer record includes accepted work, open decisions, residual risk, access removed, data returned or deleted, retained evidence, continuity owners, and the client's operating path.

Current external evidence

The current SOC 2 Type II report covers April 1, 2025 through March 31, 2026 and was issued May 2026. The latest third-party penetration test was completed April 2026.

Review subprocessors

Start a security review.