How we handle your data

You are being asked to give an outside firm access to your operational systems. This page is what we would send your IT lead or compliance officer, published so you do not have to ask for it.

BASELINE CONTROLS

Applied to every engagement

Control area

Standard applied

Access

Least privilege, read-only wherever the engagement permits. We do not require administrator credentials. Access is documented at engagement start, reviewed during the engagement, and revoked at close.

Authentication

Multi-factor authentication enforced on every account, ours and yours.

Encryption

Encryption in transit and at rest for all client data, including full-disk encryption on every device used for delivery.

Data minimization

De-identified extracts wherever the analysis permits. In healthcare engagements, protected health information is kept out of the reporting layer by design rather than removed afterwards.

Retention and disposal

A written retention schedule. Your data is returned or securely destroyed at engagement end, with certification on request.

Logging and monitoring

Activity logging on our systems. Scheduled refresh failure alerting on any pipeline we operate for you.

Change control

All transformation logic held in version control. Changes to definitions, models and reports documented and versioned.

Subcontractors

Written confidentiality and data-handling terms flow down to any specialist we engage. No subcontractor touches regulated client data without your written consent and an executed downstream agreement.

Incident response

 A written incident response procedure with defined notification timeframes to affected clients, aligned to HIPAA and GLBA notification expectations.

BY SECTOR

Sector-specific obligations

Healthcare

We execute a business associate agreement before any access to protected health information, and maintain a documented Security Rule risk analysis under 45 CFR 164.308.

Our controls are designed against the strengthened requirements proposed in the January 2025 Security Rule rule-making rather than the current minimum: encryption at rest and in transit, multi-factor authentication, and documented risk analysis. A control set built now to the higher bar does not need rebuilding when the rule is finalized.

Financial services

We maintain a written information security programme mirroring the GLBA Safeguards Rule elements, with a designated qualified individual, written risk assessment, access controls, data inventory, encryption, and activity logging.

We hold prepared vendor due diligence responses aligned to the June 2023 Interagency Guidance on Third-Party Relationships, so your due diligence process does not stall waiting for us.

Nonprofit and public sector

Controls and record retention sufficient to satisfy 2 CFR 200 contractor and subrecipient expectations, including the reinforced cybersecurity safeguarding language added in the 2024 revision.

Where an engagement touches data connected to federal awards, handling and retention are documented to the standard your Single Audit would expect.

Retail and e-commerce

Engagements are scoped to exclude cardholder data wherever possible. Where it is unavoidably in scope, PCI DSS v4.0.1 service-provider obligations are addressed contractually before any access is granted.

Where biometric identifiers are present, Illinois BIPA notice, consent and retention requirements are observed.

INSURANCE

Cover in force

  • Professional liability (errors and omissions): claims arising from professional advice or deliverables
  • Cyber liability: data breach response, notification costs, regulatory defense
  • General liability: standard commercial exposure

Certificate of insurance provided on request, naming your organization where your procurement process requires it.

CONTRACTING

What we sign

  • Mutual non-disclosure agreement: before discovery, where client information is discussed
  • Master services agreement: terms, liability limitation, intellectual property, termination
  • Statement of work: per engagement, with an explicit change-order clause
  • Data processing agreement: handling, retention and destruction obligations
  • Business associate agreement: where HIPAA applies

We are happy to work from your paper rather than ours where your legal team prefers it.

INTELLECTUAL PROPERTY

Who owns what

Your data and your deliverables belong to you. The definitions register, the data model, the dashboards, the findings report, all yours, and structured so that another provider could pick them up. We do not build dependency into deliverables.

We retain only our pre-existing methodology, templates and tooling. Anonymized benchmark measurements are used only where you have given written permission at engagement start, and refusing has no effect on the engagement or its price.

ARTIFICIAL INTELLIGENCE

Where AI is and is not used

AI tooling is used where it improves speed without touching client confidentiality: drafting findings narrative from our own reconciliation output, writing extraction and cleaning scripts, and first-pass research on public information.

It does not go near your data without written permission and an executed data processing agreement.

Where your own analytics environment includes AI features, Copilot in Power BI or Fabric, for example, those operate inside your tenancy under your governance. That is a materially different question from us processing your data through an external service, and we state which is which in every proposal.

Need more before you proceed?

We hold vendor questionnaire responses, a one-page security summary, and a certificate of insurance ready to send. We are also happy to join a security review call with your IT or compliance lead before any engagement is signed.

Find out what your data can and cannot tell you

Ten business days, a fixed price, and a findings register you can act on whether or not you work with us again.

Not ready to talk? Score your own data estate first. The 30-Point Data Health Checklist. Get the checklist