Engagement data handling

The safest transfer is the one the engagement does not need

Governance reviews require architecture, policies, inventories and evidence—not production personal data. The default delivery model is designed around that fact.

No production personal data by default

The work reviews policies, architecture, model inventories, control evidence and synthetic examples. Production customer, patient or employee records are neither requested nor required.

Client-tenant first

Working documents remain in the client's approved tenant under its identity, access, retention and audit controls whenever procurement permits.

Synthetic illustrations

Examples and test fixtures use synthetic or irreversibly de-identified data. A client must explicitly approve any exception before transfer.

No public-AI submission

Confidential client material is not submitted to public consumer AI tools. Client-approved enterprise tooling may be used only inside the client's contractual and technical boundary.

Named access

Access is granted to the principal only. Additional specialists are disclosed and approved before they receive any client material.

Return and destruction

At close, client-controlled work remains with the client. Local working copies are returned or destroyed and that action can be certified in writing.

Exception path

If real data becomes necessary, work stops until purpose, fields, location, access, retention, transfer mechanism and deletion evidence are written into the scope. An exception is never created by someone pasting a record into a chat or email.

Evidence a buyer can request

  • Access list and approval record
  • Client-tenant working location
  • Approved-tool and subprocessor list
  • Return or destruction certificate at close
  • Incident contact and escalation path
Next step

Test the boundary against your questionnaire

Send the exact data-flow or supplier-risk question. The response should be specific enough to attach to the vendor record.