# No-Personal-Data Engagement Attestation — Draft

**Status:** buyer-specific draft; confirm against the signed statement of work before execution.

The parties intend the advisory engagement to examine governance policies, system architecture,
model and agent inventories, control evidence, and synthetic examples. The advisor does not require
and will not request production customer, patient, employee, account, credential, or special-category
personal data to perform the default scope.

Client materials remain in the client-approved tenant wherever practicable. Any departure from this
boundary requires written approval identifying the data categories, purpose, location, access list,
retention period, deletion method, and applicable data-processing terms before transfer.

This attestation describes an operating boundary; it is not a substitute for a DPA where law or the
client's policy requires one.

