00Enterprise Trust

Data governance, designed for the enterprise.

How we classify, secure, retain, and govern the information you entrust to the Crisis Intelligence Assessment Platform — written to be scanned by your risk, security, and procurement teams.

Confidential by DesignSecure Data HandlingEnterprise Security & Data Governance
01

Data classification

We separate data by type so handling, access, and retention rules can be applied at the right level of sensitivity.

  • Personal Data — name, email, phone
  • Organizational Data — assessment responses
  • Analytical Data — scores, insights, derived metrics
02

Data usage

Data you submit is used only to deliver the diagnostic and the services you request.

  • Generating your readiness report
  • Delivering advisory and consultation services
  • Anonymized benchmarking against peer cohorts
03

Data security

Information is protected in transit and at rest using enterprise-grade controls.

  • TLS encryption in transit; encryption at rest
  • Row-level access controls scoped to the authenticated user
  • Managed cloud infrastructure with provider-maintained controls (independent assessment planned)
04

Data retention

We hold data only as long as necessary to deliver the service or meet legal obligations.

  • Reports retained for as long as your account is active
  • Deletion requests honored on written request
  • Audit and compliance logs retained per legal minimum
05

User rights

You retain control over the information you provide.

  • Access — request a copy of your data
  • Correct — update inaccurate information
  • Delete — remove your account and associated data
  • Withdraw consent — at any time, without penalty
06

Third-party services

We use a small set of vetted providers, each bound by their own enterprise terms.

  • Payment processors — handle card data; we never store full PAN
  • Analytics tools — usage metrics, respect cookie preferences
  • Scheduling tools — for advisory and consultation booking
07

Confidentiality

Organizational data is treated as confidential and is not shared externally except in anonymized form.

08

Access governance

Internal access is restricted, logged, and reviewed.

  • Least-privilege role assignments
  • Audit logging on sensitive operations
  • Periodic access reviews

Confidentiality statement

“Organizational data is treated as confidential and is not shared externally except in anonymized form.”

Document version: 0.9 · Last reviewed: 2026-08-17 · Status: Reviewed