Encryption in transit and at rest
Data moves over encrypted channels and sits encrypted while we hold it. No unencrypted extracts on laptops, no data sent by email attachment.
Data moves over encrypted channels and sits encrypted while we hold it. No unencrypted extracts on laptops, no data sent by email attachment.
We ask for the narrowest access that will do the job, and we tell you when to revoke it. Credentials are never shared between engagements.
If your obligations require onshore processing, we work to that. Where cloud services are involved we agree the region with you before anything moves.
Working copies are destroyed at the end of the engagement and we confirm it in writing. We do not keep your data as a reference set.
We sign your NDA, or provide ours. Either way it is in place before we see anything.
Before any cutover we confirm you have a restore point that has actually been restored — not just a backup that has been taken.
Moving personal information is a processing activity, and the obligations do not transfer to your supplier — they stay with you. That means the way your migration is run is your compliance position, not ours.
Practically, that comes down to four things: only move what you need, keep it secure while it is in flight, be able to show where it went, and be able to prove the working copies were destroyed. Our engagements are built to produce that evidence as a by-product, so you are not assembling it afterwards.
This is a description of how we work, not legal advice. For advice specific to your obligations, talk to your legal counsel or the Office of the Privacy Commissioner.
Get moving
Send us your security questionnaire, or just ask. We would rather answer it now than have it surface halfway through a project.