Security & Confidentiality

Security & Confidentiality

Product-security work involves sensitive technical information. Our operating model is designed around protecting it.

Product-security work involves sensitive technical information. Our operating model is designed around protecting it.

What clients may entrust to us

Depending on scope, engagements may involve product architecture, firmware information, SBOMs, vulnerabilities, software repositories, technical documentation, incident information and security-testing results. We agree the necessary information and handling arrangements before access is provided.

Access Control

Least privilege, role-based access and engagement-specific permissions limit access to personnel who need it for the work. Access should be reviewed as responsibilities change and removed when no longer required.

Data Handling

Technical information is transferred through encrypted channels and held in controlled storage with appropriate encryption. Retention, secure deletion and permitted locations are defined for the engagement. Client-controlled repositories are preferred where suitable.

Client Repositories

Where practical, 5Z can work within customer-controlled repositories and engineering systems rather than copying technical information into separate systems.

AI Usage

Confidential client information is not used to train public AI models. AI-assisted tools may only be used where appropriate and subject to agreed confidentiality and security controls.

Vulnerability Information

Vulnerability data receives restricted handling. Disclosure is limited to personnel with a need to know and follows agreed coordination, escalation and disclosure processes. Do not send vulnerability details through the initial contact form.

Third Parties

Penetration testers, laboratories, certification organisations and other specialists will not receive confidential customer information without appropriate controls and, where required, client approval. Independent assessment remains the responsibility of the relevant authorised provider.

Procurement Review

Our security architecture and information-handling procedures can be reviewed as part of customer procurement and supplier-security assessment. Engagement-specific requirements, provider arrangements and evidence should be confirmed during that review.

NDA

An NDA can be executed before sensitive technical information is exchanged. Start with a confidential discussion about scope, without sending technical files.

Book a confidential CRA Readiness Call

Book a confidential CRA Readiness Call