What clients may entrust to us
Depending on scope, engagements may involve product architecture, firmware information, SBOMs, vulnerabilities, software repositories, technical documentation, incident information and security-testing results. We agree the necessary information and handling arrangements before access is provided.
Access Control
Least privilege, role-based access and engagement-specific permissions limit access to personnel who need it for the work. Access should be reviewed as responsibilities change and removed when no longer required.
Data Handling
Technical information is transferred through encrypted channels and held in controlled storage with appropriate encryption. Retention, secure deletion and permitted locations are defined for the engagement. Client-controlled repositories are preferred where suitable.
Client Repositories
Where practical, 5Z can work within customer-controlled repositories and engineering systems rather than copying technical information into separate systems.
AI Usage
Confidential client information is not used to train public AI models. AI-assisted tools may only be used where appropriate and subject to agreed confidentiality and security controls.
Vulnerability Information
Vulnerability data receives restricted handling. Disclosure is limited to personnel with a need to know and follows agreed coordination, escalation and disclosure processes. Do not send vulnerability details through the initial contact form.
Third Parties
Penetration testers, laboratories, certification organisations and other specialists will not receive confidential customer information without appropriate controls and, where required, client approval. Independent assessment remains the responsibility of the relevant authorised provider.
Procurement Review
Our security architecture and information-handling procedures can be reviewed as part of customer procurement and supplier-security assessment. Engagement-specific requirements, provider arrangements and evidence should be confirmed during that review.
NDA
An NDA can be executed before sensitive technical information is exchanged. Start with a confidential discussion about scope, without sending technical files.