A security page that overstates is a liability, not a credibility asset (PRD §13). Every statement below must describe a control that is actually in place. Delete any item that is not yet true rather than softening its wording.
Data in transit and at rest
[To complete with what is actually implemented: TLS version enforced in transit; encryption at rest for each system that stores client data — named, not implied.]
Access control
[To complete: who has access to client data, how access is granted and revoked, whether multi-factor authentication is enforced, and how privileged access is handled.]
Subprocessors
[To complete: the list of subprocessors that may handle client data, each with its role. Must stay consistent with the processor list in the Privacy Policy and the DPA.]
Human review and handling
[To complete: how documents handled during an engagement are stored, who reviews exceptions, and how long working data is retained.]
Vulnerability reporting
[To complete: the security contact address (PRD D8), what researchers can expect, and the target acknowledgement window.]
Incident response
[To complete: the commitment actually being made — how incidents are triaged and the notification timeframe for affected clients. State a timeframe only if it can be met.]
