Data Retention & Security Policy
Our commitment to responsible data handling and minimal retention practices
Our Philosophy
SunTzu Security Labs is built around long-term security relationships, not long-term data collection.
Our goal is to help organizations improve their security posture through trusted, professional engagement while minimizing unnecessary retention of sensitive customer information.
We believe security assessment data should be:
- protected
- encrypted
- purpose-driven
- retention-limited
- and responsibly destroyed when no longer needed
Data Collection Principles
During authorized security assessments, SunTzu Security Labs may collect and process:
- externally observable network information
- TLS/SSL configuration data
- publicly accessible service metadata
- vulnerability assessment results
- assessment artifacts
- and generated reports
We do not intentionally collect unnecessary customer content, internal business records, or sensitive operational data beyond the scope of the authorized engagement.
Encryption & Storage Protection
Assessment artifacts and customer-related security data are protected using industry-standard encryption controls.
Data protections may include:
- encrypted storage volumes
- encrypted object storage
- encrypted backups
- transport-layer encryption
- access control restrictions
- and role-limited administrative access
Access to customer assessment data is restricted to authorized SunTzu Security Labs personnel with a legitimate operational need.
Retention Philosophy
SunTzu Security Labs retains assessment information only for as long as it provides operational, reporting, or relationship value to the client.
Retention periods vary based on:
- engagement type
- active service relationship status
- recurring assessment agreements
- legal or contractual obligations
- and customer-requested retention requirements
Our retention model is designed to minimize unnecessary long-term storage of customer security data.
Raw Artifact Retention
Raw scanner artifacts and low-level telemetry data are typically retained for shorter periods than finalized reports and curated findings.
Examples of raw artifacts may include:
- scanner output
- protocol negotiation details
- raw TLS assessment data
- service fingerprints
- and temporary analysis artifacts
These records may be compressed, archived, anonymized, or permanently deleted after operational usefulness expires.
Active Customer Relationships
For customers with active recurring services or ongoing assessment relationships, selected historical findings and reports may be retained to support:
- trend analysis
- remediation tracking
- historical comparison
- posture improvement measurement
- and longitudinal security review
This allows customers to measure security improvement over time while avoiding unnecessary raw telemetry retention.
Inactive Customer Relationships
When customer relationships become inactive, SunTzu Security Labs may:
- reduce retained assessment data
- purge raw artifacts
- archive only finalized reports
- or permanently remove customer-related assessment records
Our objective is to avoid indefinite retention of customer assessment data after the operational relationship has ended.
Data Destruction
When assessment data reaches the end of its retention lifecycle, SunTzu Security Labs may securely delete or destroy:
- raw artifacts
- temporary processing data
- generated telemetry
- and associated assessment records
Deletion processes are designed to reduce the risk of unauthorized recovery or exposure.
Confidentiality
Customer assessment information is treated as confidential and is not sold, publicly disclosed, or shared with third parties except:
- as required by law
- as authorized by the customer
- or as necessary to fulfill contracted services
Continuous Improvement
SunTzu Security Labs continuously evaluates and improves its operational security, retention practices, and evidence-handling procedures to align with evolving security standards and customer expectations.
Contact
For questions regarding assessment data handling, retention practices, or security procedures, please contact:
SunTzu Security Labs
Website: suntzusecuritylabs.com
Email: security@suntzusecuritylabs.com
Mature Data Handling PracticesThis policy represents a commitment to minimal data collection and responsible retention— substantially more mature than what many security startups publish publicly.