Skip to main content
Security Policy

Data Retention & Security Policy

Our commitment to responsible data handling and minimal retention practices

Our Philosophy

SunTzu Security Labs is built around long-term security relationships, not long-term data collection.

Our goal is to help organizations improve their security posture through trusted, professional engagement while minimizing unnecessary retention of sensitive customer information.

We believe security assessment data should be:

  • protected
  • encrypted
  • purpose-driven
  • retention-limited
  • and responsibly destroyed when no longer needed

Data Collection Principles

During authorized security assessments, SunTzu Security Labs may collect and process:

  • externally observable network information
  • TLS/SSL configuration data
  • publicly accessible service metadata
  • vulnerability assessment results
  • assessment artifacts
  • and generated reports

We do not intentionally collect unnecessary customer content, internal business records, or sensitive operational data beyond the scope of the authorized engagement.

Encryption & Storage Protection

Assessment artifacts and customer-related security data are protected using industry-standard encryption controls.

Data protections may include:

  • encrypted storage volumes
  • encrypted object storage
  • encrypted backups
  • transport-layer encryption
  • access control restrictions
  • and role-limited administrative access

Access to customer assessment data is restricted to authorized SunTzu Security Labs personnel with a legitimate operational need.

Retention Philosophy

SunTzu Security Labs retains assessment information only for as long as it provides operational, reporting, or relationship value to the client.

Retention periods vary based on:

  • engagement type
  • active service relationship status
  • recurring assessment agreements
  • legal or contractual obligations
  • and customer-requested retention requirements

Our retention model is designed to minimize unnecessary long-term storage of customer security data.

Raw Artifact Retention

Raw scanner artifacts and low-level telemetry data are typically retained for shorter periods than finalized reports and curated findings.

Examples of raw artifacts may include:

  • scanner output
  • protocol negotiation details
  • raw TLS assessment data
  • service fingerprints
  • and temporary analysis artifacts

These records may be compressed, archived, anonymized, or permanently deleted after operational usefulness expires.

Active Customer Relationships

For customers with active recurring services or ongoing assessment relationships, selected historical findings and reports may be retained to support:

  • trend analysis
  • remediation tracking
  • historical comparison
  • posture improvement measurement
  • and longitudinal security review

This allows customers to measure security improvement over time while avoiding unnecessary raw telemetry retention.

Inactive Customer Relationships

When customer relationships become inactive, SunTzu Security Labs may:

  • reduce retained assessment data
  • purge raw artifacts
  • archive only finalized reports
  • or permanently remove customer-related assessment records

Our objective is to avoid indefinite retention of customer assessment data after the operational relationship has ended.

Data Destruction

When assessment data reaches the end of its retention lifecycle, SunTzu Security Labs may securely delete or destroy:

  • raw artifacts
  • temporary processing data
  • generated telemetry
  • and associated assessment records

Deletion processes are designed to reduce the risk of unauthorized recovery or exposure.

Confidentiality

Customer assessment information is treated as confidential and is not sold, publicly disclosed, or shared with third parties except:

  • as required by law
  • as authorized by the customer
  • or as necessary to fulfill contracted services

Continuous Improvement

SunTzu Security Labs continuously evaluates and improves its operational security, retention practices, and evidence-handling procedures to align with evolving security standards and customer expectations.

Contact

For questions regarding assessment data handling, retention practices, or security procedures, please contact:

SunTzu Security Labs

Website: suntzusecuritylabs.com

Email: security@suntzusecuritylabs.com

Mature Data Handling PracticesThis policy represents a commitment to minimal data collection and responsible retention— substantially more mature than what many security startups publish publicly.