Security & Compliance
Documented authorization, data minimization, access control, and evidence-handling practices for organizations with rigorous security requirements.
Our Trust Pillars
Privacy First
SunTzu Security Labs follows data minimization principles designed to reduce unnecessary collection and retention of customer information. We do not sell customer information and only collect information necessary to perform authorized assessments, support customer relationships, and deliver assessment results.
- No data sales or marketing lists
- Minimal collection approach
- Purpose-limited data use
- Transparent data practices
Data Retention
Assessment artifacts, findings, and supporting data are retained only as long as operationally necessary or required to support ongoing customer relationships. Our retention philosophy is simple: Retain only what is necessary, encrypt stored assessment information, reduce long-term exposure by limiting unnecessary retention, and remove assessment data when it is no longer required operationally or contractually. Security data should not exist forever simply because it can.
- Retain only what is necessary
- Encrypt stored assessment information
- Reduce long-term exposure
- Remove data when no longer required
Authorization Requirements
Authorized assessments are fundamental to our process. Assessment activities occur only against explicitly approved targets following scope validation, ownership verification, and authorization procedures. We believe trust begins with clear boundaries.
- Required Letters of Authorization
- Documented consent process
- Scope verification procedures
- Legal compliance checks
Compliance Support
We support organizations operating under major compliance frameworks and regulatory requirements
Regulated-Environment Support
We understand that organizations operating in regulated environments require additional privacy and security considerations.
Privacy by Minimization
Our data handling philosophy is built around minimizing collection, limiting retention, and supporting customer privacy requirements.
Security Documentation
Assessment documentation, authorization records, and customer documentation are maintained to support assessment workflows.
Customer Agreements
We support authorization documentation, customer agreements, and additional security documentation requirements when necessary.
Protecting Customer Information
Customer information, assessment artifacts, and operational data are handled using security controls designed to reduce unnecessary exposure.
Our approach emphasizes:
- Limited data collection
- Controlled access to customer information
- Encryption of stored assessment data
- Separation between authorization workflows and assessment workflows
- Reduction of unnecessary long-term retention
Trust should be designed into security processes rather than assumed.
Security Is Built On Trust
Organizations authorize us to assess systems, infrastructure, and externally observable assets.
That responsibility requires transparency.
We believe customers should understand what is being assessed, why it is being assessed, and how assessment information is handled throughout the process.
Security Controls
Data Protection
- Encryption at rest and in transit
- Encrypted backup procedures
- Secure key management
- Data segregation by customer
Access Management
- Role-based access control
- Multi-factor authentication
- Principle of least privilege
- Regular access reviews
Operational Security
- Security monitoring and logging
- Incident response procedures
- Vulnerability management
- Security awareness training
Audit & Compliance
- Audit trail maintenance
- Activity logging
- Compliance monitoring
- Regular security assessments
Our Transparency Commitment
Security companies should hold themselves to the same standards they expect from their clients. We're committed to transparency in our operations, data handling, and security practices.
Clear Documentation
Our policies are written in plain language and publicly available for review
Regular Updates
We continuously improve our security practices and update documentation accordingly
Customer Rights
Clear processes for data access, correction, and deletion requests
Responsive Support
Direct contact for security, compliance, and data-handling questions