Skip to main content
Trust & Compliance

Security & Compliance

Documented authorization, data minimization, access control, and evidence-handling practices for organizations with rigorous security requirements.

Our Trust Pillars

Privacy First

SunTzu Security Labs follows data minimization principles designed to reduce unnecessary collection and retention of customer information. We do not sell customer information and only collect information necessary to perform authorized assessments, support customer relationships, and deliver assessment results.

  • No data sales or marketing lists
  • Minimal collection approach
  • Purpose-limited data use
  • Transparent data practices

Data Retention

Assessment artifacts, findings, and supporting data are retained only as long as operationally necessary or required to support ongoing customer relationships. Our retention philosophy is simple: Retain only what is necessary, encrypt stored assessment information, reduce long-term exposure by limiting unnecessary retention, and remove assessment data when it is no longer required operationally or contractually. Security data should not exist forever simply because it can.

  • Retain only what is necessary
  • Encrypt stored assessment information
  • Reduce long-term exposure
  • Remove data when no longer required

Authorization Requirements

Authorized assessments are fundamental to our process. Assessment activities occur only against explicitly approved targets following scope validation, ownership verification, and authorization procedures. We believe trust begins with clear boundaries.

  • Required Letters of Authorization
  • Documented consent process
  • Scope verification procedures
  • Legal compliance checks

Compliance Support

We support organizations operating under major compliance frameworks and regulatory requirements

Regulated-Environment Support

Regulated-Environment Support

We understand that organizations operating in regulated environments require additional privacy and security considerations.

Privacy by Minimization

Privacy by Minimization

Our data handling philosophy is built around minimizing collection, limiting retention, and supporting customer privacy requirements.

Security Documentation

Security Documentation

Assessment documentation, authorization records, and customer documentation are maintained to support assessment workflows.

Customer Agreements

Customer Agreements

We support authorization documentation, customer agreements, and additional security documentation requirements when necessary.

Protecting Customer Information

Customer information, assessment artifacts, and operational data are handled using security controls designed to reduce unnecessary exposure.

Our approach emphasizes:

  • Limited data collection
  • Controlled access to customer information
  • Encryption of stored assessment data
  • Separation between authorization workflows and assessment workflows
  • Reduction of unnecessary long-term retention

Trust should be designed into security processes rather than assumed.

Security Is Built On Trust

Organizations authorize us to assess systems, infrastructure, and externally observable assets.

That responsibility requires transparency.

We believe customers should understand what is being assessed, why it is being assessed, and how assessment information is handled throughout the process.

Security Controls

Data Protection

  • Encryption at rest and in transit
  • Encrypted backup procedures
  • Secure key management
  • Data segregation by customer

Access Management

  • Role-based access control
  • Multi-factor authentication
  • Principle of least privilege
  • Regular access reviews

Operational Security

  • Security monitoring and logging
  • Incident response procedures
  • Vulnerability management
  • Security awareness training

Audit & Compliance

  • Audit trail maintenance
  • Activity logging
  • Compliance monitoring
  • Regular security assessments

Our Transparency Commitment

Security companies should hold themselves to the same standards they expect from their clients. We're committed to transparency in our operations, data handling, and security practices.

Clear Documentation

Our policies are written in plain language and publicly available for review

Regular Updates

We continuously improve our security practices and update documentation accordingly

Customer Rights

Clear processes for data access, correction, and deletion requests

Responsive Support

Direct contact for security, compliance, and data-handling questions

Questions About Our Security Practices?

Our security team is available to answer questions about compliance, data handling, and security controls