Policy
Data Handling Policy
Last updated: June 2026
This policy describes how Stealth Layer Security handles client data and engagement artifacts throughout the engagement lifecycle.
Data minimization
We request only the data needed to scope and deliver an engagement. Where possible, testing is performed against environments containing synthetic or de-identified data.
Storage and access
Engagement data is stored in access-controlled systems. Internal access is limited to personnel directly involved in delivering the engagement and is logged where appropriate.
Encryption
Engagement artifacts are encrypted in transit and at rest using current industry-standard mechanisms.
Retention
Engagement artifacts are retained for the period agreed in the engagement contract — typically sufficient to support retesting — and then securely deleted. Retention periods may be shortened or extended by written agreement.
Disposal
When the retention period ends, engagement data is securely deleted from all working systems and any associated backups in line with documented procedures.
Subprocessors
Any subprocessors used to support an engagement are disclosed during scoping and bound by confidentiality obligations consistent with this policy.
Incident handling
Any suspected incident affecting client data is investigated promptly and reported to the affected client in line with the engagement contract.