Skip to main content
SurfaceShield Logo
SurfaceShield

Privacy Policy & Data Handling

LAST REVISED: OCTOBER 2024 • STRICT DATA MINIMIZATION STANDARD

1. Data Minimization Principle

SurfaceShield Security adheres to strict data minimization practices. We collect and retain only the minimal technical information necessary to schedule, execute, and document authorized external security exposure assessments.

We do not sell, rent, monetize, or trade client information, contact details, or assessment findings under any circumstances.

2. Information Collected Via Inquiries

When you submit a scoping inquiry through our website, we collect your name, business name, corporate email address, primary domain name, and operational notes. This information is used exclusively to evaluate your requested security assessment scope and prepare an assessment proposal.

3. Treatment of Assessment Findings & Evidence

All technical evidence, network captures, HTTP headers, screenshots, and findings gathered during an authorized assessment are classified as Strictly Confidential.

  • Evidence is stored on encrypted storage with access restricted strictly to the principal consultant.
  • Reports are delivered directly to authorized client contacts via encrypted channels.
  • No assessment data is ever shared with third-party advertising networks or external data processors.

4. Mandatory 60-Day Data Destruction

Following the conclusion of an engagement and any included verification re-testing, all raw HTTP responses, evidence captures, and internal notes are scheduled for permanent cryptographic deletion after 60 calendar days.

5. Contact Regarding Confidentiality

For questions concerning our data retention procedures or to request an expedited certificate of data destruction, please contact our contact page.