Global Active Key-Person Risk Brief

How Your Data Moves Through the Engagement

A temporary, single-client workflow using approved records, encrypted handling, SSH-managed isolated cloud infrastructure, authenticated edge access, a dedicated workspace for named users, source-cited deliverables, and written deletion confirmation.

1client
at a time
1

Scope and authority

  • Client signs data authority before records move.
  • Custodians, systems, date range, and file types are approved in writing.
  • Client terms define legal, HR, medical, privileged, and regulated categories.
2

Secure AWS upload

  • We provide an expiring, engagement-specific AWS upload page.
  • Upload the approved ZIP without adding encryption or a password. Transfer and storage are encrypted.
  • Integrity is verified. Upload receipt is not written acceptance.
3

Encrypted workbench

  • Received records remain in the encrypted AWS engagement workspace.
  • Protected identifiers are masked before any AI processing.
  • Ingest, extraction, normalization, and indexing stay inside the engagement workspace.
4

Verified analysis

  • AI-augmented retrieval runs through Amazon Bedrock, grounded only in approved records, with account data retention set to none.
  • After masking, sensitive topics are classified. Written ALLOW/BLOCK rules govern analytical use; approval never restores always-masked identifiers.
  • Claims, quotes, and citations are checked against source material.
  • Reports are reviewed before delivery; there is no required per-email adjudication process.
5

Protected workspace

  • Temporary single-client AWS workspace, protected by Cloudflare Access.
  • Up to three named recipients get authenticated access for the agreed period, normally 30 days after delivery.
  • Source context is Screen-safe but not category-redacted; BLOCK prevents analytical use.
  • The destruction date is stated at delivery. Final confirmation follows verified deletion and required access/infrastructure removal; pending actions are reported separately.
Authority checked
Hash verified
Vault only
Citations reviewed
Deletion confirmed
STOP

Sensitive material stops here — not your engagement.

Screening automatically redacts, excludes, or quarantines legal, HR, medical, privileged, investigation, and other sensitive categories. Excluded material is never analyzed, and the work continues. It is included only if your data authority directs it in writing.

Handled inside the engagement Upload steps, access, and records are arranged privately within the engagement, not on this public site.
Controlled engagement storage Client records and working results stay in the encrypted AWS engagement environment until authorized closeout, outside code repositories and contentless audit records.
Bedrock no-retention path The required retention setting is checked at each governed provider launch. Model-service no-retention is distinct from temporary engagement storage; client records are not used to train AI models.
Time-boxed, named access Workspace access is temporary, authenticated, and limited to named users.
US-region pipeline Storage, processing, and the client workspace run in United States AWS regions.
Deletion confirmed in writing Final confirmation states actual verified completion after data deletion and required access/infrastructure removal. A scheduled deletion is not a completed deletion.