Global Active Key-Person Risk Brief
How Your Data Moves Through the Engagement
A temporary, single-client workflow using approved records, encrypted handling, SSH-managed isolated cloud infrastructure, authenticated edge access, a dedicated workspace for named users, source-cited deliverables, and written deletion confirmation.
1client
at a time
at a time
1
Scope and authority
- Client signs data authority before records move.
- Custodians, systems, date range, and file types are approved in writing.
- Client terms define legal, HR, medical, privileged, and regulated categories.
2
Client-controlled transfer
- Client IT provides the secure transfer site or approved channel.
- Archive is encrypted before upload; passphrase is sent separately.
- SHA-256 hash is verified and a receipt manifest is created.
3
Encrypted workbench
- Records are downloaded directly into an encrypted engagement vault.
- Malware scan and sensitive-material screen run before analysis.
- Ingest, extraction, normalization, and indexing stay inside the engagement workspace.
4
Verified analysis
- AI-augmented retrieval runs through Amazon Bedrock, grounded only in approved records, with account data retention set to none.
- Claims, quotes, and citations are checked against source material.
- Human review happens before any client deliverable is released.
5
Protected workspace
- Temporary single-client AWS workspace, protected by Cloudflare Access.
- Up to three named recipients get authenticated access for follow-up questions, for 30 days after delivery.
- Everything is destroyed on the written destruction date, with confirmation to your team.
Authority checked
Hash verified
Vault only
Citations reviewed
Deletion confirmed
STOP
Sensitive material stops here — not your engagement.
Screening automatically redacts, excludes, or quarantines legal, HR, medical, privileged, investigation, and other sensitive categories. Excluded material is never analyzed, and the work continues. It is included only if your data authority directs it in writing.
Handled inside the engagement Upload steps, access, and records are arranged privately within the engagement, not on this public site.
Records stay in the vault Client records, secrets, and engagement data live only in the encrypted vault, kept out of code, repositories, and screenshots.
Bedrock no-retention path Approved record text is processed through Amazon Bedrock with account data retention set to none; prompts and outputs are not shared with model providers or used to train base models.
Time-boxed, named access Workspace access is temporary, authenticated, and limited to named users.
US-region pipeline Storage, processing, and the client workspace run in United States AWS regions.
Deletion confirmed in writing After hosted access and workspace materials are removed, your team receives written confirmation.