Information Security & Data Safety Policy
Rigorous technical, cryptographic, and operational safeguards engineered to protect client confidential records, forensic disk images, and strategic workpapers.
1. Clean-Room Workstation & Hardware Hygiene
All advisory analysis, forensic examination, and client deliverable drafting takes place exclusively on hardened, dedicated hardware:
- Hardware Full-Disk Encryption: AES-256 XTS encryption enforced at hardware level across all endpoints (Apple FileVault / BitLocker TPM 2.0).
- FIDO2 Hardware Key Authentication: Passwords are fortified with physical FIDO2/WebAuthn hardware security keys (YubiKey) required for all administrative access.
- Ephemeral Enclaves: Client datasets are segregated in cryptographically isolated enclaves and destroyed upon mandate completion using NIST SP 800-88 sanitization standards.
2. Transport Cryptography & Communications Channels
Data in transit is protected using modern, defensible cryptographic standards:
Enforced TLS 1.3 with Perfect Forward Secrecy (PFS), HSTS with 1-year preload, and strict Content Security Policies (CSP).
Priority client briefings supported via Signal Protocol and WhatsApp Business end-to-end encryption protocols.
3. 72-Hour Breach Notification SLA
In compliance with Article 33 of the UK GDPR and international best practices, in the unlikely event of a verified or suspected security incident involving client confidential information:
4. Digital Forensics & Evidence Chain of Custody
For specialized advisory mandates involving digital investigations and forensic preservation:
- Hardware Write-Blockers: All raw media acquisition utilizes forensic hardware write-blockers to eliminate write-back risks.
- Cryptographic Hashing: Dual SHA-256 and SHA-512 verification hashes are computed immediately at acquisition and re-verified at each handoff.
- Audited Custody Logs: Physical and digital chain-of-custody ledgers document exact timestamps, handler identities, and storage locations.