SecAgent™ may collect information submitted through contact, intake, payment-verification, and security-assessment workflows, including contact details, organization information, authorized target information, and security evidence.
Information is used to respond to inquiries, scope services, deliver assessments, maintain audit records, improve services, and meet legal or contractual obligations.
Clients should not submit production passwords, private keys, or unnecessary sensitive data through general contact forms. Dedicated credentials for authorized testing should be delivered through an approved secure process.
Production deployments should define retention periods for assessment evidence, client records, logs, and reports according to contractual and legal requirements.
Client security information should not be sold. Disclosures may occur to service providers necessary to deliver the service, when authorized by the client, or when legally required.
This policy is a starter template and should be customized to actual SecAgent data practices and reviewed by qualified counsel before production use.