Back to websiteSummit Strategy Consulting
SECURITY / CONFIDENTIALITY

Data Security & Confidentiality Policy

Effective: August 9, 2025Annual review: August 9, 2026Next scheduled review: August 9, 2027

Remote technical support may require temporary access to business systems and non-public information. This policy describes a least-access, practical security approach while recognizing that the client retains responsibility for its systems, users, legal obligations and long-term security program.

IMPORTANT CONTEXT

Federal Trade Commission business guidance emphasizes data minimization, sensible access controls, secure authentication, protection of sensitive information and planning for security incidents. The practices described here follow those general principles without representing a formal certification or managed security program.

1. Purpose and scope

This policy describes practical security and confidentiality principles for remote IT consulting and support. It applies to information received through business communications, project records and authorized technical access to client-controlled systems.

2. Data minimization

Access to information should be limited to what is reasonably necessary for the agreed task. Unrelated business records should not be intentionally inspected or copied merely because they are technically accessible during support.

3. Least-privilege access

Where a platform permits it, client access should be granted at the lowest privilege level reasonably sufficient for the task. Temporary roles, scoped invitations or separate support accounts are preferable to unnecessary sharing of a primary administrator credential.

4. Authentication

Strong passwords and multi-factor authentication should be used where supported by the relevant platform and appropriate to the account. Authentication methods remain subject to the controls and limitations provided by the third-party vendor.

5. Credential handling

Clients should avoid sending passwords, private keys, recovery codes or other sensitive credentials through ordinary website forms. Where credentials are necessary, an appropriate secure sharing method should be used and access should be changed or revoked after the engagement when practical.

6. Remote connections

Remote access should use reputable tools and encrypted connections provided by the relevant service or platform. The client should confirm the identity of the person receiving access and avoid granting persistent remote control when it is not required.

7. Client-controlled information

Business data stored inside a client’s systems remains under the client’s ownership or control, subject to the client’s agreements with its own providers. Technical access does not transfer ownership of that information.

8. Confidentiality

Non-public client information learned during an engagement should be treated as confidential and used only for legitimate service purposes. Information may be disclosed only where the client authorizes it, a service provider reasonably needs it to perform an authorized function, or disclosure is otherwise required or permitted by law.

9. Service providers

Website hosting, email, cloud storage, payment processing, accounting and productivity services may involve third-party providers. Security for those systems depends partly on the provider’s controls and the configuration selected by the business. Provider access should be limited to services reasonably needed for business operations.

10. Secure configuration

Reasonable configuration practices may include current software versions, appropriate permissions, authentication controls, secure sharing settings, removal of unused access, backup configuration and review of obvious security warnings. The exact safeguards depend on the platform and the agreed scope.

11. Backups

Important data should be backed up according to the client’s operational needs. A backup configuration should not be treated as reliable solely because it was created; status, storage capacity, retention and recovery should be reviewed periodically where continuity is important.

12. Retention and deletion

Temporary access and unnecessary technical information should be removed when no longer needed for the engagement. Business records may be retained where reasonably necessary for accounting, project history, legal obligations, security, dispute resolution or other legitimate operational purposes.

13. Incident awareness

If an obvious security incident is discovered while performing authorized work, the client should be informed within the reasonable scope of the engagement. A general support engagement does not automatically include forensic investigation, breach notification analysis or regulated incident-response services.

14. Breach response limitations

Security incidents may trigger legal, contractual, insurance or notification obligations that depend on the affected data and jurisdiction. Clients should obtain appropriate legal or specialist advice when an incident involves sensitive personal information, regulated data or material business impact.

15. Employee and contractor access

Clients remain responsible for determining which employees, contractors and administrators should have access to their systems. User accounts should be changed or removed when roles change or access is no longer needed.

16. Physical security

Remote consulting does not control the physical security of the client’s offices, devices, networking equipment or paper records. Clients should maintain appropriate physical safeguards for devices and locations that contain important information.

17. No absolute security guarantee

Reasonable safeguards reduce risk but cannot guarantee that a system will never be compromised. Security depends on people, devices, software, vendors, networks and evolving threats, including factors outside the control of a remote consultant.

18. Annual review

This policy is scheduled for review once each year on August 9 and may be updated earlier if the service model, commonly used technology, security practices or legal requirements materially change.

Summit Strategy ConsultingRemote IT consulting and technology support