How we protect assessment data

A certification service must protect submissions and its own decisions. This page separates planned safeguards from verified operational facts.

Planned handling

Assessment evidence will get least-privilege access, customer separation, encryption, retention rules, tamper-showing event records and controlled exports. Public reports will carry only authorized fields; detailed evidence will never leak through the registry.

Reporting a concern

A verified security-reporting channel, with response expectations, will be published before the service accepts sensitive submissions. Until then, never send vulnerabilities, credentials or confidential evidence through a general preview form.

No unverified infrastructure claims

We currently claim no Swiss data residence, no particular cloud setup, no certification and no completed penetration test. Processing locations and subprocessors will be stated from deployed facts, with transfer safeguards assessed where they apply.