Data Security and Confidentiality
1. Controls, Not Claims
“We take security seriously” is not evidence. Search Intelligence publishes only controls that are implemented, assigned, documented, reviewable and capable of being evidenced.
2. Minimise Collection
We ask whether information is required, what purpose it supports, whether less sensitive information can be used, how long it must be kept and who needs access.
3. Limit Access
Access is granted according to role, legitimate need, authorised scope and confidentiality. Access is reviewed when roles, engagements, suppliers or systems change.
4. Protect Confidentiality
Strategy, technical findings, commercial data, stakeholder information and governance records are governed through authorised access, approved storage, secure transfer, contractual confidentiality, controlled reporting, retention and deletion.
5. Govern Suppliers
For every supplier we consider their purpose, the information they receive, their locations, subcontractors, contractual terms, retention, deletion and incident responsibilities.
6. Govern AI-Assisted Processing
Confidential or personal information is not submitted to a public generative-AI service unless the use is authorised, the tool is approved, minimisation is applied and appropriate safeguards exist. Human Intelligence remains accountable.
7. Respond to Incidents
Detection → containment → assessment → escalation → evidence preservation → Legal and regulatory review → notification where required → recovery → learning.
8. What We Do Not Publish
We do not publish unverified claims concerning encryption, hosting region, data residency, backups, recovery times, penetration testing, certifications, patching, log retention or notification periods.
9. Contact
For due-diligence information, contact: diane@seolens.co.za / roelof@seolens.co.za