Diagnostic
"We take security seriously" is not evidence.

Security statements should match controls that actually exist.

3 min read

SI publishes only controls that are implemented, assigned, documented, reviewable and capable of being evidenced.

Review the Privacy Policy

Governing principles

Minimise collection

Ask whether information is required, what purpose it supports, whether less sensitive information can be used, how long it must be kept and who needs access.

Limit access

Grant access according to role, legitimate need, authorised scope and confidentiality. Review access when roles, engagements, suppliers or systems change.

Protect confidentiality

Govern strategy, technical findings, commercial data, stakeholder information and governance records through authorised access, approved storage, secure transfer, contractual confidentiality, controlled reporting, retention and deletion.

Govern suppliers

Understand the provider's purpose, information received, locations, subcontractors, contractual terms, retention, deletion and incident responsibilities.

Govern AI-assisted processing

Confidential or personal information is not submitted to a public generative-AI service unless the use is authorised, the tool is approved, minimisation is applied and appropriate safeguards exist. Human Intelligence remains accountable.

Respond to incidents

Detection containment assessment escalation evidence preservation Legal and regulatory review notification where required recovery learning.

SI does not publish unverified claims concerning encryption, hosting region, data residency, backups, recovery times, penetration testing, certifications, patching, log retention or notification periods.

Trust the control that can be shown, not the claim that sounds reassuring.

"We take security seriously" is not evidence.