Security statements should match controls that actually exist.
3 min read
SI publishes only controls that are implemented, assigned, documented, reviewable and capable of being evidenced.
Governing principles
Minimise collection
Ask whether information is required, what purpose it supports, whether less sensitive information can be used, how long it must be kept and who needs access.
Limit access
Grant access according to role, legitimate need, authorised scope and confidentiality. Review access when roles, engagements, suppliers or systems change.
Protect confidentiality
Govern strategy, technical findings, commercial data, stakeholder information and governance records through authorised access, approved storage, secure transfer, contractual confidentiality, controlled reporting, retention and deletion.
Govern suppliers
Understand the provider's purpose, information received, locations, subcontractors, contractual terms, retention, deletion and incident responsibilities.
Govern AI-assisted processing
Confidential or personal information is not submitted to a public generative-AI service unless the use is authorised, the tool is approved, minimisation is applied and appropriate safeguards exist. Human Intelligence remains accountable.
Respond to incidents
Detection containment assessment escalation evidence preservation Legal and regulatory review notification where required recovery learning.
SI does not publish unverified claims concerning encryption, hosting region, data residency, backups, recovery times, penetration testing, certifications, patching, log retention or notification periods.
Trust the control that can be shown, not the claim that sounds reassuring.
"We take security seriously" is not evidence.