Confidentiality and security
Our clients make products that matter. We treat everything they share with us accordingly.
Confidentiality agreements
We sign a confidentiality agreement before receiving any non-public information. We can sign yours or provide ours.
What not to send
Please do not send us:
- classified information of any kind
- technical data your export control authority has not cleared for release
- operational information about deployments, locations or users
- personal data beyond what we need to contact you
If you’re unsure whether something is appropriate, ask before sending it.
How we handle your files
- Files are exchanged through an encrypted shared folder, not email attachments, wherever possible.
- Files are stored in encrypted storage with access limited to the people working on your project.
- Work devices use full-disk encryption and multi-factor authentication.
- We do not upload client technical information to public tools or services that retain it.
Retention and deletion
We keep source materials only for as long as the project requires. Unless you ask us to keep them for future updates, we delete source files within 30 days of final delivery and confirm deletion in writing on request.
Naming clients
We never name a client, publish their work or refer to it in our marketing without written permission.
If something goes wrong
If we become aware of any unauthorised access to client information, we will notify the affected client within 72 hours with what we know and what we are doing about it.
Security questions can be sent to security@datumdefencegroup.com.
Last updated September 2026.