Confidentiality Commitment
Last updated:
1. Why this matters
Our clients trust us with sensitive details of their environments, vulnerabilities, and operations. Protecting that information is not a formality; it is central to our work and our reputation. As an official PECB partner, confidentiality and rigor are built into how we engage.
2. What we treat as confidential
We treat as confidential all non-public information disclosed to us in the course of an engagement, including:
- technical details such as architecture, configurations, source code, credentials, and vulnerability findings;
- business information such as strategy, contracts, finances, and personnel;
- personal information handled in accordance with our Privacy Policy and applicable law; and
- the existence and details of the engagement itself, unless disclosure is agreed.
3. How we protect it
- least-privilege access, so information is available only to those who need it for the engagement;
- encryption of confidential data in transit and, where applicable, at rest;
- secure handling and storage practices, with separation between client engagements;
- secure communication channels for sensitive findings rather than general email; and
- documented retention and destruction practices.
4. Our people
Our personnel are bound by confidentiality obligations as a condition of their work with us. We limit access to engagement information to the team members who need it, and we provide guidance on the secure handling of client information.
5. Use and disclosure
We use confidential information only to deliver the engagement. We do not disclose it to third parties except as authorized by you, as required by a service provider under equivalent confidentiality obligations, or as required by law. Where the law compels disclosure, we will, to the extent permitted, inform you so you may seek appropriate protection.
6. Subcontractors
Where we engage subcontractors or service providers, we require them to be bound by confidentiality obligations consistent with this commitment and the applicable engagement agreement.
7. Return and destruction
On completion of an engagement, or at your request, we return or securely destroy confidential information that is no longer required, subject to legal, regulatory, or contractual retention obligations.
8. Incident response
If a confidentiality incident affecting your information occurs, we will act promptly to contain it, investigate, and notify you and the relevant authorities where required by law, in accordance with our obligations under Quebec and Canadian law.
9. Contact
- Risk Core Vision
- Email: contact@riskcorevision.com
- Montreal, Quebec, Canada