Security & Trust
Security consultancies should be able to answer the questions they ask everyone else. This page describes how NeoSecGov handles your data.
Client data handling
We collect the minimum information needed for an engagement, and client materials stay in the engagement, not in marketing. Anything sensitive (architecture documents, audit evidence, credential scopes) is shared through agreed channels, accessed on a least-privilege basis, and deleted or returned at the end of the engagement on request.
Confidentiality
We sign NDAs before reviewing client environments, and we never name a client publicly, in a case study, or on this site without written permission.
Access and accounts
Client environment access is scoped, time-bound, and read-only wherever the work allows. We use multi-factor authentication on our own accounts, and we ask clients to grant access through their own identity provider so they keep the audit trail and can revoke it instantly.
Our own tooling
The practice runs on a small, vetted set of tools (HubSpot for this site and scheduling, hardened cloud accounts for engagement work). We apply the same posture we recommend: MFA everywhere, least privilege, logging on, and no client data in AI tools without the client's explicit agreement.
Reporting a concern
If you believe you have found a security issue with this website or with how we have handled information, contact [EMAIL]. We respond to good-faith reports and appreciate them.