Confidentiality & Data Policy

Discretion is not
a feature.
It is the foundation.

Clients share sensitive operational, financial, and geopolitical information with SISG because the work demands it. This document sets out precisely how that information is protected — not as a legal formality, but as a professional obligation central to what SISG is.


"Every engagement at SISG begins and ends with discretion. We do not confirm client relationships, discuss mandate scope, or share findings outside the explicit terms of a signed engagement. This is non-negotiable and applies to every member of our team and associate network."

Section 01

Client Confidentiality — Core Commitments

SISG's foundational confidentiality commitments apply automatically to all client relationships from the moment of first contact — before any contract is signed.

01.1
No Disclosure of Client Identity

SISG does not confirm, reference, or disclose the existence of any client relationship — past, present, or prospective — to any third party, without explicit written consent from the client.

01.2
No Disclosure of Mandate Scope or Findings

The nature, scope, and outputs of any engagement are strictly confidential. Findings, assessments, reports, briefings, and analytical products produced for a client belong exclusively to that client and are never shared, referenced, or adapted for any other purpose.

01.3
Default Confidentiality Before Signature

Confidentiality obligations apply from the first substantive communication, including discovery calls and preliminary consultations. No formal agreement is required for SISG to treat information shared in these interactions as confidential.

01.4
No Cross-Mandate Information Transfer

Information shared within one client mandate is never used to inform, supplement, or cross-reference another. Each engagement is fully compartmentalised. SISG does not operate a shared intelligence pool across clients.

Section 02

Data Handling & AI Usage

SISG uses AI tools to augment intelligence collection and analysis. The following rules govern how client data interacts — or does not interact — with these systems.

02.1
Client Data Is Never Used to Train AI Models

No client information — including documents shared, questions asked, or mandate context provided — is ever submitted to external AI systems in ways that could contribute to model training. SISG takes active steps to ensure this in all AI tool usage.

02.2
AI-Processed Data Remains Under SISG Control

Where AI tools are used to process, structure, or analyse information related to a mandate, all outputs remain within SISG's operational environment. They are not accessible to the AI service provider and are deleted upon mandate closure unless retention is explicitly agreed.

02.3
Secure Communications Available on Request

Clients requiring encrypted communications channels — including end-to-end encrypted messaging, PGP-secured email, or secure file transfer — can request this at engagement initiation. SISG supports client-specified security protocols where operationally feasible.

02.4
Retention and Deletion

Client documents and mandate-related data are retained only for the duration required to deliver the engagement, plus any legally mandated period thereafter. Upon request, SISG will confirm deletion of client-provided materials within 30 days of mandate closure.

Section 03

Associate & Network Confidentiality

03.1
All Associates Bound by NDA

Every member of SISG's associate and specialist network is bound by a Non-Disclosure Agreement before any access to client information. Associates receive only the information necessary for their specific contribution to a mandate — nothing more.

03.2
Need-to-Know Access Control

SISG operates a strict need-to-know principle. Associates are not informed of client identity unless operationally necessary, and are not briefed on the full scope of a mandate beyond their assigned deliverable.

03.3
Post-Mandate Obligations

Confidentiality obligations for both partners and associates survive the end of any engagement indefinitely. There is no expiry on SISG's commitment to protecting client information.

Section 04

Client-Initiated Confidentiality Agreements

Clients frequently operate under their own confidentiality frameworks. SISG accommodates these without friction.

04.1
Client NDA Review and Signature

Where clients prefer to govern the engagement under their own Non-Disclosure Agreement, SISG will review and sign client-provided NDAs as standard practice. We do not impose our own template as a precondition of engagement.

04.2
Mutual Confidentiality Available

For engagements where both parties share sensitive information, SISG can execute mutual NDAs that protect both the client's information and SISG's methodologies, source frameworks, and proprietary analytical tools.

Standard Documentation

SISG maintains standard Non-Disclosure Agreement templates for client engagements and associate onboarding. These are available on request prior to any substantive discussion. Contact engagements@sisg.net to receive them.

Questions

Confidentiality questions or specific requirements?

If your organisation has specific data handling, classification, or security requirements that go beyond this policy, contact us before initiating an engagement. We will confirm in writing what SISG can accommodate.

Contact SISG