Data Inventory & Classification Policy
About This Document
This policy defines how 7 Minute Security LLC inventories, classifies, and handles data based on its sensitivity. It ensures every piece of data we hold is known, labeled, and protected appropriately.
1. Purpose
You can't protect what you don't know you have. This policy establishes how 7MinSec identifies, inventories, and classifies the data it holds, and defines the handling requirements for each classification level.
2. Scope
This policy applies to all data created, received, processed, stored, or transmitted by 7MinSec, regardless of format (digital or physical) or location (cloud, local, or endpoint).
3. Data Classification Levels
When in doubt, classify data at the higher level. Reclassification requires approval from Brian Johnson (President).
4. Data Inventory
5. Handling Requirements by Classification
Requirements are cumulative. Each level carries every requirement of the levels below it, plus its own.
5.1 Level 1: Public
- No special handling required
- May be freely shared externally
5.2 Level 2: Internal
- Share only with 7MinSec personnel and subcontractors on a need-to-know basis
- Store in 7MinSec-managed systems (productivity suite, cloud file storage)
5.3 Level 3: Confidential
- Access restricted to personnel directly involved in the relevant engagement
- Must be transmitted as expiring, password-protected, encrypted links, never as email attachments
- Must be stored in access-controlled locations (cloud file storage with restricted sharing, the report authoring platform, or cold storage)
- Must be encrypted at rest
- Labeled "CONFIDENTIAL" on documents where practical
5.4 Level 4: Restricted
- Access limited to the minimum number of personnel required
- Client credentials stored exclusively in a dedicated password manager vault and deleted at engagement close
- Raw vulnerability data stored on the report authoring platform (address-restricted), on the self-hosted vulnerability scanning host (network-isolated), or in cloud file storage with strict access controls
- Never transmitted via email under any circumstances
- Never stored on unmanaged or personal devices beyond the duration of active work
- Must be encrypted at rest
- Where transmission is unavoidable, use the same expiring, password-protected encrypted links required at Level 3
- Labeled "RESTRICTED" on all documents
6. Approved Storage Platforms
Storing 7MinSec or client data on unapproved platforms (personal cloud storage, USB drives, personal email, etc.) is prohibited without explicit approval from Brian Johnson (President). Subcontractor data handling obligations are established in the 7MinSec Partnership Agreement and reaffirmed annually via the Subcontractor Security Acknowledgment form.
7. Data Disposal
When data reaches the end of its retention period, it must be disposed of securely:
- Digital files: secure deletion using approved tools (file shredding / verified overwrite)
- Cloud storage: permanent deletion confirmed (emptying trash/recycle bin)
- Credentials: revoked and deleted from the password manager, not just archived
Disposal is logged for Level 3 and Level 4 data.
8. Policy Review
This policy and the data inventory table are reviewed annually, or whenever a new data category, platform, or significant business change occurs. The current version is published in the 7MinSec Trust Center.
Policy Approval
The signed master copy of this policy is maintained in Word format and is available to customers and partners on request.
Change Log
This log records all changes made to this policy over time.
Document Feedback
To suggest changes to this policy or report an issue, contact: security@7minsec.com
Last reviewed: October 2, 2026