Privacy Management Policy

How 7 Minute Security collects, uses, protects, and disposes of personal and sensitive information.
Version Effective Approved Last reviewed Owner
1.4 October 2, 2026 October 2, 2026 October 2, 2026 Brian Johnson, President

1. Purpose

7 Minute Security LLC ("7MinSec") takes privacy seriously, not just as a legal obligation, but as a core professional value. As a cybersecurity firm that regularly handles sensitive client information, we are committed to responsible data stewardship. This policy defines how we collect, use, protect, share, and dispose of personal and sensitive information.

2. Scope

This policy applies to all personal and sensitive data collected or processed by 7MinSec in the course of delivering services, and to all personnel, subcontractors, and vendors who access 7MinSec systems or client data.

3. What Data We Collect

Data Category Examples
Client contact information Names, email addresses, phone numbers, job titles
Client technical data IP addresses, network diagrams, system configurations, vulnerability findings
Authentication data Credentials used during authorized penetration tests (never retained after engagement)
Assessment artifacts Raw scan output, screenshots, test notes (retained 60 days, then purged)
Final report deliverables Final assessment reports (retained in cold storage for 3 years)
Business contact data Prospect and client contact details for business communications

4. How We Use Data

7MinSec uses collected data solely for: delivering contracted security services; communicating with clients about engagements and findings; maintaining business records as required by law or contract; and improving our internal processes. We do not sell, rent, or share client data with third parties for marketing or commercial purposes, ever.

5. Data Retention

Data Type Retention Period Disposal Method
Raw assessment data (scans, notes, screenshots) 60 days post-engagement Secure deletion
Credentials used during testing Duration of engagement only Immediate secure deletion upon close
Final report deliverables 3 years in cold storage Secure deletion after 3 years

6. Data Protection Controls

6.1 Access Control

  • Access to client data is restricted to personnel directly involved in the relevant engagement
  • Every account a person signs in to requires MFA, enforced across our productivity, file storage, and all other cloud services
  • Credentials are managed exclusively in an enterprise password manager
  • Our report authoring platform is self-hosted and network-restricted to approved addresses only. It is not accessible from the public internet

6.2 Secure Transmission

  • All report deliverables are transmitted as password-protected, encrypted links that expire after 7 days, never as email attachments
  • Client environment access is conducted exclusively through MFA-protected, zero-trust remote access

6.3 Endpoint Security

  • All endpoints run active malware protection with automatic signature updates, with full-disk encryption enabled and automatic locking after no more than 15 minutes of inactivity
  • Only vendor-supported operating systems and licensed software are used, and a host-based or network firewall is enabled on every endpoint. Patching follows the timeframes set out in Access Management Policy Section 7.1
  • 7MinSec-managed endpoints additionally enforce application allowlisting on a deny-all basis and forward security telemetry to our centralized monitoring platform. Subcontractor-owned devices are covered by perimeter controls instead; see Access Management Policy Section 7

6.4 Data Storage

  • Active engagement data is stored in access-controlled cloud file storage, limited to relevant personnel
  • Report authoring occurs on a self-hosted platform that is not accessible from the public internet. Access is restricted by firewall to approved addresses only
  • Long-term report archives are maintained in cold storage with access logging

Approved storage platforms, and the classification level permitted on each, are listed in our Data Inventory & Classification Policy.

7. Subcontractor Data Handling

Subcontractors engaged by 7MinSec who access client data or systems are required to:

  • Sign a 7MinSec Partnership Agreement prior to engagement, which includes data handling obligations
  • Access internal client environments only through 7MinSec's MFA-protected, zero-trust remote access
  • Handle client data with the same level of care and control 7MinSec applies to its own: devices patched on the timeframes set out in Access Management Policy Section 7.1, a host-based or network firewall enabled, all data held on encrypted media, and all data deleted within the retention periods set out above
  • Report any suspected data exposure or security incident to Brian Johnson (President) immediately

All subcontractors sign a Partnership Agreement setting out confidentiality and data handling obligations. Agreement to this policy and to the wider 7MinSec policy suite is established through the 7MinSec Subcontractor Security Acknowledgment form, signed before engagement and re-signed annually.

7MinSec does not engage subcontractors who cannot demonstrate a baseline security posture consistent with this policy.

8. Data Breach Response

In the event of a confirmed or suspected privacy breach involving client data, 7MinSec will: immediately contain the incident and assess scope; notify affected clients within 72 hours of confirmed breach discovery; document the incident, response actions, and lessons learned; and cooperate fully with any required regulatory notifications. Full incident response procedures are documented in our Incident Response Policy.

9. Individual Rights

Where applicable law grants individuals rights over their personal data, 7MinSec will honor such requests in a timely manner.

10. Compliance

All 7MinSec personnel and subcontractors are required to comply with this policy. This policy aligns with the CIS Controls framework and supports compliance with applicable privacy regulations.

11. Policy Review

This policy is reviewed annually or following any significant change in operations, tools, applicable law, or a privacy-related incident. The current version is published in the 7MinSec Trust Center.

Change Log

This log records all changes made to this policy over time.

Version Date Author Description of Change
1.0 September 1, 2026 Brian Johnson Initial release.
1.1 September 23, 2026 Brian Johnson Corrected Section 7 to describe the subcontractor Partnership Agreement accurately: it sets out confidentiality and data handling obligations, while agreement to this policy is established through the Subcontractor Security Acknowledgment, signed before a subcontractor's first engagement and re-signed annually. Expanded Section 6.3 to distinguish the endpoint controls present on every device from the additional controls carried only by 7MinSec-managed endpoints. Linked the Incident Response and Data Inventory & Classification policies where they are referenced.
1.1.1 September 24, 2026 Brian Johnson Editorial pass ahead of publication: em dashes removed throughout. No requirement changed.
1.2 September 28, 2026 Brian Johnson Incorporated recommendations from an independent policy review against the CIS Controls. Section 6.3 corrects the endpoint protection description to match the Access Management Policy, and adds vendor-supported software, licensing, and firewall requirements. Section 7 restates the subcontractor data handling requirement as a standard of care rather than only a prohibition.
1.3 October 2, 2026 Brian Johnson Independent review of v1.2 completed with no further changes requested, and 7MinSec's own accuracy review completed with no findings. No change to this policy. Version aligned with the rest of the suite.
1.4 October 2, 2026 Brian Johnson Scoped the multi-factor authentication requirement in Section 6.1 to accounts a person signs in to, matching the correction to Access Management Policy Sections 4.2 and 7.1.

Last reviewed: October 2, 2026