Skip to content
Secure Data Vault

Where sensitive client data lives.

An encrypted, access-governed, fully-audited store for the sensitive data every engagement necessarily touches, the firm’s own embodiment of its data-security philosophy.

Protected data pathPolicy enforced
Governed intakeEngagement artefacts
Findings packageClassified
Client evidenceRestricted
Access materialEphemeral
Custody stateProtection travels with the data
IdentityBound
AccessTemporary
EvidenceImmutable
Encryption at rest and in transitManaged keysComplete access history
Data as the perimeter

Protect the data, not merely the place it rests.

A breach of the defender is the one incident from which there is no recovery.

Every security engagement necessarily touches sensitive data, the very findings, credentials, and client information that, if mishandled, would turn the firm from a defender into a liability. The Secure Data Vault is the firm’s answer to that existential risk, and the literal embodiment of the principle it sells: protect the data, not merely the place it rests.

Everything within it is encrypted at rest and in transit, reachable only through least-privilege, time-boxed access, and recorded in an immutable audit trail. Sharing is done through governed, expiring links, never an attachment that escapes the boundary. It is the quietest product in the suite, and the one on which all the others depend.

Custody lifecycle

Protection begins before storage and survives every movement.

The vault treats custody as a continuous control: context enters with the artefact and remains attached until governed deletion.

ReceiveA governed channel accepts the artefact without exposing it to email or local storage.01
ClassifySensitivity, engagement, owner, and retention context are attached immediately.02
SealEncryption and managed keys protect the data before it becomes available.03
GovernEvery view, share, download, and deletion remains attributable and reviewable.04
Four custody controls

The quiet product every other surface depends on.

Protection control

Encrypted by default

At rest and in transit, with key management that does not silently undermine the cryptography.

Protection control

Least-privilege access

Only the right people, only for as long as they need it.

Accountability control

Immutable audit

Every access to every artefact, recorded and reviewable.

Accountability control

Governed sharing

Time-boxed, access-controlled links, never an unguarded attachment.

Least privilege

Access is a temporary condition, never a permanent convenience.

Permission is evaluated against identity, engagement, artefact, purpose, and time. When any part expires, the route closes without relying on someone to remember.

WhoVerified identity and roleWhyNamed engagement purposeHow longExplicit access window
Access decisionEvaluation complete
IdentityReviewer / verifiedScopeEngagement NL-284ResourceEvidence packageDuration45 minutes
DecisionGRANT · TIME-BOXED
Immutable audit

Every consequential action leaves a durable record.

The audit trail is part of the protection model, not an administrative afterthought. It answers who, what, when, why, and under which policy.

Event timeActionContextState
08:42:11Artefact sealedEngagement / NL-284Verified
09:03:28Access grantedReviewer / 45 minTime-boxed
09:31:06Evidence viewedFinding / F-019Recorded
09:48:44Share link revokedExternal recipientClosed
Chain integrityAll events linked and verifiedAppend-only
Technical foundation

Built so convenience cannot silently weaken custody.

01Encryption at rest & in transit02Least-privilege access control03Immutable audit trail04Time-boxed signed sharing links05Secrets in a managed vault
Secure custody

The discipline behind every other product.

See how sensitive engagement data remains encrypted, governed, attributable, and intentionally temporary.