Swift Vaultgate
// policy

Privacy Policy

Swift Vaultgate · rev. 2019

We only collect personal information that you choose to share with us — your name, email address, and phone number if you contact us, plus whatever details you include in the body of your message. We use that information for one purpose: to write back to you. We do not sell it, lend it, license it, or share it with marketing partners or advertising networks. We store it on the same servers that run this site, kept reasonably long enough to follow up on your inquiry — usually six to twelve months, sometimes longer for orders or projects with open warranty. You may request a copy of everything we hold, ask us to correct mistakes, or have it deleted entirely. Just send a note and we will act on it within thirty days. If you feel we have not handled your data properly, you have the right to lodge a complaint with your local data protection authority.

Engagement evidence and how long it lives

Penetration-test deliverables necessarily contain your vulnerabilities. Reports, raw scan output and exploitation notes are encrypted at rest, shared only through the agreed channel, and destroyed 90 days after report acceptance unless your compliance team asks us to hold them longer. Scoping documents and rules-of-engagement letters are kept for three years as evidence of authorisation.

We do not reuse client findings in marketing, anonymised or otherwise. Sales enquiries that go nowhere are deleted after six months.

Contact for data matters

Swift Vaultgate, 18-6 Miyazakicho, Okazaki City, Aichi 444-3611, Japan — or +81 564-83-2028. Verified subject-access and deletion requests are answered within fourteen days.

Handling of credentials and captured material

Testing sometimes captures credentials, session tokens or fragments of production data. Captured material is treated as radioactive: stored only in the encrypted engagement vault, referenced in the report by redacted example, and destroyed with the rest of the evidence at the 90-day mark. Screenshots in reports are cropped and masked so that the finding is demonstrable without the underlying secret being legible.

Our own staff records — background checks, certification status — are retained for the duration of employment plus three years, as clients' procurement teams routinely require.

Subprocessors and where data physically sits

The engagement vault runs on domestic infrastructure; report drafts never transit consumer file-sharing services. The full subprocessor list is exactly two entries long — the hosting provider and the encrypted-backup provider — both contracted under confidentiality terms reviewed annually, both storing data in Japan. Clients are notified thirty days before any addition to that list, with the right to object before their data touches the new party.

Access inside the firm follows engagement membership: a tester not named on your rules-of-engagement letter cannot open your vault folder, and access logs are reviewed monthly.

Policy revisions

Revisions are dated on this page. Changes affecting how engagement evidence is stored or destroyed are notified to active clients directly, before they take effect. Prior versions are archived for three years.

Recruitment data

CVs from candidates are kept for the hiring round plus six months, then deleted — unless the candidate asks to stay on file for future openings, which is an explicit tick-box rather than a default. Interview notes follow the same schedule. Background-check results are seen by exactly two people and stored separately from the general HR file.

Website enquiry forms

The enquiry form transmits over TLS and lands in the engagement-intake mailbox, which is separate from testing infrastructure. Attachments to enquiries are opened in an isolated environment — a habit from the day job — and enquiry threads that become engagements move into the vault, at which point the mailbox copy is deleted. Enquiries that do not become engagements are purged on the six-month schedule described earlier, attachments included, with the isolated environment wiped between openings. Telephone enquiries are logged as a name, a number and a topic; the notes never include technical detail about a caller's environment until an NDA exists to protect it.