Information Security Policy

1. Purpose and scope

This policy summarizes the security program of Peck Stelzer Systems LLC for our compliance file-review product (the "Service") and the customer data it touches. Detailed technical commitments for a given customer are set out in that customer's signed agreement.

2. Architecture and isolation

3. Data handling

4. Access control

5. Encryption

Data in transit to hosted deployments is protected with TLS 1.2 or higher. Data at rest in hosted environments is encrypted using platform-managed encryption. Local deployments inherit the customer's at-rest controls, and we document recommended configurations.

6. AI processing safeguards

7. Secure engineering

8. Incident response

Suspected security incidents are assessed and contained promptly. We notify affected customers without undue delay, consistent with their agreements and applicable law, and provide the information they need for their own obligations.

9. Vendors

Third-party providers are reviewed before use and limited to the roles listed in our Privacy Policy. Providers who could touch customer data must meet retention and confidentiality requirements consistent with this policy.

10. Personnel and review

Everyone with access to customer data is bound by confidentiality obligations. This policy is reviewed at least annually and upon material changes to the Service. Questions: our contact page.