Privacy, security and quality belong in the scope of the engagement. Our public policies set the standards; the actual requirements and supporting evidence are considered for the work.
Information must have a defined, authorized purpose. Our policies restrict unnecessary collection, unrelated reuse and access outside the engagement. Client personal information is not available for independent ADCO model training, unrelated datasets, advertising or licensing. The full notices explain processing roles, international access, retention criteria and individual rights.
Security requirements are established for the engagement, including permitted access, approved systems and information handling. Our standards call for individual accounts, supported multi-factor authentication, appropriate confidentiality obligations and role-specific preparation. Qualification, work locations, devices and the boundaries of a person's authority must be addressed before access begins.
The Information Security Policy covers authorization, credentials, devices, approved tools, storage, transfer, logging and controlled changes. Proposed work must be assessed against its information and system requirements. Requests for assurance should identify the intended scope so the relevant obligations and available evidence can be considered through an appropriate exchange.
Quality starts with task instructions and acceptance criteria that reflect the intended result. Our policy establishes requirements for qualification, calibration, review, correction and authorized release. Objectives and review coverage have stated conditions. Managed delivery and staff augmentation allocate responsibilities differently, as defined by the engagement.
The Code of Ethics establishes standards for voluntary work, fair treatment, pay, working hours, safety, truthful records and reporting concerns without retaliation. These standards also inform relevant supplier and subcontractor requirements. The complete Code describes responsibilities and corrective action; it does not represent an independent audit of employment practices.
Our incident and continuity policy defines requirements for assessment, containment, evidence, communication and controlled recovery. Engagement arrangements need actual contacts, responsibilities and dependencies. Required notification and recovery commitments follow applicable law and agreement; any assurance about an exercise or tested capability must be supported by the relevant record.