Credentials & access tokens
Use an agreed transfer method, limit to the required purpose and plan rotation or withdrawal when access is no longer needed.
Client administrators retain account responsibilities unless agreed otherwiseDataConsultant approaches confidential client information as an engagement responsibility that should be defined before transfer, limited to an approved purpose, accessed on a need-to-know basis, exchanged through agreed channels and addressed deliberately at project close.
This page describes a general confidentiality approach for due diligence. Binding obligations, technical measures and retention requirements are established through applicable law, signed agreements and approved engagement documentation.
Confidentiality risk is not limited to deliberate disclosure. It can arise through excessive access, unapproved tools, unnecessary copies, unclear ownership, cross-project exposure, remote-working practices or incomplete closure.
A structured approach reduces ambiguity for legal, procurement, security, privacy and delivery teams.
The exact definition comes from the applicable contract. In data, analytics and AI work, confidentiality can span technical, commercial, personal and proprietary material.
This illustrative matrix supports scoping discussions. The client’s classification policy and signed engagement terms take precedence.
| Illustrative level | Examples | Handling consideration | Access / sharing decision | Closure decision |
|---|---|---|---|---|
| Public | Published webpages, approved marketing material, public datasets | Normal business handling; source, licence and release status still matter | Confirm that publication or onward use is authorised | Follow ordinary record or project requirements |
| Internal | Non-public drafts, routine project notes, internal operating information | Limit to relevant project participants and approved channels | Define whether external or onward sharing is permitted | Remove obsolete access and unnecessary working copies |
| Confidential | Client datasets, code, roadmaps, architecture, financials, reports | Need-to-know access, controlled exchange and defined workspace | Specify tools, locations, recipients and permitted purpose | Apply agreed return, deletion or retention treatment |
| Highly restricted | Production credentials, sensitive personal data, trade secrets, regulated records | Additional controls or client-hosted work may be required before transfer | Narrow access; confirm legal, security and contractual conditions first | Document access removal and any retained dependency or obligation |
Illustrative only. This page does not assert a universal DataConsultant classification standard or a fixed control set for every engagement.
Useful due diligence connects the business purpose to concrete decisions about information, people, systems, contracts and evidence.
Start with scope, classifications, contractual requirements and environment choices. Then agree how confidential material can enter the engagement.
The signed agreement remains controlling. This matrix shows common responsibility areas for a data, analytics or AI engagement.
| Area | Client | DataConsultant | Technology provider / other third party | Shared review |
|---|---|---|---|---|
| Classification Sensitivity and restrictions | Defines client classifications, restrictions and authority to disclose | Uses supplied classification and engagement requirements to shape handling | Provides platform capabilities and contractual conditions relevant to use | ✓ Confirm categories before material access |
| Access Accounts and permissions | Approves client-system access and removes obsolete access where client controlled | Seeks access appropriate to assigned responsibilities and approved work | Operates underlying identity or platform controls where provider managed | ✓ Review changes in role, phase or scope |
| Environment Repositories and tools | Identifies required or prohibited platforms and client-hosted environments | Uses agreed delivery environments and avoids unapproved destinations | Provides infrastructure or product capabilities according to its service | ✓ Clarify logging, backup, storage and admin responsibilities |
| Contract NDA, IP and confidentiality | Provides client-specific legal and procurement requirements | Reviews proposed terms and works within agreed obligations | May impose separate service terms, licences or data-use conditions | ✓ Resolve conflicts before sensitive work begins |
| Closure Return, retention, disposal | Provides instructions and removes client-managed permissions | Addresses close-out actions within agreed responsibilities | May retain provider-controlled backups or records under separate terms | ✓ Record outstanding dependencies and ownership |
The diagram is a conceptual assurance model—not a representation of one fixed DataConsultant production architecture.
The right handling pattern depends on the asset, sensitivity, environment, contract and work being performed.
Use an agreed transfer method, limit to the required purpose and plan rotation or withdrawal when access is no longer needed.
Client administrators retain account responsibilities unless agreed otherwiseDefine repository access, contribution workflow, branch permissions and where code may be copied or processed.
Separate client code from reusable non-client materialUse only the information reasonably required for the agreed work and consider masking, sampling, aggregation, synthetic data or client-hosted analysis where practical.
Minimise unnecessary production-data exposureAlign model artefacts, prompts, evaluation results and derived insights with approved tools, data classifications, ownership terms and client instructions.
AI use should not bypass confidentiality restrictionsLimit strategic, financial, operational and project documents to relevant contributors and approved exchange channels.
Audience and onward sharing should be explicitWhere work occurs in a client environment, handling should follow the agreed account, logging, network, change and access model.
Do not imply control of provider- or client-operated infrastructureQuestions about permitted disclosure, suspected mishandling, compelled disclosure or scope changes should be routed for review rather than resolved informally.
Record the information, event or requested disclosure.
Limit further sharing or access where appropriate and authorised.
Review contract, client instructions, legal context and affected systems.
Involve the relevant client, legal, privacy, security or delivery stakeholders.
Document decisions, remediation and any required process change.
Retention and disposal decisions depend on contracts, client instructions, legal or operational obligations, ownership and technology dependencies. This page does not claim a universal retention period.
Different reviewers need different evidence depths. Some information can be public; other material may require relevance review, confidentiality terms or client-specific discussion.
Use the Trust Team route to explain the decision your organisation needs to make. Avoid sending sensitive evidence in the initial message.
Confidentiality decisions can become stale as an engagement evolves. Review points should follow meaningful changes rather than rely on one initial approval.
Confidentiality overlaps with—but does not replace—security, privacy, secure delivery and formal due-diligence review.
These answers support initial review. Engagement-specific requirements should be confirmed through the appropriate contractual and technical process.
Provide the proposed scope, information categories, delivery environment, stakeholders and review requirements. The Trust Team can help identify the contractual and operational questions that need resolution.
Do not include confidential data, credentials, private keys, source code, personal information or proprietary documents in an initial contact message.