Data Security & Identity Protection Provisions

1. Identity and access model

Access to your internal customer data is role-based with privileged access management. Human users authenticate individually; platform/headless access (API keys, Agent identities) is tracked and governed separately from human seats, consistent with the actor model described in the Product Data Processing Policy.

2. Least privilege as a working principle

Where our products need write access to a customer's systems (for example, repo write access for auto-instrumentation), that access is scoped to the minimum required for the specific service purchased. This is a security-permissions decision, made independently of what data the access happens to touch — see the Product Data Processing Policy §7 for the fuller explanation of that distinction.

3. Segregation of duties

No single role has unchecked end-to-end control over both data processing configuration and its own oversight.

4. Logging and tamper-evidence

System and access logs are retained for 1 month and protected against undetected modification. (This is the log retention period; it is stated once, here, and is separate from the customer data retention periods in the Product Data Processing Policy §5.)

5. Configuration baseline and drift detection

Production configuration is tracked against a known baseline, with drift flagged rather than silently tolerated.

6. Encryption

Data is encrypted in transit and at rest.

7. Breach notification

In the event of a data breach affecting customer data, we will notify affected customers in line with ICO requirements.

8. Incident response

We maintain an incident response process covering detection, containment, notification, and post-incident review.

9. Patching and vulnerability management

We maintain patching and vulnerability management based on quarterly prioritisation cycles and proactively based on ongoing security monitoring and automated policy adherence on deployment.

10. Certification status — stated accurately

Scout & Swan is progressing toward UKAS ISO 27001 certification. This document reflects the security posture we operate today; it does not claim certification is complete. We'll update this section the moment that status changes.

A note on scope: this document describes how we protect your data where we process it within our services for you.

A note on disclosure: the specific technologies, tools, and configuration parameters that implement the principles in §3, §5, and §6 are maintained explicitly within our internal deployment architecture and codebase — that is where they are required to be explicit, not in this document. They are not published here, and are disclosed only under commercial terms and confidentiality obligations, consistent with how the Product Data Processing Policy (§3) handles the equivalent boundary for its data-object schema. Stating a principle here without naming the underlying method is a deliberate choice, not an omission.

Version 0.1.2