PILOT-STAGE SECURITY & DATA HANDLING

Least data.
Visible controls.

This is a pilot-stage control statement, not a certification claim. Final commitments belong in the signed services agreement and data-processing addendum.

Control principles

Transfer, storage, and isolation

Use client-controlled secure exchange, an approved data room, or encrypted files with the password transmitted separately. Store each client’s pilot data in a logically separated workspace, restrict access to assigned personnel, maintain an access inventory, and remove access when the pilot closes.

AI use

Retention and deletion

The default pilot target is deletion of client source data within 30 days after final acceptance unless the agreement requires a different period. Only the minimum engagement record needed for legal, billing, and agreed support obligations is retained.

Incident handling

  1. Contain the event and preserve relevant evidence.
  2. Notify the client’s named security contact without undue delay under the contract.
  3. Document affected systems, data categories, dates, and corrective actions.
  4. Revoke or rotate affected credentials and links.
  5. Complete a written post-incident review.

Certification status

MarginChef does not claim SOC 2, ISO 27001, PCI DSS, HIPAA, or another third-party certification unless and until that certification is actually obtained and can be evidenced. The 30-day pilot should be treated as a restricted, read-only analytics engagement with contract-specific controls.

Review the pilot scope →