Home

How we handle confidential documents

Agree the scope, confidentiality terms and sharing arrangements before sending sensitive material. These arrangements apply across our six services.

On this page

Before documents are shared

Start with a brief description of the work and your confidentiality requirements. The public website form is for initial inquiries. Do not send tender pricing, identity documents, financial records or passwords through it.

We sign an NDA before confidential documents are shared. We agree the document-sharing method and who may receive information for the engagement.

Identify the records the work needs

The scope determines which documents are needed. Share the relevant records through the agreed route.

  • Company registration: ownership, identity and company papers.
  • Vendor registration: credentials, personnel evidence and supporting records.
  • ISO support: management-system documents and relevant evidence.
  • Tender preparation: technical and commercial submissions, including pricing.
  • Corporate websites: approved materials and account permissions.
  • Bookkeeping and filing: financial records and relevant employee or supplier details.

Access during the work

Much of our work is delivered in-house. When a service requires an outside contractor, they sign an NDA. Access arrangements are defined for each engagement. Any submission to a buyer, authority or certification body follows the agreed scope and client approvals.

Keybridge uses Element X for end-to-end encrypted internal communication. Our CRM and internal systems are hosted locally. Two-factor authentication is required on Keybridge systems used for client work.

Erbil is our main branch. Helsinki does not handle client work or client documents.

Our boundary for AI

We use LLMs only with public or non-private information. Internal, secure and private client documents are never uploaded to LLMs.

The website’s external AI links open a generic public prompt. Do not add confidential client information to those external conversations.

Handover and document retention

Storage and retention arrangements must be confirmed in writing for the engagement. They should cover what is returned, what must be retained and why, when access ends, and how working copies and backups are handled.

We do not currently publish a fixed retention period or promise immediate deletion from every system. See Privacy for personal-data handling and requests, and Website terms for engagement boundaries.