Security Policy v0
Scope
This policy describes BEL Advisory’s baseline security practices for advisory work, client material, and digital working systems.
Access
Client material is handled with access limited to the engagement purpose. Devices and accounts used for client work should use strong authentication and reasonable access controls. Where a client provides a secure workspace, BEL Advisory can use that workspace where practical.
Data handling
Files are organized by engagement and kept separate from unrelated client work. Sensitive files should be shared through appropriate channels rather than public links or uncontrolled email chains. Public or generic examples should not include confidential client details.
Tools and service providers
BEL Advisory may use reputable professional tools for email, document creation, file storage, coding, automation, AI-supported work, and business administration. Where a tool processes client or personal data, BEL Advisory considers the purpose, sensitivity, and available contractual/security controls.
Incident handling
If BEL Advisory becomes aware of unauthorized access, loss, or disclosure affecting client information, Brian will assess the situation and inform affected clients without undue delay where notification is appropriate.
Changes
This is version v0. Future material changes will be published as a new version at a new stable URL.