2. Information Covered
The following are considered confidential information, among others:
- Network architecture, topology and asset inventory;
- Credentials, tokens, cryptographic keys and system secrets;
- Identified vulnerabilities and developed exploits;
- Personal data of employees, clients or third parties present in the systems;
- Source code, intellectual property and trade secrets;
- Technical and executive reports produced during the project;
- Financial, strategic and operational information accessed incidentally;
- The existence, nature and outcome of the engagement itself.
We collect and store only the data strictly necessary to execute the agreed scope. Incidentally accessed data (e.g. database records, employee emails) is documented in the report as evidence of criticality, not copied for use beyond the engagement.
3. Handling of Sensitive Data
Evidence, artifacts and client data are stored in encrypted environments (AES-256), isolated from other projects, with access restricted to the team members assigned to the specific engagement. Reports and sensitive materials are transmitted over encrypted channels (email with PGP, secure links with automatic expiration); we never send vulnerability reports by unencrypted email or platforms without access control. Remote access to client systems is performed through a dedicated VPN or a jump server provisioned by the client, with multi-factor authentication, and all accesses are logged and reported at the end of the engagement.
4. Team and Subcontractors
Every Nocera InfoSec® professional with access to client information is bound by: an individual NDA with a non-compete and post-employment non-disclosure clause; annual training in information security and data protection; and access restricted to the minimum necessary (least privilege principle).
When specialized subcontractors are used, we sign specific bilateral NDAs before any involvement. Nocera InfoSec® remains fully liable to the client for the fulfillment of confidentiality obligations by subcontractors.
5. Data Destruction
At the end of the engagement and after the client has received and accepted the deliverables:
- All raw evidence, captured data, credentials and artifacts are securely deleted (7-pass overwrite or media destruction, per NIST SP 800-88);
- Provisioned accesses (test accounts, VPN, jump server) are revoked immediately;
- The client receives written confirmation of data destruction within 5 business days of completion;
- Only the signed final reports are retained, for the period defined in the Privacy Policy.
6. Responsible Disclosure
In the event of discovering zero-day vulnerabilities in third-party products during an engagement: the client is notified immediately; Nocera InfoSec® waits for the agreed remediation period (usually 90 days); the vendor is notified confidentially, without identifying the client; after the fix or once the period has elapsed, Nocera may publish a technical advisory without mentioning the client. Any publication or presentation is subject to the client's prior authorization when there is a risk of identification.
7. Term
Confidentiality obligations take effect upon signing the NDA or the Commercial Proposal and remain in effect for 5 years, covering trade secrets, credentials, personal data and vulnerabilities not publicly disclosed by the client.
8. Breach of Confidentiality
In the event of a breach of confidentiality by Nocera InfoSec® (e.g. a leak due to negligence): the client will be notified within 24 hours of our becoming aware of the incident; we will take reasonable measures to contain the leak; we will fully cooperate with the investigation and any regulatory notification; and we will assume the responsibilities provided for in the contract and in the applicable legislation.