Information handling
Collect less. Control access. Retain only what the engagement requires.
Executive and corporate intelligence work can involve personal identifiers and sensitive findings. DarkWater’s approach begins with data minimization and a written handling plan—not a promise that any single device, operating system, paper form, or platform is automatically secure.
Executive onboarding
In-person by design for the Executive Concierge Baseline.
DarkWater does not conduct the sensitive executive intake interview by video conference. The preferred process is a private onsite interview at an agreed location, coordinated with the organization’s authorized security or legal lead.
Sponsor Alignment
The organization first provides administrative scope: executive count, locations, program purpose, authorization path, and security contacts.
Private Onsite Interview
The participating executive identifies only the personal emails, aliases, domains, historical identities, and concerns they authorize for the program.
Controlled Profile
Only identifiers necessary for approved monitoring are entered into the working process. Account access secrets are never requested.
Handling principles
Controls are agreed across the full data lifecycle.
Minimum Necessary
Collect only the identifiers and contextual information required for the stated intelligence question.
Named Access
Limit access to the assigned DarkWater professional and specifically authorized client recipients.
Approved Storage
Document the storage, encryption, physical protection, device, and backup requirements appropriate to the engagement.
Controlled Delivery
Agree how urgent alerts, routine reports, sensitive exhibits, and executive briefings will be delivered before findings arise.
Defined Retention
Set retention periods by contract and minimize duplicate copies. Preserve longer only where legally or operationally required.
Documented Closure
Return, archive, or securely destroy client information according to the engagement terms and applicable obligations.
Secure does not mean invisible
A credible program can explain its controls and limitations.
DarkWater will not claim certifications, independent audits, continuous controls, or technical capabilities it has not actually implemented and verified. Client security requirements are evaluated during scoping, and higher-assurance requirements may affect the delivery model, schedule, or price.
Never requested
- Passwords or password hints
- MFA codes or recovery codes
- Session cookies or authentication tokens
- Answers to security questions
- Access to personal email or social accounts
- Unapproved client secrets through the public website
Public contact form
High-level scoping only
The form is delivered using a third-party form service and email. It is suitable for contact information, approximate executive count, onsite city, public company domains, public third-party company names, and a non-sensitive description of the need.
Engagement intake
Established after authorization
Sensitive identifiers, escalation rules, report recipients, retention terms, and technical handling requirements are established only after the client, authority, contract, and scope are confirmed.
Security review
Bring your security requirements into the first scoping conversation.
DarkWater can coordinate with the CISO, security architecture, privacy, legal, procurement, or vendor-risk team designated by the client.
