Trust Center Sign in
Sign inContact us
Human-led security service

Data Security Assessments

Trace material data flows and evaluate protection, access, lifecycle, residency, and third-party boundaries.

What we evaluate

Scope the decision before testing the control.

Trace material data flows and evaluate protection, access, lifecycle, residency, and third-party boundaries. Scope, access, evidence sources, and safety conditions are agreed before work begins.

01

Authorize

Confirm objectives, owners, scope, access, and stop conditions in writing.

02

Evaluate

Gather and test evidence using practices appropriate to the agreed environment.

03

Validate

Review observations, uncertainty, business context, and practical remediation priorities.

04

Brief

Deliver decision-ready findings, owners, dependencies, and recommended next actions.

What you receive

Evidence your team can act on.

Deliverable

Data inventory and flows

Documented for decision-making, ownership, and follow-through.

Deliverable

classification

Documented for decision-making, ownership, and follow-through.

Deliverable

access

Documented for decision-making, ownership, and follow-through.

Deliverable

cryptography

Documented for decision-making, ownership, and follow-through.

Deliverable

retention

Documented for decision-making, ownership, and follow-through.

Deliverable

deletion

Documented for decision-making, ownership, and follow-through.

Deliverable

monitoring and dependency observations

Documented for decision-making, ownership, and follow-through.

Standards-informed approach

Recognized practices, applied to the engagement.

References guide the method and evidence boundary. They do not make this engagement an accredited audit, certification, legal opinion, or formal PCI validation.

Reference

NIST SP 800-53 and Privacy Framework

Used to structure applicable scope, evidence, and recommendations—not to assert certification or compliance.

Reference

ISO/IEC 27001, 27002, 27018 and 27701

Used to structure applicable scope, evidence, and recommendations—not to assert certification or compliance.

Reference

PCI DSS 3 and 4 conditionally

Used to structure applicable scope, evidence, and recommendations—not to assert certification or compliance.

Reference

OWASP ASVS data protection

Used to structure applicable scope, evidence, and recommendations—not to assert certification or compliance.

Customer-authorized by design

Start with the outcome and scope.

Our services are human-led, customer-authorized engagements. The Spacetime platform remains purely defensive.

Assess data security