Confidentiality & Data Handling
How we handle transaction data before, during and after an engagement — stated plainly, because you are trusting us with material non-public information.
Discuss a deal Engagement modelsNDA before data
No transaction data moves until a non-disclosure agreement is executed. We will sign yours; we do not require you to sign ours first.
- Mutual NDA executed before any file is shared or any system access granted.
- Named individuals. Only team members assigned to your engagement receive access, and we tell you who they are.
- Least privilege. Access limited to the data required for the scope, removed when the engagement closes.
- No downstream sharing. Your data is never used for another client, a case study, or a marketing example without written permission.
Practical controls
- Secure intake. Data received through your data room or a secure link — not email attachments.
- Segregated storage. Each engagement kept in its own access-controlled workspace.
- Device controls. Encrypted disks, screen locks, no working from personal unmanaged devices.
- Documented deletion. On closure, working files are deleted or returned on your instruction, and we confirm it in writing.
- Named point of contact. One senior person accountable for the engagement's data handling.
What we do not claim
We hold no SOC 2 or ISO 27001 certification today. Rather than imply otherwise, we would rather tell you exactly what our controls are so you can assess them against your own requirements. If your procurement process requires a certified supplier, say so early and we will tell you honestly whether we can meet it.
Frequently asked questions
Will you sign our NDA?
Yes. We work under the client's NDA as standard and do not insist on our own paper.
Where is our data stored?
In an access-controlled workspace segregated per engagement. We will confirm the specific location and provider on request before you share anything.
What happens to our data after the engagement?
Working files are deleted or returned on your instruction and we confirm completion in writing. We retain nothing beyond what you agree to.
Do you use client data to train AI tools?
No. Client transaction data is never used to train models. Our automation operates on your data within the engagement and nothing leaves it.
Security questions before you engage?
Ask them now — we would rather answer in detail up front.
Book a consult Get the data-request listOr email abhishek.bhandari@zionadvisor.com directly.
