aisecurity.llc
hello@aisecurity.llc
Operational Policy · Negotiation Draft
Launch Gate Evidence Handling Policy
Evidence handling, retention schedule, destruction obligations, and redaction requirements for launch-gate review evidence. Governs working notes, correspondence, and system artifacts.
This document describes how findings, artifacts, and working materials created during an AI Launch Security Review engagement are captured, stored, retained, redacted, and destroyed. Final binding terms are set in the executed version of this Policy.
1. Purpose
The Evidence Handling Policy ensures that findings and artifacts from the Launch Security Review are handled in a way that protects the customer's confidential information, limits unnecessary exposure of security vulnerabilities, and produces outputs that are appropriate for the customer's intended use of the deliverables.
2. What Constitutes Evidence
For purposes of this Policy, "evidence" includes:
- Technical notes, screenshots, and working session artifacts from the review
- Vulnerability findings, abuse-path notes, and reproduction steps
- Draft and final deliverables: Launch Risk Memo, Abuse-Path Findings, Release Gate Checklist, Sprint Backlog, Buyer-Ready Evidence Summary
- Correspondence between aisecurity.llc and the customer containing system or finding details
3. Capture
Evidence is captured in the minimum form necessary to support finding documentation and deliverable production. aisecurity.llc does not capture, store, or retain:
- Customer credentials, API keys, or secrets encountered during review (if inadvertently disclosed, aisecurity.llc will notify the customer immediately)
- Personally identifiable information (PII) of end users unless explicitly authorized in the Data Processing Addendum
- Customer source code beyond excerpts necessary to document specific findings
4. Storage
Working evidence is stored in aisecurity.llc's internal systems during the active review period. Access is limited to the aisecurity.llc reviewer(s) assigned to the engagement. Evidence is not shared with third parties.
5. Retention Schedule
| Category | Retention period |
|---|---|
| Final deliverables (customer copy) | Customer retains; no aisecurity.llc copy after delivery |
| Internal working notes and draft findings | 90 days after engagement close |
| Correspondence containing system details | 90 days after engagement close |
| Abuse-path reproduction steps | Deleted within 30 days of deliverable acceptance |
Customer may request earlier deletion of internal working materials. aisecurity.llc will confirm deletion in writing within 10 business days of the request.
6. Redaction
Deliverables delivered to the customer are pre-redacted by aisecurity.llc to remove any credentials, tokens, PII, or third-party system details that were inadvertently captured during review. Customer is responsible for reviewing deliverables and requesting further redaction before sharing externally.
7. Customer Handling of Deliverables
Customer is responsible for the handling, storage, access control, and external distribution of the deliverables it receives. The following guidelines apply:
- Buyer-Ready Evidence Summary and public-facing excerpts must be reviewed under the Assessment Terms Addendum (Section 6) before external distribution
- Abuse-Path Findings are for internal security and engineering use; not for external publication without redaction and claim review
- The Release Gate Checklist and Sprint Backlog are internal operational documents
8. Breach or Inadvertent Disclosure
If aisecurity.llc discovers that evidence has been inadvertently disclosed or accessed outside the scope of this Policy, aisecurity.llc will notify the customer within 48 hours and describe the nature, scope, and remediation steps taken.
9. Relationship to Other Agreements
This Policy is read in conjunction with the Mutual NDA and the Assessment Terms Addendum. In the event of conflict regarding evidence handling, this Policy governs.
This is a summary of key terms for planning and discussion. The executed Evidence Handling Policy governs. This document does not constitute legal advice.