Policy
Data handling
The operating boundary for project information, confidential material, and third-party systems.
Last updated: August 7, 2026
This page describes the default operating posture for Crusoe Advisory LLC. Project-specific written terms control when they are more restrictive.
Collection and purpose
Only information needed to evaluate or perform an agreed project should be collected. Project data is used for the stated analysis, deliverables, validation, and administration. Client data is not used to train public or third-party general-purpose models.
Transfer and access
Do not send sensitive files through ordinary email. Before transfer, the parties should agree on the approved system, authorized people, permitted data classes, and deletion trigger. The selected provider must show that it encrypts data in transit and at rest, or the transfer must not proceed.
Public tools
The site has no public upload endpoint. When a public tool uses local browser storage, that storage is identified inside the tool and a clear-data control is provided. Local browser storage is not encrypted by Crusoe Advisory and should not be used for credentials, personal data, regulated information, export-controlled material, or confidential production details.
Subcontractors and AI providers
Subcontractors and AI providers must not receive client material unless their role, access, contractual protections, and retention behavior have been reviewed for the project. Sensitive identifiers should be removed or minimized before any approved processing.
Retention and deletion
Unless project terms say otherwise, working copies should be deleted within 30 days after final delivery and backups should age out within 90 days. Legal, accounting, dispute, or security requirements may require limited records to be retained longer. A client may request deletion, subject to those obligations.
Security incidents
Suspected unauthorized access, disclosure, loss, or material corruption will be investigated promptly. Affected clients will be notified without unreasonable delay when an incident materially affects their information, together with known scope and containment steps.
Questions
Review the security posture and email brian@crusoeadvisory.com before sending any non-public data.