369 HERTZ · CREATIVE TECHNOLOGY STUDIORECORD 003 / SECURITY & PRIVACY
Written for your security reviewer.
Everything procurement usually has to ask for, published up front. Anything this page doesn't answer: security@369hertz.com (PGP available).
DPA · SUB-PROCESSORS · QUESTIONNAIRES · SECURITY.TXT
0.0 · IN SHORT
NONE, BY DESIGN
READY TO COUNTERSIGN
PUBLISHED BELOW
5 BUSINESS DAYS
1.0 · DATA WE HANDLE
The engagement model keeps the data surface small: we design and build the interface layer against fixtures and staging environments. We never hold production data.
| CATEGORY | WHAT | WHERE | RETENTION | |
|---|---|---|---|---|
| 1.1 | Contact & contract | Names, work emails, agreements, invoices | Encrypted storage, EU | Relationship + statutory period |
| 1.2 | Project artifacts | Research notes, designs, code, documentation | Your repo + encrypted storage | Transferred or deleted ≤ 90 days after close |
| 1.3 | Research recordings | Session recordings, only with participant consent | Encrypted, access-limited | Deleted ≤ 90 days after synthesis |
| 1.4 | Production data | None. Fixtures and staging only. The boundary is contractual, not aspirational. | — | — |
2.0 · SECURITY POSTURE
Hardware-key MFA on every account. Least-privilege access to client systems, requested per engagement, revoked at close, same day.
Managed, full-disk-encrypted machines with screen locks and automatic updates enforced. No client work on personal devices.
All data encrypted in transit (TLS 1.2+) and at rest. Secrets in a managed vault, never in repositories or documents.
Dependencies pinned and audited. Code reaches your repo through reviewed pull requests only: no direct pushes, no side channels.
Documented response plan. Affected clients notified within 72 hours of a confirmed incident, with a written post-mortem.
Professional liability and cyber coverage held; certificates available on request.
3.0 · DPA & CONTRACTS
Paper that doesn't need a redline round.
Standard terms drafted to pass review as-is. Your paper works too; we've signed plenty of it.
- 3.1Data Processing Agreement (GDPR Art. 28), ready to countersignSTANDARD
- 3.2Standard Contractual Clauses for any cross-border transferINCLUDED
- 3.3Mutual NDA before any product detail is shared, including in the contact formDEFAULT
- 3.4Breach notification within 72 hours, in writingCONTRACTUAL
- 3.5IP assignment on payment: code merged into your repo is yoursSTANDARD
4.0 · SUB-PROCESSORS
The complete list. There is no shadow tooling. Changes are announced 30 days in advance to active clients.
| PROVIDER | PURPOSE | REGION | SAFEGUARD | |
|---|---|---|---|---|
| 4.1 | GitHub | Source code hosting and review | US | DPA + SCCs |
| 4.2 | Google Workspace | Email, documents, video calls | EU-pinned | DPA |
| 4.3 | Hetzner | Encrypted project file storage | EU (DE) | DPA |
| 4.4 | Plausible | Site analytics: cookieless, aggregate only | EU | DPA |
RESEARCH RECORDINGS AND CLIENT ARTIFACTS NEVER TOUCH TOOLS OUTSIDE THIS LIST.
5.0 · VENDOR QUESTIONNAIRES
SIG Lite, CAIQ, and custom questionnaires returned within five business days. A call with your security team is available at no charge during evaluation. Bring the hard questions.
6.0 · REPORTING A CONCERN
security@369hertz.com has its PGP key published alongside /.well-known/security.txt. Good-faith reports acknowledged within one business day.