Contact information here. Assessment evidence somewhere else.
The public website is a consultation channel, not a client evidence repository.
Before evidence is accepted
LeftOut Security and the client must have accepted written scope, authorization, evidence-handling terms, responsible contacts, system boundaries, and an approved transfer channel. Evidence is not requested merely because a consultation request was sent or a meeting occurred.
Minimize by default
Use redacted, synthetic, test, or least-sensitive evidence whenever it can answer the question. Prefer configuration excerpts, diagrams, guided walkthroughs, targeted logs, and narrowly scoped exports over broad repositories, production datasets, or unrestricted accounts.
Do not provide by default
- Passwords, private keys, API keys, session tokens, or recovery codes.
- Full production datasets, payment-card data, or unnecessary customer records.
- Unrestricted cloud, model-provider, repository, or administrator access.
- Evidence outside the accepted system, period, and decision boundary.
- Information you are not authorized to share.
Access controls
When access is explicitly required, it should be read-only where practical, least-privileged, time-bounded, attributable, and revocable. Testing permissions, stop conditions, and prohibited actions must be written before access begins.
Use, disclosure, and retention
Evidence is used only for the accepted engagement and handled according to the written terms. The engagement defines approved systems, subprocessors where applicable, retention, return or deletion, and any required residual records.
If evidence is sent through the wrong channel
Stop sending additional material and contact security@leftoutsecurity.com. Identify the message or transfer without repeating the sensitive contents.