Least data, least time
I collect only the data an engagement genuinely needs, keep it only as long as the work requires, and return or destroy it on close. Scoping favors read-only and scoped access over standing credentials.
Trust Center
A security practice should be able to show its own posture, not just audit yours. This is an honest account of how TechJavelin — a boutique, principal-led practice — protects client data, produces defensible evidence, and works inside the frameworks my clients answer to.
Posture & practices · not a badge wall
TechJavelin is a solo, senior-only practice. I don’t claim certifications the practice doesn’t hold or imply a compliance program sized for a hundred-person firm. What follows is how I actually operate. Formal artifacts — a security summary, my data-handling terms, and reference material — are available to active and prospective clients on request.
Data handling
Least data, least time
I collect only the data an engagement genuinely needs, keep it only as long as the work requires, and return or destroy it on close. Scoping favors read-only and scoped access over standing credentials.
Encryption in transit & at rest
Client material is exchanged over encrypted channels and stored encrypted at rest. Findings, evidence, and reports move through controlled channels — never a public link or an unmanaged inbox thread.
Segregation by client
Each engagement’s data is kept logically separated. Nothing from one client is reused, cross-referenced, or exposed to another, and sensitive artifacts are access-controlled to the engagement.
Return & disposal
At the end of an engagement, deliverables are handed over and working data is disposed of on a defined timeline. Retention beyond that happens only where you ask for it, in writing.
Evidence
The output of the work is built to survive an auditor’s scrutiny — because that’s usually the point of the work.
Every finding ties back to what was tested, when, and how — so it stands up as evidence, not assertion. Reporting is layered for executive, technical, and compliance readers.
Engagements follow a documented, repeatable method. For recurring assurance clients, results are comparable engagement-to-engagement so posture drift is visible over time.
Test evidence and deliverables are versioned and attributable, with a clear record of what was produced and shared — useful directly as audit evidence in SOC 2 and similar programs.
Frameworks
Fluency in the control sets my clients are measured against. I help you meet these — and I hold my own practices to the spirit of them.
SOC 2
Evidence-backed testing and reporting that feeds directly into Trust Services Criteria audits.
NIST 800-171
Protecting Controlled Unclassified Information for suppliers in the defense and aerospace supply chain.
CMMC
Readiness and control implementation for Cybersecurity Maturity Model Certification levels.
HIPAA
Safeguards and incident-response practices for teams handling protected health information.
ISO 27001
Information-security management alignment for organizations standardizing on ISO controls.
Naming a framework means I work within it on client engagements and align my own handling to its intent. It is not a claim that TechJavelin holds that certification.
On request
Regulated buyers shouldn’t have to take posture on faith. If you’re evaluating or already working with me, ask and I’ll share the relevant documentation directly.
How client data is accessed, stored, transmitted, and disposed of across an engagement.
Confidentiality commitments, scope-of-access constraints, and mutual expectations before any work begins.
Anonymized examples of method, evidence traceability, and the reporting you’d receive.
Trust Center
Ask for the security summary and data-handling terms. Send the request async — I’ll get the right documents to you by email personally.
Request the documents