Institutional policy
Security & data handling
The public boundary, minimum-necessary principles, and controls that must be verified before client data is accepted.
Public boundary
This public site is not a secure upload channel. Never submit protected records, personal financial information, credentials, secrets, or other confidential client material. No public page should expose credentials, provider tokens, private client records, or internal release evidence.
Activation requirements
Before client data is accepted, the exact provider environment must have verified identity and access control, role separation, transport and storage protections, audit logging, backup and recovery, retention and deletion, incident handling, tested export, and rollback evidence. Secure processing is not available through this public website.
Minimum necessary and separation
Each workflow must define the minimum fields, authoritative sources, allowed users, purpose, retention period, and release authority. Public content, tenant data, operator evidence, and credentials remain separated.
Human release and exceptions
Automation may classify, compare, or prepare a queue only within declared inputs. Unsupported, conflicting, stale, or out-of-scope evidence remains blocked until an authorized human resolves or explicitly defers it.
Reporting a concern
Report a suspected vulnerability or data-handling concern to hello@yourdeputy.com with a concise reproduction and no live credentials or protected records. Do not perform destructive testing or access data you do not own.