Overview
Controls
Applies to everyone working on client materialAccess control
- Two-factor authentication enforced
- Company password manager
- Least-privilege access per client engagement
- Access removed within 2 business days of leaving a project
- All access revoked within 1 business day of leaving WriteChoice
- Quarterly access reviews, recorded
Endpoint security
- Full-disk encryption (FileVault / BitLocker)
- Automatic OS updates, critical patches within 14 days
- Built-in anti-malware enabled (XProtect / Defender)
- Supported OS, firewall on, screen lock within 10 minutes
- Device compliance attested at onboarding and annually
Data security
- Client material kept only in approved tools
- No client material on personal accounts
- Client credentials only in the password manager
- Data returned or deleted within 30 days of engagement end
Secure delivery
- Docs-as-code in the client's repository
- Peer-reviewed pull requests for every change
- No secrets or customer data in repositories
- Sandbox environments only, never production
- Placeholder values in every code sample
AI governance
- Single approved provider (Anthropic Claude)
- Company Claude Team account only, no personal accounts
- Client data not used for model training
- One Claude project per client, deleted at engagement end
- Human review of every AI-assisted output
Incident response
- Documented incident response procedure
- Client notification within 72 hours
- Post-incident review within 10 business days
Sub-processors
Third parties that may process client material| Provider | Purpose | Location |
|---|---|---|
| Google Workspace | Email, file storage, documents | United States |
| Slack | Internal and client communication | United States |
| Notion | Project management and notes | United States |
| GitHub | Documentation source code | United States |
| Anthropic (Claude) | AI-assisted writing and review | United States |
| Fireflies.ai | Meeting recording and transcription, with consent | United States |
| 1Password | Storage of credentials | United States |
Resources
Read the full text onlineFAQ
Do you hold SOC 2 or ISO 27001 certification?
Not currently. We complete client security questionnaires and publish our security policies on this site, so your team can review our controls directly.
Do you use AI on our content?
We use Claude by Anthropic, through our company's Claude Team account, to speed up drafting and review. Each client has its own Claude project, and a writer reviews and edits every AI-assisted output.
Will Anthropic use our data to train its models?
No. Under Anthropic's commercial terms, which cover our Claude Team account, inputs and outputs are not used to train models. Personal AI accounts are not allowed for client material.
How long do you keep our data?
Only while we work together. Within 30 days of the end of an engagement, we remove our access to your systems, delete your Claude project and conversations, delete call recordings, and return or delete your files.
Do you need access to our production systems?
No. We work in documentation repositories and sandbox or test environments. We never need production access, cardholder data or end-customer personal data.
What devices does your team use?
Our team works remotely on their own devices. Every person who handles client material must use full-disk encryption, built-in anti-malware, automatic updates, a supported operating system, an active firewall and screen lock, and confirms this in writing at onboarding and every year.
How do we report a security concern?
Email security@writechoice.io. If your information is affected by an incident on our side, we notify you within 72 hours of confirmation.
