WriteChoice

Information Security Policy

WriteChoice protects the confidentiality and integrity of client information by limiting where it lives, who can reach it, and which devices and tools may process it.

Version 1.0 Effective September 2026 Owner Security Officer (COO) Review At least once a year Contact security@writechoice.io

Scope

WriteChoice provides technical documentation services. In delivering them, personnel may handle API specifications, product documentation, pre-release product information, and access to client documentation repositories and sandbox environments. WriteChoice does not require or accept access to client production systems, cardholder data, or end-customer personal data. Any engagement that would require such access is scoped separately, with additional controls agreed in writing before work starts.

Personnel

In these policies, "personnel" means all WriteChoice employees and contractors. Every person must read these policies and confirm acceptance at onboarding and once a year.

1.1 Roles and responsibilities

  • Security Officer: owns these policies, approves exceptions, coordinates incident response, and reviews the policies yearly.
  • Project leads: request and remove client access for their engagement, and confirm that their team follows these policies.
  • All personnel: follow these policies, protect client information, and report suspected incidents immediately to security@writechoice.io.

1.2 Information classification

ClassExamplesHandling
Client ConfidentialAPI specs, pre-release product information, repository and sandbox access, client credentialsApproved tools only; access limited to the assigned engagement team; never shared outside the engagement
InternalInternal processes, pricing, team informationApproved company tools; not shared publicly
PublicPublished documentation, marketing contentNo restrictions

All material received from a client is Client Confidential unless the client says otherwise.

1.3 Acceptable use

  • Client information is stored and processed only in approved company tools (listed in 1.6).
  • Client information is never stored in personal accounts, personal cloud storage, or personal email.
  • Client credentials and keys are stored only in the company password manager, never in documents, chat messages, or repositories.
  • Personnel do not share client information with anyone outside the engagement team without the client's permission.
  • Personnel lock their screen when they step away and do not work on client material on shared or public computers.

1.4 Endpoint security

Personnel work remotely on their own computers. Any device used to access or process client information must meet this baseline:

ControlRequirement
Disk encryptionFull-disk encryption enabled (FileVault on macOS, BitLocker on Windows)
Anti-malwareBuilt-in anti-malware enabled and up to date (XProtect on macOS, Microsoft Defender on Windows)
PatchingAutomatic operating system and security updates enabled; critical updates installed within 14 days of release
Supported OSOperating system version still receiving security updates from the vendor
Screen lockAutomatic lock after no more than 10 minutes of inactivity, password or biometric to unlock
FirewallOperating system firewall enabled

Each person confirms compliance in writing at onboarding and once a year. Devices that do not meet the baseline may not be used for client work. A lost or stolen device is reported as a security incident (section 4).

1.5 AI and LLM tools

  • The only AI tool approved for client material is Claude by Anthropic, used through WriteChoice's Claude Team account. Each client has its own Claude project, so client material is never mixed between clients and can be deleted in one place.
  • Under Anthropic's commercial terms, inputs and outputs from the business account are not used to train models. Claude conversations and projects that contain client material are deleted at the end of the engagement, within the 30 days set in section 1.7.
  • Personal or consumer AI accounts (for example free or personal paid plans of any AI tool) must never be used with client material.
  • Personnel do not paste client credentials, secrets, or personal data into any AI tool.
  • A writer reviews and edits every AI-assisted output before delivery.

1.6 Third-party tools and sub-processors

Client material may be processed only in these approved tools:

ProviderPurposeLocation
Google WorkspaceEmail, file storage, documentsUnited States
SlackInternal and client communicationUnited States
NotionProject management and notesUnited States
GitHubDocumentation source codeUnited States
Anthropic (Claude)AI-assisted writing and reviewUnited States
Fireflies.aiMeeting recording and transcription, with participant consentUnited States
1PasswordStorage of credentialsUnited States

A new tool that will process client material requires approval from the Security Officer and is added to this list before use.

1.7 Data retention and return

When an engagement ends, or when a client asks, the project lead completes this checklist within 30 days:

  1. Remove all personnel access to the client's repositories, sandbox environments and tools (section 2.3), and ask the client to disable any accounts it created.
  2. Delete the client's Claude project and every Claude conversation containing client material.
  3. Return or delete client files held in Google Workspace, Notion and GitHub, keeping only what the contract allows WriteChoice to keep.
  4. Delete meeting recordings and transcripts of the client's calls from Fireflies.ai.
  5. Delete the client's credentials from the password manager.
  6. Ask personnel to delete any local copies of client material from their devices.
  7. Record the completion date, and confirm completion to the client in writing on request.

1.8 Exceptions and enforcement

Exceptions require written approval from the Security Officer, with a reason and an end date. Breaches of these policies may lead to removal of access and termination of the contract.