Scope
WriteChoice provides technical documentation services. In delivering them, personnel may handle API specifications, product documentation, pre-release product information, and access to client documentation repositories and sandbox environments. WriteChoice does not require or accept access to client production systems, cardholder data, or end-customer personal data. Any engagement that would require such access is scoped separately, with additional controls agreed in writing before work starts.
Personnel
In these policies, "personnel" means all WriteChoice employees and contractors. Every person must read these policies and confirm acceptance at onboarding and once a year.
1.1 Roles and responsibilities
- Security Officer: owns these policies, approves exceptions, coordinates incident response, and reviews the policies yearly.
- Project leads: request and remove client access for their engagement, and confirm that their team follows these policies.
- All personnel: follow these policies, protect client information, and report suspected incidents immediately to security@writechoice.io.
1.2 Information classification
| Class | Examples | Handling |
|---|---|---|
| Client Confidential | API specs, pre-release product information, repository and sandbox access, client credentials | Approved tools only; access limited to the assigned engagement team; never shared outside the engagement |
| Internal | Internal processes, pricing, team information | Approved company tools; not shared publicly |
| Public | Published documentation, marketing content | No restrictions |
All material received from a client is Client Confidential unless the client says otherwise.
1.3 Acceptable use
- Client information is stored and processed only in approved company tools (listed in 1.6).
- Client information is never stored in personal accounts, personal cloud storage, or personal email.
- Client credentials and keys are stored only in the company password manager, never in documents, chat messages, or repositories.
- Personnel do not share client information with anyone outside the engagement team without the client's permission.
- Personnel lock their screen when they step away and do not work on client material on shared or public computers.
1.4 Endpoint security
Personnel work remotely on their own computers. Any device used to access or process client information must meet this baseline:
| Control | Requirement |
|---|---|
| Disk encryption | Full-disk encryption enabled (FileVault on macOS, BitLocker on Windows) |
| Anti-malware | Built-in anti-malware enabled and up to date (XProtect on macOS, Microsoft Defender on Windows) |
| Patching | Automatic operating system and security updates enabled; critical updates installed within 14 days of release |
| Supported OS | Operating system version still receiving security updates from the vendor |
| Screen lock | Automatic lock after no more than 10 minutes of inactivity, password or biometric to unlock |
| Firewall | Operating system firewall enabled |
Each person confirms compliance in writing at onboarding and once a year. Devices that do not meet the baseline may not be used for client work. A lost or stolen device is reported as a security incident (section 4).
1.5 AI and LLM tools
- The only AI tool approved for client material is Claude by Anthropic, used through WriteChoice's Claude Team account. Each client has its own Claude project, so client material is never mixed between clients and can be deleted in one place.
- Under Anthropic's commercial terms, inputs and outputs from the business account are not used to train models. Claude conversations and projects that contain client material are deleted at the end of the engagement, within the 30 days set in section 1.7.
- Personal or consumer AI accounts (for example free or personal paid plans of any AI tool) must never be used with client material.
- Personnel do not paste client credentials, secrets, or personal data into any AI tool.
- A writer reviews and edits every AI-assisted output before delivery.
1.6 Third-party tools and sub-processors
Client material may be processed only in these approved tools:
| Provider | Purpose | Location |
|---|---|---|
| Google Workspace | Email, file storage, documents | United States |
| Slack | Internal and client communication | United States |
| Notion | Project management and notes | United States |
| GitHub | Documentation source code | United States |
| Anthropic (Claude) | AI-assisted writing and review | United States |
| Fireflies.ai | Meeting recording and transcription, with participant consent | United States |
| 1Password | Storage of credentials | United States |
A new tool that will process client material requires approval from the Security Officer and is added to this list before use.
1.7 Data retention and return
When an engagement ends, or when a client asks, the project lead completes this checklist within 30 days:
- Remove all personnel access to the client's repositories, sandbox environments and tools (section 2.3), and ask the client to disable any accounts it created.
- Delete the client's Claude project and every Claude conversation containing client material.
- Return or delete client files held in Google Workspace, Notion and GitHub, keeping only what the contract allows WriteChoice to keep.
- Delete meeting recordings and transcripts of the client's calls from Fireflies.ai.
- Delete the client's credentials from the password manager.
- Ask personnel to delete any local copies of client material from their devices.
- Record the completion date, and confirm completion to the client in writing on request.
1.8 Exceptions and enforcement
Exceptions require written approval from the Security Officer, with a reason and an end date. Breaches of these policies may lead to removal of access and termination of the contract.
