> ## Documentation Index
> Fetch the complete documentation index at: https://irisdocs.prescientlabs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Privacy Brief

> High-level client-facing guidance on responsible use of Iris during a consulting diagnostic.

Iris is used to support evidence-led consulting diagnostics. Participant communication, appropriate consent and responsible handling of client information are part of the engagement design.

## Current baseline

Prescient Labs' secure Iris environment is hosted on Microsoft Azure, with the current secure deployment in UK South. Prescient Labs has achieved Cyber Essentials Plus.

## Participant evidence

Stakeholder interviews and screen observation should be introduced transparently. Screen observation is consent-based and should only be used where it is appropriate to the engagement.

## Data minimisation

The consulting team should request only the information needed to answer the agreed diagnostic question. Sensitive or unnecessary information should not be collected simply because it is available.

## Human validation

Iris supports analysis; consultants remain responsible for validating findings and applying professional judgment before recommendations are presented.

## Engagement-specific details

The following must be confirmed against the current product and contractual setup before external use:

* **\[PRODUCT DETAIL TO CONFIRM]** retention/deletion periods;
* **\[PRODUCT DETAIL TO CONFIRM]** precise subprocessor wording;
* **\[PRODUCT DETAIL TO CONFIRM]** client-specific data residency;
* **\[PRODUCT DETAIL TO CONFIRM]** approved security questionnaire responses.

For formal security review, use the current Prescient Labs security documentation rather than relying on this short guide alone.
