> ## Documentation Index
> Fetch the complete documentation index at: https://irisdocs.prescientlabs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Iris Security & Privacy

> Explain the current security and privacy posture accurately without improvising commitments that have not been approved.

Security questions are normal in consulting engagements involving employee evidence and operational data.

## Current baseline

The currently established product context includes:

* hosting on Microsoft Azure for the secure Iris environment;
* Azure services used for application hosting, storage, search and Azure OpenAI / Foundry capabilities;
* UK-region hosting for the current secure deployment;
* Cyber Essentials Plus certification;
* consent-based participant workflows for interviews and screen observation.

## Consultant rule

Use approved Prescient wording for:

* retention;
* deletion;
* subprocessors;
* backup and disaster recovery;
* client-hosted deployment options;
* exact regional data residency;
* security response commitments.

If the current answer is not established, use **\[PRODUCT DETAIL TO CONFIRM]** rather than guessing.

## Client-friendly positioning

> Iris is used as part of a defined consulting engagement to collect and analyse relevant process evidence. We scope the data required, communicate participant use clearly and work within the approved security and privacy arrangements for the engagement.

## Escalate appropriately

Complex procurement, legal or security questionnaires should be answered using approved company material rather than ad hoc consultant wording.
