Trust & Security
How PBW Professional Services protects confidential engagement information, client environments, and sensitive data throughout the consulting lifecycle.
PBW treats all client data, system configurations, architecture details, and engagement specifics as confidential by default. This commitment applies from the first discovery call through engagement close, and governs how we handle every piece of information we encounter. We are prepared to work under your NDA, MSA, or both — from day one if required.
PBW does not require a separate confidentiality onboarding phase. All client-facing information — including system architecture, workflow designs, compliance rule configurations, integration specifications, vendor relationships, and operational details — is treated as confidential regardless of whether a formal NDA has been executed. Where a client NDA or data-processing agreement exists, PBW operates strictly within its stated scope.
PBW does not use client information for marketing, case studies, or reference purposes without explicit written consent. Client names, firm details, engagement scope, and operational information are never disclosed to prospective clients or third parties.
If you require a specific confidentiality term, right-of-deletion provision, or data-handling constraint, PBW will document those requirements in the engagement agreement before work begins.
During an engagement, PBW may require access to client systems — typically Bloomberg AIM administration, Charles River IMS configuration, reference data feeds, compliance rule engines, order-routing infrastructure, or development/testing environments.
Access model:
Access termination should be coordinated as part of the engagement close process. PBW will confirm credential return or destruction upon client request.
Project artifacts — including requirements documents, architecture diagrams, configuration workbooks, test scripts, SOWs, meeting summaries, and deliverable files — are not shared through consumer-grade cloud services, public file shares, or unsecured portals.
Exchange channels:
If your organization has a preferred secure file exchange method, indicate it during engagement scoping — PBW will accommodate your existing infrastructure and protocols.
During UAT, parallel-run phases, and system configuration work, PBW may work with sample data or data extracted from client systems. Data handling follows these principles:
If your compliance, legal, or information-security team has specific constraints on data access — including data residency, processing location, or specific prohibited operations — communicate these during scoping and they will be documented in the engagement agreement.
Engagements may require access to sensitive credentials — system administration accounts, Bloomberg AIM user profiles, Charles River administrator roles, custodian feed credentials, API keys, database connections, or network access tokens.
PBW's credential policy:
Coordinate credential return as part of the engagement close checklist. PBW will provide written confirmation upon return or destruction.
PBW maintains internal engagement logs that record key activities, access events, and work performed on client systems during the engagement. These logs support accountability, issue resolution, and client audit requests.
If your organization requires a specific log format, export schedule, or SIEM integration, discuss requirements during scoping.
PBW retains project artifacts, engagement records, and client information according to the following policy:
Immediate deletion on request. A client may request immediate deletion of their engagement records, artifacts, and communications at any time by contacting PBW at info@pbwps.com. PBW will confirm deletion in writing.
Secure deletion. PBW uses industry-standard secure deletion practices for electronic records. Deleted materials are not recoverable through standard methods.
PBW is experienced working under client-provided confidentiality agreements, data-processing agreements, and master services agreements. We are also prepared to provide our own standard terms where needed to accelerate engagement initiation.
To request a copy of PBW's standard MSA, or to submit your NDA or MSA for review, contact info@pbwps.com with the subject line "Agreement Review Request."
Questions about PBW's data-security practices? Have a compliance or legal review in progress? Contact us to discuss your requirements before engaging.