Legal
Privacy Notice
Vector Risk Advisors, LLC d/b/a Vector Risk Assessment — how we handle information collected through this website and in the course of client engagements.
1. Who We Are and What This Notice Covers
Vector Risk Advisors, LLC, doing business as Vector Risk Assessment ("Vector," "we," "our," or "us"), is a Georgia limited liability company providing cybersecurity risk assessment services to businesses.
This notice explains how we handle information collected through vectorriskassessment.com and in the course of inquiries, scheduling, contracting, payment, and client engagements. Vector serves businesses. We do not offer consumer products or services.
Our commitment regarding client information
We do not sell, rent, license, or trade information about our clients, their businesses, or their people, in any capacity. We do not share information for advertising or for any third party's marketing. We do not use client information to train artificial intelligence models. We use client information to perform the engagement the client has retained us for, to administer that engagement, and for the ordinary business and legal purposes described in Section 3 — and for nothing else.
Information a client provides for an engagement is governed primarily by the Master Services Agreement and Statement of Work between Vector and that client. Where this notice and a client agreement differ as to that information, the agreement controls. This notice is a general statement of practice and is not part of any client agreement.
2. Information We Collect
Business contact information
We collect information you give us when you submit a form, email us, schedule a call, request information, enter into an agreement, make a payment, or otherwise communicate with us. This typically includes name, business email address, phone number, firm name, title or role, business address, the substance of your inquiry, scheduling details, and billing information.
Client engagement information
In performing an assessment we receive materials a client or its authorized providers give us for that purpose. These are generally business records of the client rather than information about identified individuals, though they may incidentally contain personal information. They may include security program and policy documentation, control and evidence reporting, vendor information, resilience and incident response documentation, training records, information about privacy and non-public personal information practices, insurance application materials where the client asks us to review them, and related business, operational, or compliance information.
We ask clients not to send us sensitive personal information or non-public personal information unless it is necessary for the engagement, and to send it only through the secure method we designate. Where we can assess a control without receiving underlying personal information, that is our preference and our normal practice.
Website and technical information
Our website is deliberately minimal. It collects only what is needed to operate and to respond to inquiries. As with any website, our hosting provider records ordinary technical request data, such as IP address, browser type, date and time of request, and pages requested, for security, reliability, and abuse-prevention purposes. See Section 9 regarding cookies and analytics.
3. How We Use Information
We use information for ordinary business purposes:
- Responding to inquiries and scheduling meetings;
- Evaluating and scoping potential engagements;
- Performing assessments and preparing findings, recommendations, and deliverables;
- Administering engagements, secure workspaces, and evidence collection;
- Coordinating with third parties a client has authorized;
- Invoicing, processing payments, and maintaining accounting records;
- Communicating with clients and business contacts;
- Maintaining business and professional records;
- Improving our methods, templates, and internal processes, using our own work product rather than client information;
- Protecting the security and integrity of our systems; and
- Complying with legal obligations and enforcing our agreements.
4. AI-Assisted Analysis
We use AI-assisted technology, including large language models and automation tools, to support document review, analysis, drafting, summarization, and quality control.
Where client information is involved, we use business or enterprise service tiers under terms that prohibit the provider from using our inputs to train its models. We do not use consumer or retail AI tools for client information, and we do not submit client information to publicly accessible AI systems.
AI-assisted technology supports our work; it does not replace it. Every assessment is performed or reviewed by a practitioner holding the Certified Information Systems Security Professional (CISSP) credential; every finding, conclusion, recommendation, and deliverable is reviewed before it is issued, and Vector remains responsible for its deliverables.
5. How We Share Information
We do not sell, rent, or trade information, and we do not share it for third-party marketing. We share information only as reasonably necessary, and only with:
- Service providers that support our operations — cloud storage and secure file exchange, business email, scheduling, electronic signature, payment processing, accounting, and similar functions — under confidentiality and security obligations;
- Third parties a client has specifically authorized in connection with an engagement, such as the client's security services provider;
- Our professional advisors, including attorneys, accountants, and insurers, where relevant to their work for us;
- Government, regulatory, or legal authorities where required by law, legal process, or a valid governmental request;
- Parties involved in enforcing our agreements, collecting amounts owed, or responding to a dispute; and
- A successor entity in a merger, acquisition, or sale of substantially all business assets, subject to confidentiality protections.
We maintain a record of each disclosure of client information containing non-public personal information, including the date, the recipient, a description of the information disclosed, and the purpose of the disclosure. We retain that record for at least seven years and make it available to the client on written request. The record does not contain the client information itself.
Vector performs its services itself. We engage a subcontractor to perform any part of an engagement only with the client's prior written consent, and only under confidentiality and security obligations at least as protective as our own. We will identify the specific service providers we rely on to a client or prospective client on request.
6. Security
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, disclosure, alteration, loss, and destruction. Our current practices include the following.
Access control and authentication
Multi-factor authentication is required on all accounts with access to client information. Access is limited to personnel with a need to know, under least-privilege principles; Vector is a small firm and, at present, that means the principal. Client information is not stored on personal accounts or consumer services.
Encryption
Client information is encrypted in transit and at rest using the encryption provided by the platforms on which it is stored and exchanged.
Secure exchange of engagement materials
We designate a secure workspace for exchanging and storing engagement materials. We do not use personal email or consumer file-sharing services for client information, and we ask clients not to send it by ordinary email.
Endpoint protection
Devices used for client work run current endpoint protection, full-disk encryption, and supported, patched operating systems and applications.
Logging and monitoring
We log and monitor access to the systems that hold client information, and review account access and activity on those systems.
Scope limitation
Our assessment methodology is built to limit what we hold. We do not request or require administrative credentials to client systems, we do not install software or agents in client environments, and we do not conduct penetration testing or other intrusive testing. Where a control can only be confirmed from inside a client system, we ask the client to demonstrate it.
Provider selection
We review the security practices of service providers that have access to client information. We select providers that maintain recognized third-party security attestations or certifications, and review a provider's security documentation before entrusting client information to it.
Incident notification
If we confirm a security incident involving unauthorized access to or acquisition of client information in our possession or control, we notify the affected client without undue delay and in any event no later than forty-eight hours after confirming the incident, describing what we then know and providing updates as more becomes known. We cooperate with the client's own notification and regulatory obligations.
On a client's reasonable written request we will complete a security questionnaire, provide a written summary of these safeguards, and provide evidence of the technology and professional liability insurance, including cyber liability coverage, that we maintain. No security program can eliminate all risk, and we cannot guarantee that any system or method of transmission is completely secure.
7. Where Information Is Processed
Vector performs its services, and stores client information, in the United States. We serve clients located in the United States. If you provide information from outside the United States, it will be processed and stored here.
8. How Long We Keep Information
We keep information only as long as needed for the purpose it was collected, to meet legal, tax, accounting, and professional record-keeping obligations, and to resolve any dispute.
Retention and destruction of client engagement materials are set in the applicable Master Services Agreement and Statement of Work. Under our standard terms, raw technical evidence received during an engagement — including asset inventory reports, scan output, and configuration detail — is securely destroyed within sixty days after release of the final deliverable, unless the parties agree in writing to retain it for a renewal engagement. Final deliverables, workpapers, and engagement records are retained for the longer of seven years after the engagement is completed or any longer period required by applicable law, including any retention requirement applicable to a client's cybersecurity records under 23 NYCRR Part 500. The records of disclosure described in Section 5 are retained on the same basis.
A client may request earlier destruction of its information, and we will honor a reasonable request except where retention is required by law or necessary to resolve an open dispute.
9. Cookies and Analytics
We do not use advertising technologies, behavioral tracking, or non-essential cookies on our website. As published, our website loads no third-party scripts, fonts, analytics, or advertising code.
Where we use a third-party service for scheduling, forms, or payment, we link to that provider rather than embedding it in our pages wherever practical. Those providers process information under their own privacy terms. If our practice changes, we will update this notice before or when the change takes effect.
10. Marketing Communications
We may send business communications, service updates, and occasional marketing messages to business contacts, prospects, and clients. You can opt out of marketing messages using the unsubscribe link or by contacting us. We may still send transactional, administrative, security, and service communications.
11. Your Choices and Requests
You may ask us to access, correct, or delete personal information we hold about you. Write to the address in Section 15.
We may need to verify your identity or authority before responding. We may decline or limit a request where permitted or required by law, or where the information is needed for legal, accounting, security, record-keeping, or dispute-resolution purposes. Where a request concerns information we hold on behalf of a client, we will refer the request to that client.
12. State Privacy Rights
New York
Vector maintains a data security program designed to protect the private information of New York residents, consistent with New York's data security requirements for businesses holding such information. Section 6 describes that program.
California and other states
We do not sell personal information and we do not share it for cross-context behavioral advertising. In a business context we may collect identifiers such as name, business email, phone number, business address, and firm name; professional information such as title and role; commercial and transactional information such as inquiries, invoices, and engagement records; electronic activity such as form submissions and scheduling interactions; communications with us; and observations developed during an engagement, such as risk observations and recommendations.
To the extent a state comprehensive privacy law applies to us, residents of that state may have rights to request access, deletion, or correction, and to receive information about the categories of personal information we collect and the purposes for which we use them. We handle all such requests through the process described in Section 11. We do not knowingly collect personal information from individuals under sixteen.
13. Relationship to Client Agreements
This notice describes our general practices. It does not create contractual obligations, is not incorporated into any client agreement, and does not modify one. For clients, the Master Services Agreement and applicable Statement of Work govern our handling of client information, including confidentiality, security, retention, destruction, and incident notification.
14. Changes to This Notice
We may update this notice. The current version is posted on our website with its effective date and version number. We will note material changes on the website and, where appropriate, tell affected clients directly.
15. Contact Us
Privacy questions and requests: privacy@vectorriskassessment.com
Vector Risk Advisors, LLC d/b/a Vector Risk Assessment
8735 Dunwoody Place, Suite R, Atlanta, GA 30350