sgkstudio.
Security · Trust · Compliance

Trust comes from the system.

We publish the policy as written. Data classification, encryption, access control, incident response, and destruction — in the form your procurement team asks for.

  • Runs on SOC 2 Type II infrastructure

    Not our own certification — held by our processors (Vercel · Cloudflare · OpenAI · Resend)

  • Runs on ISO 27001 infrastructure

    Not our own certification — held by our processors (Cloudflare · Google Workspace)

  • PIPA Article 26

    Standard processing agreement + certificate of destruction attached

  • Network Act Article 50

    Cold email's 7 statutory requirements enforced automatically

01 — Data Classification

Four levels, kept apart.
Sensitive data is isolated.

Personal data of your employees and customers is separated from our own operating data, physically and logically.

Level 1 · Public

Public

Safe to publish

Examples

Landing page content, engineering blog, company profile

Handling rule

No restriction

Level 2 · Internal

Internal

Our operating data

Examples

Quotes, sales pipeline, revenue figures

Handling rule

Company accounts only

Level 3 · Confidential

Confidential

Client confidential

Examples

Client code, documents, database structure, business plans

Handling rule

Access only where the contract says so

Level 4 · Sensitive

Sensitive

Personal and payment data

Examples

Personal data of client employees and customers, auth tokens

Handling rule

Least privilege · encrypted · isolated

02 — Trusted Infrastructure

We only run on certified global providers.

Instead of running our own security team, we delegate to large providers holding SOC 2 Type II and ISO 27001.

VendorCertificationUseRegion
Vercel Inc.SOC 2 Type IIHosting · CDN · serverlessUS, global CDN
Cloudflare Inc.ISO 27001 · SOC 2 · PCI DSSDNS · WAF · email routingUS, global edge
Google WorkspaceISO 27001 · 27017 · 27018Business email and documentsUS
OpenAI · AnthropicSOC 2 Type IILLM API (RAG responses)US
ResendSOC 2 Type IIEmail deliveryUS
GitHubSOC 2 Type IISource code storageUS

Cross-border transfer of personal data — carried out only after the data subject consents · migration to a Korean data centre available on request (NHN Cloud · Naver Cloud)

03 — Encryption & Access

Encryption, MFA, and least privilege are the baseline.

One-way password hashing · API keys in environment variables only · personal use isolated · quarterly access review.

Encryption

In transit
TLS 1.2+ enforced (1.0/1.1 disabled)
At rest
AES-256 (database · disk)
Passwords
bcrypt · argon2 one-way hash
Laptops
FileVault · BitLocker enabled

Access control

Auth
MFA required · 30-minute idle session timeout
Privileges
Least privilege · revoked the moment a client engagement ends
Secrets
Vercel env · Cloudflare Secrets · never committed to Git
Review
Quarterly review of SaaS and account privileges

Logging & audit

Infrastructure logs
Vercel · Cloudflare · Resend, 90 days
Auth logs
Google · Vercel · GitHub, 1 year
PII access logs
Processing systems, 2 years (PIPA Art. 29)
Anomaly detection
Cloudflare WAF · automatic blocking

Secret management

Storage
Vercel Env · Cloudflare Workers Secrets
Local
Encrypted in the OS keychain
Rotation
Every 12 months, or immediately on suspected exposure
Client keys
Returned the moment the contract ends · written confirmation
04 — Incident Response

If an incident happens, we report it within 72 hours.

Aligned with PIPA Article 34. Affected clients get a first notification within 24 hours and a full report within 7 days.

  1. T+0

    Detection

    Internal alert or external report

  2. T+1h

    Containment

    Affected systems isolated · accounts locked · incident log opened

  3. T+24h

    First notice

    Email and phone notice to affected clients (summary · scope · current response)

  4. T+72h

    Regulatory filing

    On a personal data breach, filed with the PIPC and KISA (PIPA Art. 34)

  5. T+7d

    Full report

    Cause · impact · response · prevention — sent to clients and data subjects

  6. T+30d

    Post-review

    Policy updated · systems hardened · findings recorded

Report a security incident — contact@sgkstudio.co.kr · KISA 118 · privacy.go.kr

05 — Destruction

Destroyed within 30 days of contract end, with a certificate.

Source data, embedding vectors, caches, and backups are all securely wiped. Moving files to the trash does not count.

Contract end + 30 days

Source data · embeddings

Permanent database deletion · index wipe

Contract end + 90 days

Logs · backups

Compressed, then media wipe

7 days after destruction

Certificate of destruction

Table of scope, items, volume, method, and timestamp + company seal

Statutory retention

Data we are legally required to retain — Commercial Act Art. 33 (5 years), Framework Act on National Taxes Art. 85-3 (5 years), Network Act Art. 50 (1 year) — is held in isolation for that period and destroyed afterwards.

See the certificate template
06 — Processing Agreement

The data processing agreement comes as a standard form.

Aligned with PIPA Article 26. Sending the NDA, MSA, and this agreement together is our standard step before a first engagement.

Personal data processing agreement (DPA)

Parties · scope of processing · data categories · security measures · sub-processing · cross-border transfer · audit rights · destruction on termination · incident response · confidentiality · liability — 14 clauses + certificate of destruction

Our privacy policy

Purpose · categories · retention · third-party disclosure · processing delegation · cross-border transfer · data subject rights · security measures · automatic collection · privacy officer · remedies · change history — reviewed quarterly

Information security policy (condensed)

Classification · access control · encryption · trusted processors · secret management · logging and audit · incident response · destruction · sub-processor control · training — where ISMS/ISMS-P is required, we provide our processors' certificates

Marketing compliance guide

Fair Labeling and Advertising Act Art. 3 copy guidelines · Network Act Art. 50 seven requirements for cold email · our own limits on overstatement · quarterly self-audit · penalty schedule

The security package, sent within 24 hours.

NDA · MSA · data processing agreement · information security policy · certificate of destruction template, as a ZIP.
Vendor registration packs are available on request.