Level 1 · Public
Public
Safe to publish
Examples
Landing page content, engineering blog, company profile
Handling rule
No restriction
We publish the policy as written. Data classification, encryption, access control, incident response, and destruction — in the form your procurement team asks for.
Runs on SOC 2 Type II infrastructure
Not our own certification — held by our processors (Vercel · Cloudflare · OpenAI · Resend)
Runs on ISO 27001 infrastructure
Not our own certification — held by our processors (Cloudflare · Google Workspace)
PIPA Article 26
Standard processing agreement + certificate of destruction attached
Network Act Article 50
Cold email's 7 statutory requirements enforced automatically
Personal data of your employees and customers is separated from our own operating data, physically and logically.
Level 1 · Public
Safe to publish
Examples
Landing page content, engineering blog, company profile
Handling rule
No restriction
Level 2 · Internal
Our operating data
Examples
Quotes, sales pipeline, revenue figures
Handling rule
Company accounts only
Level 3 · Confidential
Client confidential
Examples
Client code, documents, database structure, business plans
Handling rule
Access only where the contract says so
Level 4 · Sensitive
Personal and payment data
Examples
Personal data of client employees and customers, auth tokens
Handling rule
Least privilege · encrypted · isolated
Instead of running our own security team, we delegate to large providers holding SOC 2 Type II and ISO 27001.
| Vendor | Certification | Use | Region |
|---|---|---|---|
| Vercel Inc. | SOC 2 Type II | Hosting · CDN · serverless | US, global CDN |
| Cloudflare Inc. | ISO 27001 · SOC 2 · PCI DSS | DNS · WAF · email routing | US, global edge |
| Google Workspace | ISO 27001 · 27017 · 27018 | Business email and documents | US |
| OpenAI · Anthropic | SOC 2 Type II | LLM API (RAG responses) | US |
| Resend | SOC 2 Type II | Email delivery | US |
| GitHub | SOC 2 Type II | Source code storage | US |
Cross-border transfer of personal data — carried out only after the data subject consents · migration to a Korean data centre available on request (NHN Cloud · Naver Cloud)
One-way password hashing · API keys in environment variables only · personal use isolated · quarterly access review.
Aligned with PIPA Article 34. Affected clients get a first notification within 24 hours and a full report within 7 days.
Detection
Internal alert or external report
Containment
Affected systems isolated · accounts locked · incident log opened
First notice
Email and phone notice to affected clients (summary · scope · current response)
Regulatory filing
On a personal data breach, filed with the PIPC and KISA (PIPA Art. 34)
Full report
Cause · impact · response · prevention — sent to clients and data subjects
Post-review
Policy updated · systems hardened · findings recorded
Report a security incident — contact@sgkstudio.co.kr · KISA 118 · privacy.go.kr
Source data, embedding vectors, caches, and backups are all securely wiped. Moving files to the trash does not count.
Permanent database deletion · index wipe
Compressed, then media wipe
Table of scope, items, volume, method, and timestamp + company seal
Statutory retention
Data we are legally required to retain — Commercial Act Art. 33 (5 years), Framework Act on National Taxes Art. 85-3 (5 years), Network Act Art. 50 (1 year) — is held in isolation for that period and destroyed afterwards.
Aligned with PIPA Article 26. Sending the NDA, MSA, and this agreement together is our standard step before a first engagement.
Parties · scope of processing · data categories · security measures · sub-processing · cross-border transfer · audit rights · destruction on termination · incident response · confidentiality · liability — 14 clauses + certificate of destruction
Purpose · categories · retention · third-party disclosure · processing delegation · cross-border transfer · data subject rights · security measures · automatic collection · privacy officer · remedies · change history — reviewed quarterly
Classification · access control · encryption · trusted processors · secret management · logging and audit · incident response · destruction · sub-processor control · training — where ISMS/ISMS-P is required, we provide our processors' certificates
Fair Labeling and Advertising Act Art. 3 copy guidelines · Network Act Art. 50 seven requirements for cold email · our own limits on overstatement · quarterly self-audit · penalty schedule
NDA · MSA · data processing agreement · information security policy · certificate of destruction template, as a ZIP.
Vendor registration packs are available on request.