1. Security principles
- Least privilege — discovery should use scoped service accounts / roles you approve.
- Desktop-first credentials — secrets intended to remain in OS-protected storage on the endpoint (e.g. DPAPI / safeStorage patterns).
- Customer control of estate data — minimise unnecessary export of personal data to ACQI-hosted systems.
- Honest claims — we do not display fake compliance badges.
- Defence in depth — transport encryption (TLS), access control, auditability, and secure development practices appropriate to stage.
2. Architecture snapshot
| Layer | Description |
|---|---|
| Client | Desktop application (Electron) + PowerShell discovery modules for deep estate scanning |
| Identity to targets | Customer-supplied credentials / app registrations against Azure, M365, AD, cloud, infra, security tools, etc. |
| Outputs | Inventories, reports, planning artefacts for M&A diligence and integration |
| Optional services | Account, licensing, support, and AI features that may use cloud subprocessors |
| Governance | Wave planning, gates, post-deal oversight modules as licensed |
3. Data handling summary
| Data type | Typical handling |
|---|---|
| Target-environment credentials | Local endpoint; not required by design for upload to ACQI for standard discovery |
| Discovery results | Customer-controlled storage / export paths; processor terms if hosted by ACQI |
| Website leads | Controller processing under the Privacy Policy |
| AI prompts | Sent to model subprocessor only when AI features used — see AI disclosure |
4. Technical & organisational measures (high level)
These reflect design goals and DPA Annex themes. Enterprise diligence should validate current state via questionnaire and demo — early-stage controls improve over time.
- Encryption in transit (TLS 1.2+) for network communications
- Encryption at rest for hosted data stores where used
- Role-based access for ACQI personnel to production systems (need-to-know)
- MFA for privileged ACQI access where implemented
- Logging of security-relevant events for hosted components
- Secure software development practices (code review, dependency hygiene)
- Incident response process with customer notification commitments under the DPA
- Confidentiality obligations for staff and contractors
Not claimed unless independently verified and listed here: SOC 2 Type I/II; ISO/IEC 27001; Cyber Essentials / Plus; FedRAMP; HIPAA attestation / BAA (available only under separate agreement if ever offered).
5. Customer responsibilities (shared model)
| You (customer) | ACQI |
|---|---|
| Authorise scans lawfully | Build and maintain product security features |
| Harden endpoints running the client | Secure our hosted infrastructure |
| Least-privilege credentials & rotation | Process data only as instructed (processor role) |
| Review discovery outputs before deal decisions | Notify material breaches per DPA |
| Clean-team / antitrust controls in M&A | Maintain subprocessors list |
| Configure AI feature data handling | Provide contractual DPAs |
| Own change control for any write/migration action | Document product security posture honestly |
| Control retention of diligence exports | Liability caps as per Terms/MSA |
Liability: Discovery/migration tooling creates material legal risk. Allocation is spelled out in Product risks & tooling liability and the Terms. ACQI is not your insurer against post-close IT surprises.
6. Vulnerability disclosure
If you believe you have found a security vulnerability in ACQI software or infrastructure:
- Email security@acqi.ai with a technical description and repro steps.
- Do not access data that is not yours or disrupt production systems.
- Allow reasonable time for assessment before public disclosure.
We do not offer a formal bug bounty unless announced.
7. Compliance context (product for M&A)
ACQI helps customers discover and assess IT estates that may be relevant to GDPR, NIS2, DORA, SOX ITGCs, and similar frameworks. Using ACQI does not make your organisation compliant. Outputs support professional judgement; they are not legal opinions or audit certifications.