Data handling

What happens to your design files

Written to be forwarded. If someone in your organisation has to approve design material leaving the building, this page is the answer to their questions.

01   THE SHORT VERSION

If you read nothing else

Your material is encrypted before it leaves your network and stays encrypted at rest, in containers belonging to your engagement alone, separate from every other client.

Design files are destroyed 90 days after close-out, or on a later date you ask for at close-out, and you get a dated certificate either way. The report and the working record behind it are kept for 7 years, because those are what defend the opinion I gave you.

Nothing is stored on a cloud service. There are no sub-processors. No external AI service is ever sent your design, and nothing of yours is used to train anything.

Export-controlled and classified work is declined rather than accommodated.

At a glance

  • AES-256, two separate encrypted containers per engagement.
  • Design files destroyed at 90 days, or later if your build schedule needs it, confirmed in writing.
  • Report and record retained 7 years.
  • No cloud storage, no sub-processors, no external AI services.
  • Deletion on request at any time.

What I am not

I hold no ISO 27001 or Cyber Essentials certification. A one-person practice buying an audit badge would tell you less than this page does.

What is described here is what actually happens, and I am happy to answer questions about any of it before you send anything.

02   GETTING IT TO ME

Transfer is the weak point, so it is handled first

Storage is the easy part. The risk in any review engagement is the moment the files cross between two organisations, because that is the part neither side fully controls.

The way out is to stop trusting the transfer at all. If the package is encrypted before it leaves your network, the route it takes afterwards stops mattering, because what crosses is ciphertext and I hold the only key.

Your own secure transfer system comes first. If you have one, send me an invite and I will use it. Your platform, your access control, your audit trail, and nothing of yours lands anywhere you have not already approved.

Otherwise, an encrypted archive. Either to my OpenPGP key, which works with standard GPG and whatever process your team already has for it, or a 7-Zip or Zip archive with AES-256 and a strong passphrase sent by a different route from the file itself.

The key is at consultana.tech/consultana.asc, fingerprint C832 139A 342F A1D4 007C 314B 2C81 0B01 4D44 5C99. Check that against the fingerprint I read out on the call rather than trusting this page for both, since anyone able to alter one could alter the other.

What I ask you not to do is email design files unencrypted. Those sit on a mail server outside our control for as long as that provider chooses to keep them, and nothing careful at my end undoes it.

On arrival

The package goes straight into the design-files container for your engagement and the transfer copy is deleted. Nothing is staged on a desktop, a downloads folder or a cloud drive on the way in.

You get a completeness confirmation within one working day listing anything missing, and a written record of exactly which files at which revisions form the reviewed baseline. That list appears in the report, so what I say I reviewed is what actually arrived.

Export control and classification

I am not set up with the facilities or the clearances for export-controlled or classified material, so I decline that work rather than trying to accommodate it.

Establish the classification of your material before anything is shared. If it turns out mid-enquiry that the work is controlled, say so immediately and we stop there.

03   WHILE I HOLD IT

Storage

Every engagement gets two AES-256-encrypted containers, each with its own passphrase. The design-files container holds your material and everything derived from it. The record container holds the report and the evidence behind it.

That split is what makes the two retention periods below possible rather than aspirational. A single container would mean the design-file deletion either destroys the 7-year record or quietly never happens, and the tool that manages them refuses to merge the two.

One client's material cannot be reached while working on another's, because opening a container is a deliberate act rather than a background state.

The machine itself is encrypted at rest with FileVault, so the containers protect client separation and full-disk encryption protects everything around them.

Containers are excluded from versioned backup. A backup that keeps historical snapshots would leave old copies behind after a deletion, which would make the confirmation I send you untrue. Instead a copy of the sealed container is mirrored to separate encrypted media, and because every copy is the same ciphertext under the same passphrase, discarding that passphrase destroys all of them at once.

Search indexing is disabled on every mounted container, because an index lives outside the container and would otherwise keep filenames and content excerpts after the container itself is gone.

Where a review needs vendor tooling that only runs under Windows or Linux, that machine's disk lives inside the encrypted container rather than the container being shared out to it. The boundary stays in one place.

Who else sees it

Nobody outside the company sees your design material, at any point. No sub-contractors, associates or reviewers. No cloud storage, file sync or shared drives. It reaches me either through your own transfer system or encrypted to my key, so nobody carrying it can read it.

Correspondence is the exception, and it is worth naming. Email to consultana.tech passes through a forwarding service and a mail provider before it reaches me, so treat anything typed into an email or the enquiry form as seen by them. That is why the design itself does not travel that way.

Inside the company, the honest answer is longer than "nobody", because every organisation has an administrator who could technically reach anything.

Rachellie Limited has two directors. One performs the reviews. The other administers the IT and could, like any system administrator anywhere, reach the machines.

She holds no container passphrases, performs no client work, and containers are closed before any support or maintenance happens, so what is reachable during that work is encrypted. She is bound by the same confidentiality obligations as the company, and by any NDA you hold with us.

Automated tooling, including AI

I use software to do the mechanical passes: cross-checking a BOM against a schematic, reading tool logs, flagging inconsistencies between documents. Some of it uses machine learning models. All of it runs on my own hardware, inside the same encrypted boundary as everything else.

Nothing is sent to an external AI service. Not to a hosted assistant, not to an API, not to anything with a terms of service that lets a vendor retain your material.

Nothing of yours trains anything. No fine-tuning, no shared index, no learned state that outlives your engagement. Anything a tool produces from your design, including any index built to search it, lives in your engagement's container and is destroyed with it.

Every finding in your report is one I reached, understood and can defend under questioning. Tools shorten the mechanical work so more of my time goes on the judgement you are actually paying for.

If something goes wrong

You will be told without undue delay, and told what I actually know at the time rather than after I have assembled a complete picture.

That means what was affected, when, and what is being done. A tidy account a week later is worth less to you than a rough one the same day.

04   RETENTION AND DELETION

Two clocks, not one

Design material and the record of the opinion have different lifetimes, and saying only the shorter one would be misleading.

What is kept, for how long, and why
MaterialRetainedWhy
Your design files, in every format supplied, plus every working copy, marked-up PDF and derived file containing your design data 90 days after close-out, then destroyed
or a longer period you ask for, up to 12 months
design-files container
They are yours and I have no reason to hold them once the engagement is finished. The window exists so you can come back with questions while the work is still fresh. Ninety days is the default because the shortest honest number is the one worth offering. It is also short next to a complex fab and assembly run, so I ask at close-out when your boards are due back and set the date around that.
The final report and findings register as issued, the proposal and order, the engagement record and conflict check, and the annotated review checklist 7 years
record container
These evidence the professional opinion I gave you. If that opinion is ever questioned, by you or by anyone else, this is what supports or defends it. They contain no design files.
A list of the files you sent, giving the name, size and SHA-256 hash of each 7 years
record container
Recorded when your material arrives, and it holds none of your design content. Once the design files are destroyed, this is what lets either of us establish which revision I actually reviewed. Without it you would be taking my word for it, and so would I.
Enquiries that never became work 12 months Long enough to pick up a conversation that went quiet, short enough not to accumulate.

What destruction actually means

On a solid-state disk, deleting a file does not guarantee the blocks are unrecoverable. Wear levelling moves data around and nobody can honestly promise otherwise, whatever their marketing says.

Destroying an encrypted container is a different claim, and a stronger one. The design-files container is deleted and its passphrase discarded, so the contents become cryptographically unrecoverable regardless of which physical blocks happen to survive. The record container is untouched and keeps its own separate passphrase.

Because the backup copy is of the same sealed container under the same passphrase, discarding that passphrase covers every copy at the same moment.

The certificate

You get a dated written confirmation naming the engagement, what was destroyed, how, how many copies existed, and what is retained instead. It only asserts what was actually verified at the time.

If, for example, backup cleanliness could not be evidenced, the certificate says so rather than claiming it. A deletion certificate that overclaims is worse than no certificate at all.

Earlier, if you want

Ask at any point and the design-files container is destroyed early, with the same certificate. You do not need a reason.

Where this sits in the contract

This page describes practice. The binding version is clause 5 of the terms of engagement, which you receive with any proposal and which says the same things in contractual language. Where a client NDA is in place, that governs too, and I am equally happy working under yours or mine.

If your organisation needs any of this in a different form, ask. I can complete a security questionnaire, agree a specific clause, or take a call with whoever has to sign it off. That is a normal part of getting started rather than an imposition.

The privacy notice covers personal data and what this website itself collects, which is almost nothing.

Last updated July 2026.

Questions before you send anything?

Ask them first. None of this gets easier once files have moved, and a conversation with whoever has to approve it is a normal part of starting.