Data governance and security
How DEISO handles client data during an engagement — where it sits, who can reach it, how AI is used, how long it is kept, and what happens if something goes wrong.
This page states DEISO’s working practice in plain terms so that a technical or procurement reviewer can assess it before an engagement begins. It is not a certification, and DEISO does not claim one.
Scope
This page covers client data: the files, figures, drawings, invoices, supplier information, emission factors, cost records and correspondence a client shares with DEISO in order for work to be carried out.
Personal data collected through the website — enquiry forms, subscriptions, analytics — is covered separately in our privacy policy.
Principles
Four principles govern how DEISO handles client material.
- Minimum necessary — DEISO asks for the data the work requires, and no more
- Named purpose — client data is used only for the engagement it was provided for
- Traceable — figures used in a deliverable are traced to their source, owner and date
- Returned or removed — client data does not accumulate indefinitely after an engagement closes
Where client data is held
DEISO is based in Japan and client work is carried out from Japan. Client files are held in access-controlled business cloud storage and on DEISO working machines, and are transferred over encrypted connections.
Where a client requires that data be exchanged through the client’s own system — a secure portal, a controlled workspace, or a nominated transfer service — DEISO will work within that system instead.
DEISO does not publish client data, does not sell it, and does not share it with any party outside the engagement without the client’s written agreement.
Who has access
Access to client data is limited to the DEISO personnel assigned to the engagement. Where a specialist is brought in for a defined part of the work, that specialist is bound by the same confidentiality terms and is given access only to the material that part of the work requires.
DEISO working accounts are protected by two-factor authentication, and working machines are protected by full-disk encryption and screen lock.
Confidentiality
Confidentiality applies to every engagement by default, whether or not a separate agreement is signed. DEISO signs client non-disclosure agreements on request, and confidentiality terms are set out in the engagement agreement for each project.
DEISO does not name a client, describe a project, or use project material in marketing, case studies or training without that client’s written permission. Where permission is given, the scope of what may be shown is agreed in advance.
Use of AI in delivery
DEISO is AI-supported. AI tools are used to accelerate structuring, drafting, checking and analysis. They do not replace the technical judgement in a deliverable.
- Human technical review — every figure, method and conclusion in a deliverable is reviewed by a DEISO technical practitioner before it leaves
- No confidential input to public tools — client-identifying material and confidential figures are not submitted to public or consumer AI services
- No model training — client data is not used to train third-party AI models, and DEISO does not grant any provider the right to do so
- Stated on request — where a client asks, DEISO will state which parts of a workflow used AI support
If a client requires that no AI tooling is used on their engagement, DEISO will work to that condition and confirm it in the engagement agreement.
Tools and third parties
Delivery involves ordinary business software: cloud file storage, email, office and spreadsheet applications, life cycle assessment and costing software, and the DEISO website and forms. Each of these is a commercial service operating under its own terms, and each processes only what the work passes through it.
Where a client requires a list of the specific services that would touch their material, DEISO will provide it before the engagement begins.
Retention and deletion
Client data is kept for the duration of the engagement and for a period afterwards, so that results can be defended in review, questions answered, and the study updated in the next cycle without rebuilding it.
Where a client asks in writing for their data to be deleted, DEISO will delete it, subject to any records DEISO is required to retain by Japanese law — principally invoices and accounting records — and will confirm what has been deleted and what has been retained.
Ownership of data and deliverables
Data a client provides remains the client’s data. Ownership of deliverables, models and reports produced during an engagement is set out in the engagement agreement for that project.
DEISO methodology, templates, curriculum and software remain DEISO property and are not transferred by an engagement.
If something goes wrong
If DEISO becomes aware of unauthorised access to, loss of, or disclosure of client data, DEISO will contact the affected client without undue delay, state what is known, state what is being done, and continue to update the client as the position becomes clearer.
To report a security concern about DEISO systems or a DEISO deliverable, email with “Security” in the subject line.
What DEISO does not claim
Clear boundaries matter more than badges, so these are stated directly.
- DEISO does not hold ISO 27001, SOC 2 or any equivalent information security certification
- DEISO is not a certification or verification body
- DEISO does not operate a client-facing data centre or hosting service
- No system is completely secure, and DEISO does not represent that it is
Where a client’s own procurement process requires a security questionnaire, supplier assessment or specific contractual data terms, DEISO will complete it and negotiate the terms.
Questions before an engagement
If your organisation needs to assess DEISO before sharing data, ask before the engagement rather than after. Send the question to and DEISO will answer it directly, including where the answer is that a formal process does not yet exist.
Contact
DEISO LLC, Japan
Email:
Website: dei.so
Share this:
- Email a link to a friend (Opens in new window) Email
- Share on LinkedIn (Opens in new window) LinkedIn
- Share on X (Opens in new window) X
- Share on Facebook (Opens in new window) Facebook
- Share on WhatsApp (Opens in new window) WhatsApp
- Share on Reddit (Opens in new window) Reddit
- Print (Opens in new window) Print
- More






