Draft — pending final review. The complete notice will be published before PRC accepts sensitive client records.
Records are the reason PRC exists, and we hold ourselves to the standard we teach. Before PRC accepts sensitive records from any client, the following protections are established and maintained:
Security commitments
- A written information-security policy
- Role-based access — only the people who need a record can reach it
- Multifactor authentication on systems that hold client records
- Encryption in transit and at rest
- Source-document preservation — originals are never altered
- Audit logging and version history
- Backups with restore testing
Lifecycle commitments
- Retention and deletion schedules agreed in writing
- Incident-response procedures
- Vendor security review for any tool that touches client records
- Employee confidentiality rules
- At offboarding: secure return or deletion of records, at the client's direction
What this means for you
Until secure intake channels are in place, please do not send PRC sensitive documents, account numbers, or identification numbers through website forms or unencrypted email. We will establish the secure channel first — that is the point of records readiness.