Security Assurance · GRC · Secure AutomationRemote delivery for growing technology businesses
Security Practices

Client evidence deserves stricter handling than ordinary consulting files.

Tech Turn is building the consultancy around client separation, scoped access, least privilege, evidence integrity, retention controls and documented handling.

Operating principles.

These practices define how Tech Turn intends to handle assurance engagements.

Scoped Access

Use the minimum level of access required for the approved assessment or remediation scope.

No Shared Personal Passwords

Use approved identities, delegated roles, OAuth, scoped API credentials, exports or screen-share rather than asking for personal passwords.

Client Separation

Maintain separate client evidence, workpapers, credentials and reports.

Evidence Integrity

Preserve source, collection date, provenance and integrity references where appropriate.

Retention & Disposal

Retain evidence only according to engagement requirements and documented retention rules.

Human Approval

High-impact changes involving access, security, legal or customer-facing actions require explicit authorisation.

Assurance independence.

Advisory and assurance are not automatically interchangeable.

Where Tech Turn materially designs or implements a client control, the engagement must not then be presented as independent assurance over that same work without appropriate safeguards. An independent auditor or contractor may be used when required.