# CE Security, Infrastructure & Data Protection Overview
## Prepared for Brandwatch/Cision Partnership Discussion

*Internal document — not for distribution. Research + gap analysis.*

---

## What Brandwatch/Cision Will Ask

Cision is a publicly-traded enterprise company. Any technology partner handling their client data will need to clear their vendor security review. Based on standard enterprise procurement processes, here's what to expect:

### 1. Vendor Security Questionnaire (VSQ)
Enterprise companies typically use standardized questionnaires:
- **SIG (Standardized Information Gathering)** — most common
- **CAIQ (Consensus Assessments Initiative Questionnaire)** — cloud-specific
- **Custom questionnaire** — Cision likely has their own

**Typical questions:**
- Where is data stored? (Region, provider)
- Who has access to client data?
- How is data encrypted (at rest + in transit)?
- What's the incident response process?
- Do you have SOC 2 Type II?
- Are you GDPR compliant?
- What subprocessors do you use?
- What's your data retention/deletion policy?

### 2. Certifications They'll Look For

| Certification | What It Means | CE Status | Priority |
|--------------|---------------|-----------|----------|
| **SOC 2 Type II** | Independent audit of security controls | ❌ Not started | HIGH — dealbreaker for most enterprises |
| **ISO 27001** | Information security management system | ❌ Not started | MEDIUM — nice to have |
| **GDPR Compliance** | EU data protection | ⚠️ Needs documentation | HIGH — BW operates in EU |
| **DPA (Data Processing Agreement)** | Legal agreement for processing personal data | ❌ Not drafted | HIGH — required before any data flows |
| **Cyber Essentials** | UK government security standard | ❌ Not started | LOW — UK-specific |

### 3. What We Can Realistically Offer NOW vs Later

#### NOW (can prepare before Friday's meeting):
- Architecture overview document
- Data flow diagram (what data we touch, where it goes)
- Encryption practices (TLS in transit, encryption at rest)
- Access control description
- AI model provider list + their security postures
- Privacy policy / terms
- GDPR compliance statement

#### 6-12 MONTHS (if partnership progresses):
- SOC 2 Type II audit (typically $30-50K, 6-12 months)
- Formal DPA
- Penetration testing report
- Business continuity / disaster recovery plan

---

## CE Infrastructure Overview (Current State)

### Hosting & Compute
| Component | Provider | Region | Details |
|-----------|----------|--------|---------|
| Primary server | Hetzner | Helsinki, Finland (EU) | Ubuntu, 8GB RAM |
| Website | Vercel | Global CDN | Static hosting |
| Domain | curiousendeavor.com | — | |

### AI Model Providers (Subprocessors)
| Provider | What We Use It For | Their Security |
|----------|-------------------|----------------|
| **Anthropic (Claude)** | Strategy, copy, analysis | SOC 2 Type II, doesn't train on inputs |
| **Google (Gemini)** | Image generation, research | SOC 2, ISO 27001, GDPR compliant |
| **OpenAI** | Backup/supplementary | SOC 2 Type II, GDPR DPA available |

**Key point for BW:** We use API access only. No client data is used to train models. All major AI providers offer enterprise DPAs and commit to not training on API inputs.

### Data Flow (How Client Data Moves)

```
Brandwatch Client Data (CSV/export)
        ↓
    CE System (EU-hosted server)
        ↓
    AI Model APIs (for analysis/generation)
        ↓
    Output (strategy briefs, campaigns, assets)
        ↓
    Delivered to client
```

**What we touch:**
- Social listening exports (aggregated, typically not PII)
- Brand mention data
- Sentiment/topic analysis
- Audience segment data (aggregated)

**What we DON'T touch:**
- Individual user profiles/PII
- Brandwatch platform credentials
- Raw social media account data
- Login/authentication data

### Current Security Measures
- ✅ TLS/HTTPS everywhere
- ✅ SSH key-only access (no passwords)
- ✅ AI API calls over encrypted connections
- ✅ No client data persisted after delivery (process and delete)
- ✅ EU-hosted infrastructure (Hetzner, Finland)
- ⚠️ No formal access logging/audit trail yet
- ⚠️ No formal incident response plan documented
- ❌ No SOC 2
- ❌ No penetration testing

---

## Data Protection / GDPR Analysis

### Why GDPR Matters Here
- Brandwatch is UK/EU-based (Brighton HQ)
- Cision operates globally but must comply with GDPR for EU operations
- Any data processor handling EU personal data needs GDPR compliance
- Social listening data MAY contain personal data (usernames, public posts)

### GDPR Requirements for CE as a Data Processor

| Requirement | Status | Action Needed |
|------------|--------|---------------|
| **Lawful basis for processing** | ⚠️ | Legitimate interest (aggregated social data) — document this |
| **Data Processing Agreement (DPA)** | ❌ | Draft DPA with Brandwatch |
| **Records of Processing Activities** | ❌ | Create ROPA document |
| **Data minimization** | ✅ | We only process what's needed for campaign output |
| **Purpose limitation** | ✅ | Data used only for agreed creative production |
| **Storage limitation** | ⚠️ | Need formal retention/deletion policy |
| **Data subject rights** | ⚠️ | Need process for handling DSARs |
| **Breach notification** | ❌ | Need 72-hour notification process |
| **International transfers** | ⚠️ | AI API calls may route outside EU — need SCCs |
| **DPO appointment** | ❌ | Likely not required at our scale |

### Key GDPR Argument in Our Favor
Most Brandwatch export data is **aggregated social intelligence** — mention volumes, sentiment scores, topic clusters, audience segments. This is largely **not personal data** under GDPR. Individual social media posts that are publicly available have different processing grounds.

However, some data MAY include:
- Public usernames/handles
- Individual post content
- Location data

**Recommendation:** Position CE's processing as working with aggregated/anonymized data wherever possible. Where individual-level data is needed, rely on legitimate interest + the public nature of the source data.

---

## What We Should Prepare Before Friday

### Must Have (for the conversation):
1. **One-pager: "How We Handle Your Clients' Data"** — simple diagram + key facts
2. **Talking point:** "All processing happens on EU infrastructure. We use enterprise-tier AI providers with SOC 2 and GDPR compliance. No data is retained after delivery."
3. **Talking point:** "We're prepared to sign a DPA and work within your existing vendor security framework."

### Nice to Have (if we want to impress):
4. Data flow diagram (visual)
5. List of AI subprocessors with their certifications
6. Draft data retention policy

### Don't Need Yet (but will need if deal progresses):
7. SOC 2 audit
8. Formal DPA (legal drafting)
9. Penetration test report
10. Full ROPA documentation

---

## Competitive Context

How other creative/AI platforms handle enterprise security:

- **Jasper AI:** SOC 2 Type II, SSO, role-based access, enterprise DPA
- **Writer.com:** SOC 2 Type II, HIPAA, custom deployment options
- **Canva Enterprise:** SOC 2 Type II, ISO 27001, GDPR
- **Copy.ai:** SOC 2 Type II (achieved after scaling)

**Pattern:** All started without SOC 2 and added it as enterprise deals required it. SOC 2 is table stakes for enterprise but NOT required for a pilot/POC.

**Our angle:** "For the pilot, we operate under your security framework and sign a DPA. As we scale, we commit to SOC 2 certification."

---

## Recommended Next Steps

1. **Immediate:** Create clean one-pager for Friday meeting context
2. **This week:** Draft a simple data retention/deletion policy
3. **If pilot approved:** Begin DPA negotiation with Cision legal
4. **If partnership scales:** Budget SOC 2 Type II ($30-50K, 6-12 month timeline)

---

## Open Questions for Lukas
- Does Cision/BW have a standard vendor security questionnaire? Can we get it early?
- What's their minimum security bar for a pilot vs full partnership?
- Who on their side handles vendor security review? (InfoSec team, legal, procurement?)
- Have they onboarded AI tool vendors recently? What was the process?
