Pentest Today.
security policy

Data Handling & Classification Policy

data-handling.md·SOC 2 · CC6.5

Generate a Data Classification & Handling Policy with sensitivity tiers and per-tier rules for storage, transmission, and disposal — including the named encryption minimums and the data-minimization rule.

What's in the policy

Classifies data by sensitivity and defines handling, storage, and disposal rules for each tier.

✓Data classification tiers (e.g. public → restricted)
✓Labeling and handling requirements per tier
✓Storage and transmission controls
✓Retention and secure disposal
✓Least-privilege access and data minimization
✓Restricted data kept out of non-production environments
Mapped toSOC 2 (CC6.5)ISO 27001 (A.5.12)GDPRHIPAA

What the document actually says

These are the standing requirements every generated copy of the document is written from — the clause text itself, not a description of it. The document you receive is drafted on top of them: it expands on them and fills the current-state detail from your intake, and the generator is instructed to keep them, to state them fully, and never to claim a certification or invent a fact you did not supply.

The four levels, and the rule attached to each

Data is classified into the following levels, and handling requirements follow the classification: | Level | Examples | Handling | … | Restricted | Customer data, personal data, secrets, credentials | Encrypted; strict least-privilege access; never in non-production | | Confidential | Internal financials, source code, contracts | Access on need-to-know; encrypted in transit | | Internal | Internal docs and communications | Default for company data; not for public release | | Public | Marketing, published docs | No restriction |
SOC 2 CC6.1 · ISO 27001 A.5.12, A.5.13 — four levels with the obligation written into the row rather than left to judgement, including the line keeping customer data out of non-production entirely.

Encryption standards

- Data is encrypted in transit using TLS 1.2 or higher; plaintext protocols are disabled. - Data is encrypted at rest using AES-256 (or an equivalent industry standard) for restricted and confidential data. - Encryption keys are managed by a dedicated key-management service, access-controlled, and rotated per the provider's guidance.
SOC 2 CC6.7 · ISO 27001 A.8.24 — a minimum TLS version for data in motion, a named algorithm for data at rest, and keys held in a managed service, in place of the bare word “encrypted”.

Who may hold it, and how little of it you keep

- Access to restricted data is limited to the smallest set of personnel and services with a need to know, per the Access Control Policy. - Only the minimum data necessary is collected, processed, and retained (data minimization). - Restricted data is not copied to personal devices or unapproved services.
SOC 2 CC6.3/CC6.7 · ISO 27001 A.5.10 · GDPR Article 5(1)(c) — minimization stated at collection and not only at deletion, and services counted alongside people as things that hold access.
AWS RDS + S3 + Cloudflare

Filled in for a real stack

Placeholder

Types of customer data processed: To be confirmed. Encryption: To be confirmed. Hosting / storage: To be confirmed.

Resolved

Types of customer data processed: account names, work email addresses, billing details, and product usage events; no health records, no card numbers. Encryption: TLS 1.3 terminated at Cloudflare, AES-256 at rest through KMS on RDS and S3. Hosting / storage: Postgres on RDS in eu-west-1, uploads in a private S3 bucket.

What the auditor asks for alongside it

Which stores hold restricted data, and where the boundary around them sits.
The architecture and data-flow drawing built from the hosting setup you describe at intake. It puts the stores it recognises — database, cache, object storage — inside a hosting trust boundary, with named third parties outside it. The table says what may live at each level; the drawing says where those things are.
The encryption answer your team sent a customer, and the document standing behind it.
The drafted questionnaire answers. The encryption question routes to the encryption summary you supplied at intake, and any question that maps to a known topic records the document or intake area it rests on, so the answer and its source travel together.
Proof that the transport rule holds on the endpoints anyone can reach.
The external scan of your approved targets. An HTTPS endpoint that returns no Strict-Transport-Security header is written up as a medium-severity finding — the distance between a policy saying TLS is required and a browser that would still accept a downgrade.
A specific list of the customer data you process, not a category name.
The current-implementation section of this document, written from the customer data types you enter at intake. The AI readiness pack restates the same list from that one field, so what you tell a security reviewer and what you tell an AI-vendor reviewer cannot quietly diverge.

Where these documents go stale

This document is written against the data you held on the day you wrote it, and classification is what drifts first. A field is added to a signup form. A support tool starts accepting attachments. An analytics event begins carrying an account identifier. A warehouse copy is stood up so finance can run its own numbers. Each of those creates somewhere new that restricted data lives, and the table never hears about any of them. The clause that ages worst is the one barring customer data from non-production: one production dump restored into staging to chase a bug contradicts it, and nobody opens the policy that afternoon. Re-validating it means re-listing your data types against the four levels, redrawing the architecture when a store appears, and checking where copies of production actually sit.

From intake to enterprise-ready in three moves
01

Tell us about your stack

Answer a short intake — cloud, data types, tools. No agents to install.

02

We generate a tailored draft

Not a blank template: a document written for your environment and pre-mapped to controls.

03

Review, edit, and share

Export it or attach it straight to an enterprise security review or questionnaire.

Data Handling & Classification Policy, answered

What is a data classification policy?

A data classification policy sorts the data an organization holds into sensitivity levels and attaches a handling rule to each level, so decisions about encryption, access, and storage follow from the label instead of from whoever is asked. Nearly every other control assumes the classification already exists.

What are the data classification levels?

Four levels cover most software companies: restricted, confidential, internal, and public. The generated table places customer data, personal data, secrets, and credentials at restricted; internal financials, source code, and contracts at confidential; everyday company documents at internal; and published material at public, each with its own rule.

Does SOC 2 require a data classification policy?

In substance, yes. The CC6 criteria assume you already know which information is sensitive before you can demonstrate it is protected, so an auditor asks for the scheme, the handling requirement attached to each level, and evidence that restricted data is genuinely treated differently from the rest.

What is the difference between data handling and data retention?

Handling governs classification, storage, transmission, and who may touch which level. Retention governs how long each type is kept and how it is destroyed at the end. In the generated pack they are one file — retention and disposal is a numbered section of the Data Handling Policy — which is the arrangement most reviewers expect.

Does this policy cover PII and PHI?

Personal data sits at the restricted level, so the strongest rules apply to it: encrypted, least-privilege access, and never in a non-production environment. The baseline does not enumerate HIPAA-specific safeguards, so if you process protected health information, treat those as an addition made on top of this scheme.

Where do encryption and key management get covered?

Here, in this document. Encryption standards are a numbered section of the Data Handling Policy rather than a separate file: a minimum TLS version for data moving, a named algorithm for data sitting still, and keys held in a dedicated key-management service that rotates them.

How does Pentest Today generate the policy?

Answer a short intake about your stack and we generate a tailored draft — not a blank template — pre-mapped to the controls your framework requires. You review, edit, and export it.

Can I edit the generated policy?

Yes. Every document is a starting draft you can edit, brand, and export. It's written to be review-ready but stays fully under your control.

Free · no account

Start your Pentest

Our agent swarm and human experts test your endpoints and deliver an audit, fast.

Generate your full security policy pack.

Get the data handling & classification policy plus everything else an enterprise security review asks for — generated from your real environment.