SNC Logo
Privacy Policy

Security & Data Sovereignty

Institutional protocols for data protection, security controls, and telemetry auditing under Project AEGIS.

Security Architecture

Document Metadata

DOCUMENT ID:SNC-POL-2026-V2
CLASSIFICATION:RESTRICTED
EFFECTIVE DATE:2026-07-13
COMPLIANCE:SOC 2 TYPE II
For inquiries concerning data protection, sovereign cryptography, or audit trail verification, contact our Data Security Officer at [email protected].

Institutional Trust Statement

Six Nine Construction operates under the highest parameters of execution precision, extending not only to physical concrete and steel but to digital architectures. As operators of Project AEGIS, our proprietary infrastructure command center, we treat client, supplier, and contractor data as highly sensitive, critical industrial assets.

This policy outlines our programmatic and organizational commitments to data security, telemetry sovereignty, and strict compliance with national and regional data protection frameworks.

[01]

Data Security & Cryptographic Isolation

SNC implements enterprise-grade physical and cryptographic controls to secure operational records, contractor documents, and structural telemetry from unauthorized intrusion.

Encryption Standards

All data in transit is encrypted using transport layer security (TLS 1.3). Data at rest within our servers and database clusters is encrypted using AES-256 with key rotation cycles managed via HSMs.

Zero-Trust Network Architecture

Project AEGIS operates on isolated VPC networks, protecting client tender databases and financial records behind adaptive multi-factor authentication (MFA) and strict role-based access control (RBAC).

[02]

Compliance & Security Audits

We validate our technical controls through routine, independent third-party audits and rigorous testing parameters. Our platforms are designed to align with international safety and security frameworks.

Audit Protocols & Verification

SOC 2 Type II Compliance

SNC undergoes annual independent audits covering security, availability, and processing integrity of the Project AEGIS system.

Penetration Testing

Semi-annual white-box and black-box penetration assessments are conducted by CREST-accredited security engineers.

ISO 27001 Alignment

Our Information Security Management System (ISMS) operates in strict conformity with the ISO/IEC 27001:2022 international standard.

[03]

Platform Telemetry & Logging

Project AEGIS tracks real-time platform actions to compile permanent audit trails, ensure operational accountability, and prevent fraudulent procurement actions.

Active Telemetry Streams

The following log structures are generated continuously and retained for a minimum of 7 years in compliance with corporate engineering regulations:

TELEMETRY TYPEDATA POINT EXAMPLESENCRYPTION STATUS
ACCESS LOGSIP Address, MFA Challenge Timestamps, User AgentAES-256-ROTATED
TENDER AUDITSBid-bond verification hashes, timestamped proposal submissionsSHA-256 INTEGRITY
SYSTEM TELEMETRYAPI latency parameters, query payloads, database state checksANONYMIZED
OPERATIONAL LOGSContractor check-ins, plant dispatch coordination requestsAES-256
[04]

Stakeholder & User Rights

We guarantee transparency and control to all registered portal users, commercial partners, and contractors. You have direct control over your digital footprint on the AEGIS platform.

01.

Right to Inspect

Request full structural transcripts of all corporate records and personal telemetry stored on our systems.

02.

Right to Restrict

Disable optional system telemetry tracking and pipeline automations tied to your contractor profile.

03.

Right to Purge

Initiate formal requests to delete profile records, subject to regulatory tax and engineering archival laws.

[05]

Regulatory Alignments

SNC operates globally, adapting its compliance postures to satisfy regional data protection statutes:

  • Zimbabwe Cyber Security & Data Protection Act [Chapter 12:07]

    Full compliance with the statutory rules regulating data controllers, trans-border data streams, and systemic disclosure events.

  • SADC Model Law on Data Protection

    Ensuring aligned cross-border data transfer security parameters for projects spanning Zambia, Mozambique, and South Africa.

  • EU General Data Protection Regulation (GDPR)

    Adhering to strict European security controls for international capital sponsors and joint-venture partners operating in the region.