Data boundaries

What we need.
What we do not.

Trust starts with a smaller request. The first conversation needs context, not your invoices, credentials, or production data. If a deeper review makes sense, we explain the next evidence request before you share anything.

First conversation: no documents.You decide whether any later evidence is shared, where it lives, and when access ends.

A staged request

More evidence only when the decision needs it.

01 · ASSESS

Free spend assessment

Name, work email, company, broad spend or pressure, and any renewal timing are enough to decide whether a deeper review is sensible.

Useful context
  • Approximate software and AI spend
  • Renewal or cost-reduction trigger
  • Capability the business must preserve
Not needed
  • Invoices or contracts
  • Passwords or system access
  • Customer, regulated, or production data
02 · MAP

Savings Map evidence

For an agreed review, we request only decision-relevant evidence: a vendor spend export or selected invoices/order forms, renewal dates, seat totals, owners, and aggregated usage.

Preferred starting point
  • Client-prepared exports or screenshots
  • Aggregated usage and seat data
  • Selected documents tied to a decision
Sharing boundary
  • Use a client-controlled workspace
  • No public-form uploads
  • No unrestricted admin access
03 · VALIDATE

Validation

We use exported usage reports or client-prepared reports to test the signal. Individual-level license data is considered only when genuinely required for the approved question.

We test
  • Unused or duplicate seats
  • Renewal terms and notice windows
  • Usage against the required capability
We avoid
  • Raw email or message content
  • Unnecessary employee records
  • Permanent or shared credentials
04 · REPLACE

Replacement analysis

A replacement question needs business requirements, integrations and dependencies, data classification, reliability expectations, internal support capacity, migration constraints, expected AI/API consumption, and a fallback path.

Required for the decision
  • Outcome and capabilities to preserve
  • Operating and switching costs
  • Risk, ownership, and rollback plan
Default exclusion
  • No raw production content
  • No source code unless separately scoped
  • No access without specific approval

Client-controlled sharing

Keep the files in a workspace you choose.

Preferred exchange

When documents are needed, the preferred route is a folder in your Microsoft 365, Google Workspace, Box, or another approved data room.

  1. You choose the workspace and the documents.
  2. You grant access to a named person for the engagement.
  3. You can redact, restrict, or revoke access at any time.

Access boundaries

Shared passwords and unrestricted admin access are not part of the normal review.

  • Start with exports, screenshots, and aggregates.
  • Direct access is exceptional and needs specific approval.
  • If approved, it is named, time-limited, least-privilege, and preferably read-only.

AI and source material

Client data does not go to public AI tools.

Client source documents or identifiable client data are not submitted to public or consumer AI tools. Redacted or derived data is the default. Any AI use involving client data requires written client approval and an approved environment for the engagement.

Plain boundary: do not send client documents, customer records, credentials, or production content to an AI service unless the approved engagement process expressly permits it.

Retention

Where your workspace can hold the source material, SaaS Spartan avoids making a separate copy. SaaS Spartan-controlled working copies are deleted within 30 days after final delivery or termination, except for records required by a signed agreement or law.

Copies that remain in your own Microsoft 365, Google Workspace, Box, or data room stay under your controls; SaaS Spartan does not control those copies.

The public form

The basic inquiry form has no document upload. It sends the fields you choose to provide to Web3Forms so SaaS Spartan can receive and reply. Under Web3Forms’ current legal materials, submissions may be retained by that provider for up to three years.

The site is hosted through Cloudflare. The site requests Google Fonts from Google when the remote stylesheet is available. See the Privacy notice for the current site-processing description.

No method is risk-free. These boundaries reduce the amount of information collected and the access granted; they do not eliminate every technical, operational, or legal risk. Ask questions before sharing anything.
Questions or a concern

Email [email protected] before sending material you are unsure about.

Related pages

How the review works · Privacy notice