Secure Intake
SHP intake establishes whether a device and requested certification target are suitable for a certification engagement.
The process is deliberately narrow.
Information is collected because it is required to establish scope, eligibility, logistics, or certification context—not simply because it might be useful.
What intake establishes
Before hardening begins, SHP needs enough information to determine:
- the device being presented
- the intended certification target
- the applicable platform scope
- whether the engagement can proceed
- any relevant delivery or handling requirements
Intake does not itself establish certification eligibility.
Final certification depends on the applicable hardening, verification, and certification requirements.
Minimum necessary information
SHP follows a minimum-information approach.
Normal intake should not require:
- account passwords
- disk-encryption passphrases
- private cryptographic keys
- unrelated client documents
- unrelated personal files
- access to unrelated online accounts
Where information is not required for the certification engagement, it should not be collected merely for convenience.
Device data
A device submitted for hardening may contain existing information that lies outside the certification purpose.
The engagement should therefore establish the required device preparation and handling conditions before work begins.
Where a certification target requires installation, reinstallation, storage reconfiguration, encryption changes, or other destructive preparation, that requirement must be made explicit before the relevant operation is performed.
Certification work must not silently imply preservation of existing data.
Secrets
Customer secrets should not become SHP operational dependencies unnecessarily.
Where credentials or cryptographic secrets are required for the resulting system, ownership and control should remain with the customer wherever the applicable implementation permits.
SHP certification signing keys are separate from customer-controlled secrets.
Scope before access
Access to a device does not create permission to inspect unrelated information.
The certification engagement remains bounded by its defined purpose.
Additional access should not be assumed merely because the device is physically or remotely available during the engagement.
Delivery method
The delivery method may vary according to the service actually offered and the requirements of the certification target.
Any remote, in-person, drop-off, shipment, or guided workflow must preserve the same certification rules.
Changing the delivery method does not change the standard.
Before proceeding
The certification target, applicable service, preparation requirements, and material destructive operations should be understood before hardening begins.
If the requested device or target falls outside the currently supported certification scope, the engagement cannot simply be treated as supported by analogy.
New platform support requires formal specification.