~/trustTrust

We Hold Your Unfixed Vulnerabilities. Here Is How We Protect Them.

During an engagement we are one of the highest-value targets connected to your business. A security firm that cannot describe its own controls in detail should not be trusted with that position, so here are ours.

Engagement data

Your findings and evidence

What we commit to for the vulnerability data, evidence and reports produced during your engagement. Retention and destruction are set out in the statement of work.

Storage
Findings and evidence are held on encrypted storage we control. Nothing is stored with a third-party reporting vendor.
Separation
One encrypted volume per client. There is no shared clients directory.
Devices
No client data on personal machines. Full disk encryption on every device used for engagement work.
Testing infrastructure
Fresh, isolated infrastructure per engagement, destroyed when the engagement closes. Never reused between clients.
Access
Least privilege. A tester sees only the engagement they are assigned to.
Transfer
Reports delivered over an authenticated channel, never as an unprotected email attachment.
Credentials
Test accounts you issue are used only for the engagement, and we ask you to disable them at close.
Retention
Evidence destroyed 90 days after the engagement closes unless you ask us to keep it. Reports retained only as long as your contract requires.
This website

How this site is built

Content is served from our own infrastructure, with no third-party platform between you and this page.

Headers
Content Security Policy with hashed inline scripts, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and cross-origin isolation headers.
Third parties
No trackers, no advertising pixels, no session recording, no third-party scripts. Fonts are self-hosted, so reading this page makes no request to a font CDN.
Cookies
No cookies are set when you browse this site, so there is no cookie banner to dismiss.
Content
Held on infrastructure we control. No third-party content or marketing platform stores it.
Disclosure
A published responsible disclosure policy and a security.txt. Report an issue in anything we run and we will respond and credit you.
Contracts

Before anything starts

Mutual NDA
Available before the first detailed conversation. Ask and we send it first.
Written authorization
Authorization letter and rules of engagement signed before any testing begins. No signature, no testing.
Liability
Capped in the master services agreement, with the cap stated plainly rather than buried.
Subcontractors
If anyone outside the core team works on your engagement, they are under the same confidentiality obligations, and we tell you in advance.
Questionnaires
Send yours and we complete it properly. We do not return boilerplate.

Full wording is on the terms page and in the signed agreement. Procurement questions go to [email protected].

Procurement questions?

Send your security questionnaire and we will complete it properly rather than returning boilerplate.

Contact
contact.log

No form, no sales desk. The person who answers is the person who would run your engagement.

Profiles
XLinkedIn
Book a scoping call

30 minutes, fixed price after. No questionnaire.