We Hold Your Unfixed Vulnerabilities. Here Is How We Protect Them.
During an engagement we are one of the highest-value targets connected to your business. A security firm that cannot describe its own controls in detail should not be trusted with that position, so here are ours.
Your findings and evidence
What we commit to for the vulnerability data, evidence and reports produced during your engagement. Retention and destruction are set out in the statement of work.
- Storage
- Findings and evidence are held on encrypted storage we control. Nothing is stored with a third-party reporting vendor.
- Separation
- One encrypted volume per client. There is no shared clients directory.
- Devices
- No client data on personal machines. Full disk encryption on every device used for engagement work.
- Testing infrastructure
- Fresh, isolated infrastructure per engagement, destroyed when the engagement closes. Never reused between clients.
- Access
- Least privilege. A tester sees only the engagement they are assigned to.
- Transfer
- Reports delivered over an authenticated channel, never as an unprotected email attachment.
- Credentials
- Test accounts you issue are used only for the engagement, and we ask you to disable them at close.
- Retention
- Evidence destroyed 90 days after the engagement closes unless you ask us to keep it. Reports retained only as long as your contract requires.
How this site is built
Content is served from our own infrastructure, with no third-party platform between you and this page.
- Headers
- Content Security Policy with hashed inline scripts, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and cross-origin isolation headers.
- Third parties
- No trackers, no advertising pixels, no session recording, no third-party scripts. Fonts are self-hosted, so reading this page makes no request to a font CDN.
- Cookies
- No cookies are set when you browse this site, so there is no cookie banner to dismiss.
- Content
- Held on infrastructure we control. No third-party content or marketing platform stores it.
- Disclosure
- A published responsible disclosure policy and a security.txt. Report an issue in anything we run and we will respond and credit you.
Before anything starts
- Mutual NDA
- Available before the first detailed conversation. Ask and we send it first.
- Written authorization
- Authorization letter and rules of engagement signed before any testing begins. No signature, no testing.
- Liability
- Capped in the master services agreement, with the cap stated plainly rather than buried.
- Subcontractors
- If anyone outside the core team works on your engagement, they are under the same confidentiality obligations, and we tell you in advance.
- Questionnaires
- Send yours and we complete it properly. We do not return boilerplate.
Full wording is on the terms page and in the signed agreement. Procurement questions go to [email protected].
Procurement questions?
Send your security questionnaire and we will complete it properly rather than returning boilerplate.