A findings report is a map of your weakest points, and engagement access reaches systems you would show to very few people. This page explains in practical terms how we handle the data you give us, the results we produce, and the security of our own operations.
Six commitments that govern client data from the first scoping call to final destruction. Each one is written into our engagement terms, so you can hold us to it.
We ask for the minimum an engagement needs to run well: named assets, relevant credentials, points of contact. We do not take bulk exports, standing database access, or copies of production data when a narrower artifact answers the same question, and we tell you when something you offered is more than we need.
Client material moves over encrypted channels and rests on encrypted storage. Engagement data lives on full-disk encrypted machines and in encrypted project stores, transfers run over TLS or the engagement VPN, and highly sensitive items such as credentials or exploit detail are additionally encrypted at the file level before they move.
The consultants staffed on your engagement are the only people with access to your systems and materials. Access is granted when the engagement starts, scoped to what the work requires, and removed when it ends. There is no shared pool of client data that anyone in the firm can browse.
Every engagement carries a written retention schedule agreed before work begins. Working data, captured traffic, and interim notes are destroyed on that schedule. The final report is retained only as long as agreed, then destroyed as well. You can request earlier destruction at any time and receive written confirmation once it is complete.
What we find in your environment stays yours. Findings are not shared with other clients, folded into research, quoted in marketing, or disclosed to any third party without your written instruction. Vulnerabilities we discover in your systems belong to your report and nowhere else.
Reports are delivered through an encrypted channel agreed at scoping, never as a plain email attachment. Distribution is limited to the recipients you name, and we confirm receipt with you. If your team prefers delivery into your own secure repository, we work inside your controls rather than around them.
Confidentiality on an engagement is not one clause in a contract. It is a set of operating rules that determine who can see your data, what we may do with it, and what we may say about you afterward. The rules here apply to every engagement, at every size, without exception.
They matter because of what testing produces. Until every issue in it is fixed, a findings report is a working exploitation guide for your environment. We treat it with the care you would expect for credentials or source code, because in the wrong hands it is worth more than either.
A firm that holds pre-authorized access into client networks and reports full of unfixed vulnerabilities is an attractive target. We plan our own security on that assumption. The practices below are the ones that matter most for the data you entrust to us, described as controls we operate rather than logos we display.
The same people who attack client environments scrutinize ours. Internal infrastructure receives the adversarial review we sell, and changes to how we store or move client data are examined before they happen, not after.
Every engagement runs under a mutual NDA and a master services agreement that define confidentiality, data handling, liability, and explicit authorization to test. We sign the NDA before scoping, so the details you share to size the work are protected from the first conversation.
Data processing terms are available on request and can be reviewed with your counsel. Where you carry regulatory obligations of your own, whether statutory rules, sector requirements, or contractual flow-downs from your customers, we align our terms with them rather than asking you to accept a template.
We describe our controls as practices, not badges, and we do not claim certifications on this site. If your procurement or security team needs a deeper review, we will walk them through our security posture, including our current certification status, under NDA.
We hold ourselves to the standard we recommend to clients. If you believe you have found a security issue in our infrastructure, our services, or this website, write to [email protected]. That address reaches the engineers who run our systems, and good-faith reports are never met with legal threats.
Our responsible disclosure page explains what to include in a report, the ground rules for good-faith research, and what you can expect from us in response.
Send the security questionnaire, bring your counsel, ask about our controls. We answer in writing before any engagement begins.