1 min read
Overview
As a security company we handle our customers’ most sensitive information — their vulnerabilities, infrastructure maps and incident records. We earn that trust by applying the same standards to our own operations.
Core controls
- All customer data is encrypted in transit and at rest.
- Engagement data is accessed only by assigned team members, on a least-privilege basis.
- Multi-factor authentication (hardware or app-based) is mandatory on every account.
- Testing tools and evidence are kept in isolated, purpose-built environments.
- At the end of an engagement data is securely destroyed within the contractual retention period.
Documents
We share our NDA, data processing agreement (DPA) and security questionnaire responses on request. Contact [email protected].