Start a build Book an assessment
Services Work Trust Insights Company Contact Start a build Book an assessment

Trust is a posture, not a badge.

We are asking to test your most sensitive systems, so it is fair to ask the same questions of us. This page states plainly how we handle your data, how to report a vulnerability in our own systems, and what we do and do not claim.

Confidentiality

NDA before scoping. Minimum necessary data handling. Encrypted evidence storage with a named access list and agreed destruction timeline.

Integrity

Findings are reproducible and evidenced. Test windows, actions taken and scope changes are recorded for the engagement file.

Least disruption

Testing is rate-limited and windowed to avoid availability impact. Destructive techniques require explicit written approval.

Transparency

You get the raw truth: what we tested, what we could not test, what we assumed, and what remains unverified.

Responsible disclosure

Found a vulnerability in our systems?

Tell us before you tell anyone else. We will acknowledge your report, keep you informed while we fix it, and credit you if you would like the recognition. We will not pursue legal action against researchers who act in good faith within the boundaries below.

Report through the contact form and we will acknowledge it within one business day. A dedicated security inbox and PGP key are being provisioned.
Acknowledge your report within two business days, give you a named contact, keep you updated on remediation progress, and confirm when the issue is resolved. We do not report good-faith research to law enforcement.
Our public website and any service we operate and clearly identify as ours. Testing must be limited to your own accounts and must not access, modify or retain data belonging to anyone else.
Denial-of-service or load testing, social engineering of staff or clients, physical attacks, third-party services we rely on, automated scanner output without a demonstrated impact, and anything involving real customer data.
Affected asset, a clear description of the issue, steps to reproduce, the impact you believe it has, and any proof-of-concept material. Please avoid including third-party personal data.
We ask for 90 days before public disclosure, or sooner by mutual agreement once a fix is deployed. If we cannot fix an issue in that window we will tell you why and agree a revised date with you.
We do not currently operate a paid bounty programme. We will state this clearly at the point of first contact so nobody invests effort expecting payment.
Data handling

How your data is treated during an engagement.

AreaPractice
AgreementsMutual NDA and a signed rules-of-engagement document before any testing begins
AccessNamed testers only; credentials issued per engagement and revoked at closure
Evidence storageEncrypted at rest and in transit, access-restricted, retained only as long as needed for retest and audit
Test dataTest accounts and synthetic records preferred; production personal data is not extracted or copied out
Third partiesNo client data is shared with subcontractors without prior written approval
DeletionEvidence destroyed on the timeline agreed in the engagement contract, with written confirmation
Incident handlingAny accidental exposure during testing is reported to your named contact immediately, in writing
Compliance & subprocessors

Claims we can evidence, and tools we rely on.

We only publish a compliance claim when we hold the certificate or report that supports it.

Compliance statements
FrameworkStatus
ISO/IEC 27001Alignment only — certification not held
SOC 2 Type IINot held
Cyber insuranceDetails to be confirmed
GDPR / data processingDPA available on request
Subprocessors
ServicePurpose
Cloud hosting providerHosting of infrastructure and evidence storage — provider to be named
Business email providerEngagement communication and report delivery — provider to be named
Analytics (this website)Aggregate, privacy-respecting measurement only — provider to be confirmed

Replace with your real subprocessor list, including locations and safeguards.

Report handling

What happens after you report a vulnerability.

A disclosure policy is only credible if the process behind it is published too. This is exactly what happens to a report that arrives in our inbox.

01

Acknowledgement

We confirm receipt within two business days and give you a named contact who owns your report until it closes.

02

Triage and reproduction

We reproduce the issue in a controlled environment, determine whether it affects customer data, and classify severity. If we cannot reproduce it we say so and ask for what we are missing.

03

Remediation

Fixes are scheduled by severity: critical within days, high within the current cycle. You keep your named contact and get updates without having to chase.

04

Verification and credit

We confirm the fix with you, agree the disclosure date, and publish credit with whatever name or handle you prefer.

05

Publication

If the issue was material we publish a short advisory after the fix ships, so the same mistake is harder for anyone else to make.

Questions we have not answered here?

Security questionnaires, DPAs and due-diligence packs are handled by a named contact, not a form letter.