// Compliance
Privacy Policy.
Last updated: July 19, 2026. How we manage client telemetry, vulnerability records, and scoping data.
1. Information We Collect
We collect information necessary to scope, execute, and deliver our security assessments. This includes:
- Corporate contact details (names, business email addresses, and phone numbers).
- Technical environment scoping data (IP addresses, domain names, API endpoints, and repository metadata).
- Temporary test credentials or restricted authentication tokens provided for testing.
- Temporary read-only access to source code repositories, cloud infrastructure environments (AWS, GCP, Azure), and server architectures required for white-box auditing.
- Assessment telemetry, logs, and vulnerability evidence collected during active testing.
2. Vulnerability Data Protection
Security vulnerabilities identified during our audits constitute highly sensitive data. We enforce the following isolation standards:
- Vulnerability evidence, proof-of-concept scripts, and draft reports are stored on encrypted offline or private networks.
- Access to client vulnerability data is restricted strictly to assigned operators on a need-to-know basis.
- Drafts are transmitted exclusively via secure channels agreed upon during scoping (such as PGP-encrypted emails or secure portals).
3. Data Retention and Destruction
We adhere to a strict data minimization and clean-slate policy:
- Temporary credentials and access tokens are deleted immediately upon completion of testing and verification.
- Source code clones, repository access, and cloud environment read-tokens are revoked and securely wiped from our systems immediately after the final report is delivered.
- Detailed attack telemetry and active raw scan logs are securely purged within 30 days of the engagement closure.
- Final deliverables and signed verification certificates are retained securely for a period defined in our mutual agreement to support compliance audits, after which they are destroyed.
4. NDA and Mutual Confidentiality
All security engagements are governed by a Mutual Non-Disclosure Agreement (MNDA) executed prior to any scoping conversation. We do not disclose client identities, findings, or engagement parameters to any third party without explicit written consent, unless required under coordinated responsible disclosure terms for public advisories where the vendor is anonymous.
5. Your Data Rights
You can request details of the technical information we hold on your environments or ask for the immediate disposal of non-archival engagement records at any time by contacting our security team directly.
6. Contact
For inquiries related to our privacy protocols or data handling, email our security team at: