Trust and privacy

What we hold, and what we do not.

Security findings are sensitive by definition: they are a list of the ways into your systems. We treat them that way, and we are deliberately careful about how much of our own arrangement we describe in public.

(a)
Your identity is kept apart from your findings
Who you are and what we found about your systems are held separately, and are not stored together. Someone who reached one side of that boundary would not simply be handed the other. This is the single most important thing we do, and it is a design decision rather than a policy promise.
(b)
The agent reports findings, not content
It inspects the state of a machine and sends back what it concluded. Your files, your mail and your databases are never read and never leave. There is nothing in our systems that contains your business data, because we never collect it.
(c)
Access is limited and recorded
Access to customer findings is restricted to what a task actually requires, and sensitive operations leave an audit trail. We can answer the question of who looked at what, and when, because it is written down as it happens.
(d)
Protected to current industry standard
Data is protected in transit and at rest using established, current practice, and the arrangement is reviewed as that practice moves. We do not publish the specifics: a detailed description of our controls is more useful to an attacker than it is to you.
(e)
Held in the EU
Your findings are stored and processed on infrastructure we operate within the European Union, under EU data protection law.
(f)
Yours to remove
You can uninstall the agent at any time and it stops reporting immediately. Ask us to delete the findings we hold and we will, and we will confirm when it is done.

We would rather answer a specific question directly than publish a document that reads well and says little. If your procurement or audit process needs detail we have not put on this page, ask us and we will answer it properly.