Verification of authority
We check that the person who signs the authorisation is entitled to sign it: the commercial register, the ownership of the domains, a confirmation through an official channel.
Assets of third parties
Systems of hosting, cloud and SaaS providers are tested only within their published testing policies or with their consent.
Requests we decline
Testing of systems the requester does not own, recovery of other people’s accounts, surveillance and retaliation. Such requests are refused.
What you can check before you trust us
Offensive security is bought on trust, and trust should rest on what can be checked. This page states how we work with authorisation, with your data and with our own security, and says plainly what we do not claim.
02Your data
How engagement data is handled
Minimum collection
We record what proves a finding and nothing more. Personal data is masked in evidence wherever the proof survives it.
Encryption
Engagement data is stored encrypted. Reports and credentials are exchanged through a secure channel agreed in advance.
Access
Only the specialists assigned to an engagement have access to its data.
Retention
Working data is destroyed 30 days after the engagement is closed. The report is kept for as long as the contract says.
Confidentiality
Clients are not named and reports are not published without written consent.
Forms of this site
A request or an application sent through a form of this site is stored for 365 days and then deleted automatically.
03This website
Security of the site you are reading
No trackers
No advertising or analytics cookies and no third-party scripts, except the abuse check of the forms.
Strict content policy
A Content Security Policy without inline code, HSTS and isolation headers on every response.
Abuse check
The forms are protected by Cloudflare Turnstile. It starts when you begin to fill in a form or send it, not before.
No raw addresses
The IP address of whoever sends a form is stored only as a keyed hash and used for rate limiting only.
security.txt
Vulnerabilities in this site are reported as described in security.txt and in our disclosure policy.
Works without scripts
Every page can be read and navigated with JavaScript disabled. Only the forms need it.
04AI policy
How we use AI, and how we do not
Verified by people
The output of tools and models is verified by a specialist before it is reported.
No client data in public services
Client code, data and findings are never submitted to public AI services.
No training on client data
Nothing from an engagement is used to train models.
Disclosure
If AI-assisted tooling is part of an engagement, the proposal says so.
05Official channels
How to be sure it is us
Security companies are impersonated. These rules let you tell.
- We answer requests only from the channels listed on this page.
- We never ask for payment, passwords or remote access in a first reply.
- We never contact a company out of the blue about a vulnerability and ask for money. Anyone who does so in our name is not us.
- Every request has a reference of the form REQ-XXXX-XXXX. Quote it, and ask us to quote it.
06What we do not claim
No promise that cannot be kept
- We do not promise to find every vulnerability. A test is limited in time and scope, and the report says what was covered.
- We do not promise that a tested system cannot be breached.
- We do not claim endorsement by OWASP, MITRE, NIST, FIRST or any platform. We follow their public standards.
- We do not show logos of clients, certifications or partners that cannot be verified.
07Request
Tell us what needs testing
- Website check free of charge
- Reply within 1 business day
- NDA before any technical detail
- Fixed price for paid engagements
- No obligation
Request received
Reference
Keep the reference: we name it in all further communication with you.
What happens next
- A manager reviews the request and replies within 1 business day.
- We agree the scope, the rules of engagement and a secure channel for sensitive material.
- You receive a proposal with method, schedule and a fixed price. For the free website check you receive the authorisation to sign.
We never ask for payment, passwords or remote access in the first reply.