Security & data handling
You are trusting us with your systems. Here is how we treat them.
An engagement touches the things you care about most. So every engagement is scoped in writing before anything starts, tested with the least access that gets the job done, and closed with your evidence staying where it belongs — with you.
Four commitments
Least access. Written scope. Your evidence stays yours.
Only the access the work needs.
An external review needs no access at all — no agent, no credentials, no VPN. We look at what an attacker on the internet can see, nothing more.
For internal work, testing runs on a node inside your network that you control. Any credentials you grant for authenticated checks are stored and used on that node only; they are never sent to us.
Nothing starts without a written scope.
Every engagement is defined in writing first: the targets, the testing window, what is in and out of bounds, and who to call if something looks wrong during the test. You approve it before we touch anything, and the scope is enforced technically — the engine will not test an address that is not on the list.
The engine is built for hostile networks.
We run the technical side of every cyber review with Cyentrix Scan, our own engine, rather than a stack of third-party SaaS scanners. Raw evidence stays on the node; only the verified, sanitised findings we put in your report leave your network.
What we keep, and for how long.
We keep what is needed to deliver and re-test the engagement: the findings, the report and the evidence behind each finding we reported. We do not keep raw scan output, and we do not keep credentials. Retention is agreed in the scope; the default is to delete engagement data after the re-test is complete, with a copy left with you.
Responsible disclosure
Found something in our systems?
We would rather hear it from you. Email security@cyentrix.com with what you found and how to reproduce it. We acknowledge reports promptly, will not pursue good-faith research, and will credit you if you want us to.
Questions before you engage?
- ✓ Ask for the scope template before booking — you will see exactly what we test and how.
- ✓ We are happy to sign your NDA or provide ours.
- ✓ Want to see the engine first? How Cyentrix Scan works →
Start with zero access
See what’s exposed from the outside.
The free external review needs nothing from you but a domain. If it is worth going further, we scope the rest in writing first.
Get my free exposure review → Talk to Cyentrix