How we handle what you trust us with.
We ask organisations to let us look at their external exposure. That only works if we are clear about what we collect, where it goes, and who can see it.
What we do.
Least privilege by role
Access to subject and case data is scoped by role, and every view of a subject record is logged.
Encryption in transit and at rest
TLS for everything on the wire. Evidence storage is encrypted and access-controlled per organisation.
Tenant isolation
One organisation's evidence is never used to enrich another's graph.
Retention you choose
Evidence retention windows are configurable, and deletion removes the artifact and its derived scores together.
Reporting a vulnerability.
If you have found a security issue in our platform or this website, we want to hear about it before anyone else does.
- Where to send it
- [email protected]. Include enough detail to reproduce it.
- What we promise
- An acknowledgement within two business days and an honest assessment, including if we disagree that it is an issue.
- What we ask
- Give us a reasonable window before publishing, and do not access data belonging to anyone else while testing.
We do not promise perfect security any more than we promise perfect visibility.
We promise that we will tell you what happened, quickly, and in plain language.
More evidence. Less guessing.
We don't promise perfect visibility. We promise better understanding.