Skip to main content

This page is also available in Türkçe.

Switch language
Security

Security & Compliance

Handling data that is sensitive by definition — and the controls that make it safe to work with.

We handle data that is sensitive by definition. The controls below are not a compliance appendix — they are the reason a security team can use this platform without creating a second incident.

How we protect breach intelligence data

Masked evidence by default

Credentials are masked in the interface and in exports. Analysts act on findings without ever needing to read a working password.

Encryption in transit and at rest

All traffic is TLS-protected; stored data is encrypted at rest.

Least-privilege access

Access to intelligence data is scoped by role and tenant, granted on need, and reviewed.

Audit logging

Access to sensitive records is logged and retained for review.

Tenant isolation

Each customer’s assets, findings and reports are separated; matching never crosses tenants.

Data minimization

We retain what is needed to detect and evidence exposure, and no more.

Operational security

Collection infrastructure is segmented from the customer-facing platform. Changes are reviewed before deployment, dependencies are monitored for known vulnerabilities, and production access requires multi-factor authentication.

Report a vulnerability

If you believe you have found a security issue in our platform or this website, please report it to us directly rather than disclosing it publicly. We will acknowledge your report, keep you updated while we investigate, and credit you if you would like us to.

Please include enough detail to reproduce the issue. Do not access, modify or exfiltrate data belonging to others, and do not run tests that degrade service for our customers.

Questions about security or compliance?

Security questionnaires, data processing agreements and architecture questions are handled by our team directly. Get in touch and we will route you to the right person.

Breach assessment

Run it against your own domains

A time-boxed assessment on the domains you register — your real exposure, not synthetic or sample data, and no procurement cycle to start one.

  1. A scoping call Which domains, brands and suppliers matter, and what you need to be able to prove internally.
  2. A live walkthrough The console, your exposure, and how a finding moves from detection to a closed ticket.
  3. A real report Sanitized, masked and structured the way you would present it to your leadership.
  4. A clear next step If the exposure does not justify a programme, we will tell you that.

Masked evidence by default · Tenant-isolated · Encrypted in transit and at rest · Nothing deployed in your estate