Skip to content
Book a call

Trust

What we do with
your systems and your data

Every security review asks these questions and most vendors answer them in a questionnaire nobody else ever reads. Here are the answers in public, so you can check them before you ask.

Ask us anything elseRead a sample report

Authorisation

Nothing gets tested that you have not authorised in writing

We do not test without written authorisation

Every engagement begins with a written scope naming the systems, the window and the person authorising the test. No target is touched before that exists. If a system turns out to belong to a third party - a hosting provider, a SaaS platform, a payment processor - we stop and ask you to confirm you can authorise testing of it before we continue.

Scope is a boundary, not a suggestion

What is in scope is tested; what is not is not, even when it is tempting and even when it is obviously reachable. If we find that the interesting attack path leaves the agreed scope, you get told about the path - you do not get an unauthorised test of somebody else’s system.

During the test

How we behave inside your systems

Destructive actions

Anything with a real chance of affecting availability or altering data - stress testing, mass automated attempts, anything irreversible - is agreed in advance and in writing, or it does not happen.

Production systems

Where testing has to happen in production, we agree the window, the rate and an escalation contact before we start, and we stop on request. A test that takes your service down has failed at its job, whatever it found.

If we find something serious mid-test

Critical findings do not wait for the report. You hear about them when we find them, with enough detail to act, and the written finding follows.

Real customer data

We work on test accounts and test data wherever the system allows it. Where production data is unavoidable, we access the minimum needed to demonstrate the issue and we do not extract more than that.

Credentials you give us

Used only for the engagement, held only for its duration, and we will tell you which accounts we used so you can rotate them afterwards. Rotating them afterwards is good practice regardless of who tested you.

Who does the work

Named engineers on our own staff. Engagements are not subcontracted to a marketplace, and the person who scoped your test is the person who runs it.

Your findings

Where the results go, and who can see them

Where findings live

Findings, evidence and reports are held in CybeRapid, our own platform, and reach you through your own account in the customer portal rather than as attachments circulating in email. Access is per customer: your people see your engagements.

Confidentiality

We work under NDA as a matter of course, and will sign yours. What we find is yours: we do not publish it, we do not name you as a client without your permission, and we do not use your findings as examples anywhere without asking first.

Research we do publish

We publish aggregate analysis of our own engagement data - how often a class of flaw appears, how often fixes hold. Those figures are counts across hundreds of projects with no customer, system or finding identifiable in them, and they are the only thing from an engagement that ever becomes public.

When the engagement ends

Your report and its evidence remain available to you in the portal so you can produce it for an auditor without asking us. If you want the engagement data removed instead, ask and we will remove it and confirm when it is done.

Our own house

How we look after ourselves

A reasonable question to ask a security company is how it looks after itself. Administrative access to our systems requires two-factor authentication, access to customer data is limited to the people working on that engagement, and our own infrastructure is monitored and logged.

Engagement data lives in the platform, not on this marketing site, and the two are separate systems with separate access. Our hardening is verified automatically on a schedule rather than checked by hand, so it cannot quietly regress between reviews.

Reporting a problem

Found something in ours?

If you believe you have found a security problem in anything we run, please tell us at info@appsec-labs.com. We will acknowledge it, we will fix what needs fixing, and we will not send a lawyer at someone acting in good faith. Given what we do for a living, that is the only defensible position.

Have a question this does not answer?

Security reviews ask specific things, and a real answer beats a generic one. Send us the question - a person who does the work will answer it.

Ask a questionBook a callHow we test