How we protect your data.
You hand us your scope, your credentials, and your findings. Here is what we do to keep all of that safe — and how to report a vulnerability if you find one.
Independently attested.
ISO 27001:2022
SecureBlock's information security management system is certified against ISO 27001. Certificate available on request.
SOC 2 Type II
Annual SOC 2 Type II report covering security, availability, and confidentiality trust services criteria.
GDPR
Full GDPR compliance programme with published DPA available before commercial engagement.
What we actually do.
Data encryption
All customer data encrypted in transit (TLS 1.3) and at rest (AES-256). Per-tenant KMS keys with automatic rotation every 90 days.
Access control
Least-privilege model with SSO-required access, MFA on all human accounts, and just-in-time elevation for privileged operations with full audit logging.
Data lifecycle
Engagement data isolated per tenant, deleted 90 days after the retest window closes unless the customer requests earlier deletion or extended retention.
Found something? Tell us.
We run a formal disclosure programme for vulnerabilities in the SecureBlock platform. In-scope reports get acknowledged within 24 hours and remediated on a schedule that matches severity.
- In scope: app.secureblock.io, api.secureblock.io, and secureblock.io.
- Out of scope: customer tenants (which are subject to their own engagement rules), third-party services, denial-of-service attacks, and social engineering of employees.
- SLA: initial acknowledgment within 24 hours. Critical fixes within 7 days. High within 30 days. Others on a best-effort basis.
Thanks to the researchers who've helped us.
Want to be on this list? See the disclosure policy above.
