SecureBlockLog inStart a pentest
Trust Center

How we protect your data.

You hand us your scope, your credentials, and your findings. Here is what we do to keep all of that safe — and how to report a vulnerability if you find one.

Certifications

Independently attested.

ISO 27001:2022

SecureBlock's information security management system is certified against ISO 27001. Certificate available on request.

SOC 2 Type II

Annual SOC 2 Type II report covering security, availability, and confidentiality trust services criteria.

GDPR

Full GDPR compliance programme with published DPA available before commercial engagement.

Controls

What we actually do.

Data encryption

All customer data encrypted in transit (TLS 1.3) and at rest (AES-256). Per-tenant KMS keys with automatic rotation every 90 days.

Access control

Least-privilege model with SSO-required access, MFA on all human accounts, and just-in-time elevation for privileged operations with full audit logging.

Data lifecycle

Engagement data isolated per tenant, deleted 90 days after the retest window closes unless the customer requests earlier deletion or extended retention.

Responsible disclosure

Found something? Tell us.

We run a formal disclosure programme for vulnerabilities in the SecureBlock platform. In-scope reports get acknowledged within 24 hours and remediated on a schedule that matches severity.

Program scope
  • In scope: app.secureblock.io, api.secureblock.io, and secureblock.io.
  • Out of scope: customer tenants (which are subject to their own engagement rules), third-party services, denial-of-service attacks, and social engineering of employees.
  • SLA: initial acknowledgment within 24 hours. Critical fixes within 7 days. High within 30 days. Others on a best-effort basis.
Hall of fame

Thanks to the researchers who've helped us.

@n3rvous@byte0@ravena@0xkai@sig-null@piprock@marisec@tempo

Want to be on this list? See the disclosure policy above.