SecureBlock

我们如何保护您的数据。

您将范围、凭据和发现交给我们。以下是我们为保护这一切所做的事情——以及如果您发现漏洞应如何报告。

认证

独立认证。

ISO 27001:2022

SecureBlock's information security management system is certified against ISO 27001. Certificate available on request.

SOC 2 Type II

Annual SOC 2 Type II report covering security, availability, and confidentiality trust services criteria.

GDPR

Full GDPR compliance programme with published DPA available before commercial engagement.

控制措施

我们实际的做法。

Data encryption

All customer data encrypted in transit (TLS 1.3) and at rest (AES-256). Per-tenant KMS keys with automatic rotation every 90 days.

Access control

Least-privilege model with SSO-required access, MFA on all human accounts, and just-in-time elevation for privileged operations with full audit logging.

Data lifecycle

Engagement data isolated per tenant, deleted 90 days after the retest window closes unless the customer requests earlier deletion or extended retention.

负责任披露

发现了什么?告诉我们。

我们为 SecureBlock 平台中的漏洞运行正式的披露计划。范围内的报告将在 24 小时内得到确认,并按照与严重性匹配的时间表进行修复。

计划范围
  • 在范围内: app.secureblock.io、api.secureblock.io 和 secureblock.io。
  • 范围外: 客户租户(受其自身参与规则约束)、第三方服务、拒绝服务攻击以及对员工的社会工程学攻击。
  • SLA: 初始确认在 24 小时内。关键修复在 7 天内。高危在 30 天内。其他尽力而为。
荣誉榜

感谢帮助我们的研究人员。

@n3rvous@byte0@ravena@0xkai@sig-null@piprock@marisec@tempo

想出现在这个列表上?请参阅上面的披露政策。