Skip to main content

Trust centre

How we secure ourselves.

We audit other people for a living, so we hold ourselves to the same standard. This is our own security posture, and how to request the documents behind it.

Threatsys operations

Our certifications

  • CERT-In empanelled security auditor
  • ISO/IEC 27001 information security management
  • ISO/IEC 20000 service management
  • ISO 9001:2015 quality management
  • SOC 2 Type II attested
  • GDPR aligned processing

How we handle your data

  • Engagement data is encrypted at rest and in transit
  • Findings are stored in India unless you require otherwise
  • Access is role based and reviewed quarterly
  • Data is destroyed on a schedule agreed in your contract
  • Every engineer signs an individual confidentiality undertaking

What we hold about you, and for how long

During an engagement we necessarily hold things you would not want loose: findings, reproduction steps, screenshots, sometimes credentials issued to us for authenticated testing. Those credentials are revoked by you at the end of testing and we ask for confirmation that they have been. Engagement artefacts are retained for the period agreed in your contract, which is usually twelve months so that the next assessment can compare against the last, and destroyed on schedule after that. If you would prefer a shorter retention, say so at scoping and we will write it into the engagement rather than treat it as an exception.

How we are tested ourselves

  • Independent penetration testing of our own platforms, not performed by the team that builds them
  • Annual recertification against ISO 27001 with surveillance audits in between
  • SOC 2 Type II, which tests whether controls operated over a period rather than on a date
  • Access reviews on our own systems quarterly, on the same cadence we recommend to clients
  • A responsible disclosure route that is monitored and answered

Sub-processors and where data sits

We keep a current list of the third parties involved in delivering our services, what each one processes, and where. It is available on request under NDA alongside the Data Processing Addendum. The short version is that engagement data for Indian clients stays in India by default, which matters both for the CERT-In log retention requirement and for clients under RBI or SEBI supervision who are asked directly about data localisation.

If you think we have a problem

Report it. Our responsible disclosure page sets out how, what we commit to in response, and the timelines we work to. We do not pursue legal action against researchers who follow it in good faith. If your concern is about our handling of your data rather than a technical vulnerability, the same route reaches a human who can act on it.

Why a security firm is a concentration risk, and what we do about it

It is worth stating the thing most security vendors would rather you did not think about. A firm that tests many organisations accumulates, in one place, a detailed map of how to compromise all of them. That makes us a target of a specific kind, and it means your third party risk assessment of us should be harder than your assessment of a supplier who only sees your invoices. We would rather help you conduct that assessment properly than be waved through on the strength of our own certifications.

How we limit the blast radius of ourselves

  • Engagement data is segregated per client rather than pooled in one searchable store
  • Access is granted per engagement to the people on it, not to the delivery organisation at large
  • Privileged access to our own systems is elevated when needed and logged, not held standing
  • Reports and findings are retained on an agreed clock and destroyed on it
  • Credentials you issue us are revoked by you at the end of testing, and we ask for confirmation
  • Every engineer holds an individual confidentiality undertaking, separate from our contract with you

Questions to ask us in your vendor assessment

Most third party risk questionnaires we receive ask which certifications we hold, which we can answer in one line and which tells you comparatively little. The questions that would actually test us are different. How many people in your firm can read my engagement data, and how is that number enforced rather than intended? What happens to my findings if our contract ends tomorrow? Who at your firm has standing administrative access to the systems holding my report? When were you last tested, by whom, and can I see the scope? If a supplier deflects on those, including us, that tells you more than the certificate list.

Incident response, if it is us

We hold an incident process for our own estate with the same shape we recommend to clients: a named decision maker with a named deputy, both reachable out of hours, a written triage rule that says what is reportable, and a rehearsal that involves waking somebody up. If an incident affected client engagement data, affected clients are told directly and early, before we have complete answers rather than after, because a supplier who waits until the picture is tidy has taken the decision about your response away from you. Where the data involved brings statutory obligations under the DPDP Act 2023 or the CERT-In Directions, those run in parallel and do not replace telling you.

Business continuity of your engagement

A practical question that rarely appears in vendor assessments: what happens to your work if the person leading it is unavailable. Every engagement has a named lead and a named second who has read the scope and can pick it up, and engagement notes are kept in a form somebody else can use rather than in one engineer's head. This is unglamorous and it is the difference between a two day delay and a restart. It also constrains how many engagements we run at once, which is one of several reasons we are deliberate about growth.

Documents on request

Data Processing Addendum, sub-processor list, penetration test summary of our own platforms, insurance certificates and our latest SOC 2 report are available under NDA. Contact us and we will turn these around within two working days.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.