Security & Trust

We protect your data while we test it

You are trusting us with access to your systems. Here is exactly how we handle that trust, the controls, the legal terms, and the transparency you should expect from any security partner.

Data protection

How your data is handled

The controls that apply to every engagement, by default, not on request.

Encrypted in transit and at rest

Engagement data, evidence and findings are encrypted both while moving and while stored. Nothing sensitive sits in the clear.

Least-privilege access

Only the researchers assigned to your engagement can access its data. Access is scoped to the engagement and revoked when it ends.

Defined retention, secure destruction

Engagement artifacts are securely destroyed after the agreed retention period. We keep nothing longer than we need to.

No third-party sharing

We never share client information, test results or vulnerability details with any third party, and never use your data for anything but the agreed work.

Isolated engagement handling

Each engagement is handled in isolation, so one client’s data and findings can never surface in another’s work.

Named, accountable team

You know who is on your engagement. Our testers are individually credentialed and every action is attributable.

Authorization

We only test what you authorize

Written authorization only

We never test a system without explicit, written authorization. Scope, targets and permitted techniques are agreed before any testing begins.

Strict Rules of Engagement

Every engagement runs under Rules of Engagement that fix what is in scope, what is excluded, the testing windows, and the escalation and emergency contacts.

Escalate before we act

If we find something outside scope that poses an immediate risk, we notify you through the agreed channel before taking any action — never after.

On paper

Confidentiality, in writing

Trust backed by contract, not just intent.

Mutual NDA

Every engagement operates under a signed non-disclosure agreement covering both directions before any information changes hands.

Request our NDA template

Data Processing Agreement (DPA)

For engagements involving personal data, a DPA sets out exactly how data is processed, protected, retained and destroyed — the baseline GDPR and enterprise buyers expect.

Request our DPA

Our paper

Documents your legal team can start with today

Standard-form NDA, DPA and a data-handling summary — published so review can begin on day one.

Mutual NDA

Balanced mutual non-disclosure agreement covering findings and engagement details.

View & download

Data Processing Agreement

GDPR Article 28-aligned DPA with processing details and security measures annexed.

View & download

Data-Handling Summary

One page for procurement: residency, encryption, retention, deletion, and access.

View & download

Happy to sign your NDA instead. These are examples and standard-form templates, not final legal advice — governing law is negotiable, and enterprises usually prefer their own paper. Send yours over, or ask us to complete your vendor questionnaire, and we will turn it around in one to two business days. See the full library on the documents page.

Transparency

Ask us anything about your data

Where your data is processed, which sub-processors are involved, how long anything is retained, and your right to audit, these are fair questions and we answer them plainly before you sign. We would rather over-explain our controls than ask you to take them on faith.

Data residency & jurisdiction

Sub-processor list on request

Retention & destruction timeline

Right-to-audit on request

Verifiable, not just stated

Credentials & assurance

Certified testers you can verify

Our researchers hold OSCP, OSCP+, Synack Red Team and Certified AI/ML Pentester credentials. Every one links directly to the issuing authority, you never have to take our word for it.

OSCP
OSCP+
Synack Red Team
AI/ML Pentester
Verify our certifications

Reports built for your compliance

Our engagement reports are structured to support the frameworks your auditors work to, methodology, evidence, CVSS-scored findings and remediation verification.

PCI DSS
SOC 2
ISO 27001
HIPAA
GDPR

Found an issue in our own platform?

We hold ourselves to the same standard we hold your systems to. If you have found a security issue in XHack, tell us through our responsible-disclosure process.

Read our disclosure policy

Doing your vendor due diligence?

We are happy to walk you through our controls, sign your NDA and DPA, and answer your security questionnaire. Ask us anything.