We protect your data while we test it
You are trusting us with access to your systems. Here is exactly how we handle that trust, the controls, the legal terms, and the transparency you should expect from any security partner.
Data protection
How your data is handled
The controls that apply to every engagement, by default, not on request.
Encrypted in transit and at rest
Engagement data, evidence and findings are encrypted both while moving and while stored. Nothing sensitive sits in the clear.
Least-privilege access
Only the researchers assigned to your engagement can access its data. Access is scoped to the engagement and revoked when it ends.
Defined retention, secure destruction
Engagement artifacts are securely destroyed after the agreed retention period. We keep nothing longer than we need to.
No third-party sharing
We never share client information, test results or vulnerability details with any third party, and never use your data for anything but the agreed work.
Isolated engagement handling
Each engagement is handled in isolation, so one client’s data and findings can never surface in another’s work.
Named, accountable team
You know who is on your engagement. Our testers are individually credentialed and every action is attributable.
Authorization
We only test what you authorize
Written authorization only
We never test a system without explicit, written authorization. Scope, targets and permitted techniques are agreed before any testing begins.
Strict Rules of Engagement
Every engagement runs under Rules of Engagement that fix what is in scope, what is excluded, the testing windows, and the escalation and emergency contacts.
Escalate before we act
If we find something outside scope that poses an immediate risk, we notify you through the agreed channel before taking any action — never after.
On paper
Confidentiality, in writing
Trust backed by contract, not just intent.
Mutual NDA
Every engagement operates under a signed non-disclosure agreement covering both directions before any information changes hands.
Request our NDA templateData Processing Agreement (DPA)
For engagements involving personal data, a DPA sets out exactly how data is processed, protected, retained and destroyed — the baseline GDPR and enterprise buyers expect.
Request our DPAOur paper
Documents your legal team can start with today
Standard-form NDA, DPA and a data-handling summary — published so review can begin on day one.
Mutual NDA
Balanced mutual non-disclosure agreement covering findings and engagement details.
View & downloadData Processing Agreement
GDPR Article 28-aligned DPA with processing details and security measures annexed.
View & downloadData-Handling Summary
One page for procurement: residency, encryption, retention, deletion, and access.
View & downloadHappy to sign your NDA instead. These are examples and standard-form templates, not final legal advice — governing law is negotiable, and enterprises usually prefer their own paper. Send yours over, or ask us to complete your vendor questionnaire, and we will turn it around in one to two business days. See the full library on the documents page.
Ask us anything about your data
Where your data is processed, which sub-processors are involved, how long anything is retained, and your right to audit, these are fair questions and we answer them plainly before you sign. We would rather over-explain our controls than ask you to take them on faith.
Data residency & jurisdiction
Sub-processor list on request
Retention & destruction timeline
Right-to-audit on request
Verifiable, not just stated
Credentials & assurance
Certified testers you can verify
Our researchers hold OSCP, OSCP+, Synack Red Team and Certified AI/ML Pentester credentials. Every one links directly to the issuing authority, you never have to take our word for it.
Reports built for your compliance
Our engagement reports are structured to support the frameworks your auditors work to, methodology, evidence, CVSS-scored findings and remediation verification.
Found an issue in our own platform?
We hold ourselves to the same standard we hold your systems to. If you have found a security issue in XHack, tell us through our responsible-disclosure process.
Read our disclosure policyDoing your vendor due diligence?
We are happy to walk you through our controls, sign your NDA and DPA, and answer your security questionnaire. Ask us anything.