Security
We hold other organisations' control evidence, which makes us a concentrated target. Our posture reflects that.
Data handling
Evidence is encrypted in transit and at rest. Tenant data is logically separated and every read is attributed to an authenticated principal. Collectors hold the narrowest credential that satisfies their read, and we document the specific permissions each one requires before it is enabled.
Access control
Staff access to production requires hardware-backed authentication and is granted per task rather than standing. Access to customer evidence is exceptional, logged, and notified to the customer.
Assurance
We are assessed annually against ISO 27001 and SOC 2 Type II. Penetration testing is performed twice yearly by an external firm, and summary reports are available to customers under agreement.
Reporting a vulnerability
We welcome reports from security researchers. Write to security@w18b.vulnytics.com with reproduction detail. We aim to acknowledge within two working days and will keep you informed through remediation. We do not pursue legal action against researchers acting in good faith within the terms of our disclosure policy.