info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomeCode of conduct and ethics

Code of conduct and ethics

How we expect our people to behave, including the commitments that cost us money.

This code applies to every Cetonix employee, officer and associate. It is published because a client is entitled to know the standard we hold ourselves to before they let us into their systems.

1. Authorised testing only

We test only what we have been authorised in writing to test, within the agreed scope, window and technique restrictions. Anyone who tests outside the agreed rules of engagement commits a disciplinary offence and, depending on severity, a criminal one. There is no circumstance in which curiosity justifies exceeding scope.

2. Honesty about findings

  • We do not inflate severity to make a report look valuable. Findings are rated on real consequence.
  • We do not manufacture findings, and we do not pad a report with low-value observations to fill pages.
  • We say when we found little. A clean report is a legitimate outcome and we will not invent problems to justify a fee.
  • We report what we could not test and why, so you know the limits of the assurance you bought.

3. Honesty about ourselves

  • We do not claim accreditations, certifications or capabilities we do not hold. Cetonix is not an accredited certification body, is not CREST or ASSURE accredited, and does not currently carry professional indemnity insurance — all three are stated plainly on this site.
  • We do not present coordinated certification as though we issue the certificate.
  • We do not use a client’s name, logo or engagement as a reference without written permission.
  • Where we cannot do something a client needs, we say so and refer it out rather than taking the work and improvising.

4. Conflicts of interest

Personnel must disclose any situation that could present a conflict. Where Cetonix coordinates a client’s certification and also tests their systems, that relationship is disclosed to the client in writing before engagement and to the appointed conformity assessment body. Full detail is in our impartiality policy.

5. Anti-bribery and corruption

We neither offer nor accept bribes, kickbacks, facilitation payments or improper inducements, in any jurisdiction, regardless of local custom. This includes payments to secure or retain business, to influence a certification decision, or to expedite an approval. Gifts and hospitality must be modest, infrequent, transparent and never offered or accepted around a live tender or decision.

We do not offer any inducement to a conformity assessment body, auditor or accreditation body personnel.

6. Confidentiality

Client information, findings and vulnerabilities are confidential indefinitely. We do not discuss client engagements outside the assigned team, publish findings without written permission, or use a client’s vulnerabilities as a teaching example even anonymously without consent.

7. Handling of discovered data

Where testing exposes personal data, we count and classify records rather than copying them, and stop at the minimum needed to evidence the finding. Where children’s data, health data or payment data is involved, additional masking applies in every copy of the report including the client’s. See DPA section 6.

If we encounter evidence of a pre-existing compromise, illegal content or an active attacker, we stop and notify the client’s escalation contact immediately.

8. Respect and non-discrimination

We treat clients, colleagues and third parties with respect regardless of race, ethnicity, nationality, religion, sex, gender identity, sexual orientation, disability or age. Harassment and discrimination are grounds for dismissal.

9. Raising a concern

Anyone — employee, client or third party — who believes this code has been breached should email conduct@cetonix.com. Reports may be made anonymously.

Non-retaliation: no one who raises a concern in good faith will suffer any detriment, even if the concern turns out to be unfounded. Retaliation against a reporter is itself a disciplinary offence.

Concerns about a certification decision should also be raised with the conformity assessment body that made it and, if unresolved, with its accreditation body. We will provide the correct contact and will not obstruct it.

Version 1.0 · Last updated: 1 October 2025 · Report a concern: conduct@cetonix.com