How we expect our people to behave, including the commitments that cost us money.
This code applies to every Cetonix employee, officer and associate. It is published because a client is entitled to know the standard we hold ourselves to before they let us into their systems.
We test only what we have been authorised in writing to test, within the agreed scope, window and technique restrictions. Anyone who tests outside the agreed rules of engagement commits a disciplinary offence and, depending on severity, a criminal one. There is no circumstance in which curiosity justifies exceeding scope.
Personnel must disclose any situation that could present a conflict. Where Cetonix coordinates a client’s certification and also tests their systems, that relationship is disclosed to the client in writing before engagement and to the appointed conformity assessment body. Full detail is in our impartiality policy.
We neither offer nor accept bribes, kickbacks, facilitation payments or improper inducements, in any jurisdiction, regardless of local custom. This includes payments to secure or retain business, to influence a certification decision, or to expedite an approval. Gifts and hospitality must be modest, infrequent, transparent and never offered or accepted around a live tender or decision.
We do not offer any inducement to a conformity assessment body, auditor or accreditation body personnel.
Client information, findings and vulnerabilities are confidential indefinitely. We do not discuss client engagements outside the assigned team, publish findings without written permission, or use a client’s vulnerabilities as a teaching example even anonymously without consent.
Where testing exposes personal data, we count and classify records rather than copying them, and stop at the minimum needed to evidence the finding. Where children’s data, health data or payment data is involved, additional masking applies in every copy of the report including the client’s. See DPA section 6.
If we encounter evidence of a pre-existing compromise, illegal content or an active attacker, we stop and notify the client’s escalation contact immediately.
We treat clients, colleagues and third parties with respect regardless of race, ethnicity, nationality, religion, sex, gender identity, sexual orientation, disability or age. Harassment and discrimination are grounds for dismissal.
Anyone — employee, client or third party — who believes this code has been breached should email conduct@cetonix.com. Reports may be made anonymously.
Non-retaliation: no one who raises a concern in good faith will suffer any detriment, even if the concern turns out to be unfounded. Retaliation against a reporter is itself a disciplinary offence.
Concerns about a certification decision should also be raised with the conformity assessment body that made it and, if unresolved, with its accreditation body. We will provide the correct contact and will not obstruct it.
Version 1.0 · Last updated: 1 October 2025 · Report a concern: conduct@cetonix.com