The questions your procurement and security teams will send us, answered in advance. Including the ones where the answer is no.
Most of a vendor security review is the same forty questions. Here they are, answered honestly and in public, so you can assess us before spending a call on it. Where the answer is unflattering, it is still here.
Who are we contracting with?
Cetonix, a privately held company established in 2008, registered in Pune, Maharashtra, India.
Are you an accredited certification body?
No. Cetonix coordinates management system certification through a network of accredited conformity assessment bodies. We do not hold accreditation, issue certificates or make certification decisions. See how certification works.
Do you hold a company-level testing accreditation such as CREST or ASSURE?
No. We are not CREST or ASSURE accredited. We would rather you weighed the individual tester credentials, our published sample reports and our references instead.
Do you carry professional indemnity or cyber liability insurance?
No, not currently. If your procurement process requires it, tell us at scoping and we will address it before contracting rather than at signature.
Are testers employees or subcontractors?
Employees. Every tester assigned to an engagement is on Cetonix payroll. Nothing is subcontracted — see our sub-processor list.
What certifications does the team hold?
Across the testing team: OSCP, PNPT, CRTP, Burp Suite Certified Practitioner and AWS Certified Security – Specialty. All are individually verifiable and we provide certification IDs for assigned testers on request.
Are personnel background checked?
Yes, to a standard appropriate to the engagement. Every tester signs an individual confidentiality undertaking in addition to the company NDA.
Is there a named point of accountability?
Yes. Every engagement has a named lead accountable for scope, conduct and delivery for its duration.
Where is engagement data processed and stored?
India, on infrastructure Cetonix controls. See the Data Transfer Addendum.
Can data stay in our jurisdiction?
Sometimes. Depending on the engagement we can work entirely inside infrastructure you provide and control, so no engagement data leaves your environment. Raise it at scoping and we confirm in writing what is achievable.
How is data encrypted?
At rest and in transit. Reports are delivered over an encrypted channel, never as an unprotected email attachment. Keys are held by Cetonix and never by a hosting provider.
How long is data retained?
Credentials are destroyed on completion of testing. Evidence and findings are retained only to the end of the agreed retest window, then destroyed. Final reports are retained only if you ask us to. Written confirmation of destruction is provided in every case.
Can we require earlier destruction?
Yes, at any time on written request.
How do you handle personal data found during testing?
Records are counted and classified, never copied. Sampling stops at the minimum needed to evidence the finding. Credential values, children’s data and images are masked in every copy of the report including yours. See DPA section 6.
Do you submit client data to AI services?
No. Not under any circumstances. No source code, configuration, traffic capture, credential, finding or report content is submitted to any AI or machine learning service.
What about AI tools used internally?
Where AI tooling is used for internal work unrelated to client engagements, it is on enterprise tiers with model training disabled and zero data retention.
Will you accept an AI restriction clause with subcontractor flow-down?
Yes, as written. Because there are no subcontractors on the delivery side, the flow-down obligation has nothing to flow down to.
Will you sign our NDA?
Yes, before any scoping detail is exchanged.
Will you sign our DPA?
Yes. We also publish our own — see the Data Processing Agreement — but we would rather sign your paper than argue about ours.
Will you work under our MSA?
Yes.
What is your governing law?
Our standard terms specify India. We negotiate this and have accepted US and EU governing law on prior engagements. Raise it at contracting.
Your breach notification window?
Within 24 hours of becoming aware of a personal data breach affecting your data.
How are critical findings handled mid-engagement?
Reported to your named contact the day we confirm them, with reproduction steps, so remediation can begin before the report exists. Criticals are never held for the report or a scheduled call.
Is a retest included?
Yes. 60 days from report issue, covering all reported findings, with a reissued report marking each as fixed, partially fixed or open.
Do you provide an attestation letter?
Yes, signed, written to be shared with auditors, customers and prospects without exposing exploit detail.
What standards do you test to?
PTES and NIST SP 800-115 as methodology; OWASP WSTG and ASVS for web; OWASP API Security Top 10 for APIs; OWASP MASVS and MASTG for mobile; MITRE ATT&CK where adversary simulation is in scope. Findings are CVSS-scored with CWE classification.
Can we see a sample report?
Yes, four of them, published without a form: sample reports.
Will you provide references?
Yes, on request, subject to those clients agreeing to be contacted.
You coordinate our certification. How is testing separated from that?
Cetonix does not issue your certificate or make the certification decision — the accredited CAB does, independently of us. But we appoint that CAB, and a test we deliver may become evidence in an audit we arranged. We disclose that in writing before engagement, you may decline the pairing at no cost, and we notify the appointed CAB so it can apply its own impartiality controls. Their view governs. Full detail: impartiality policy.
Send your questionnaire to security@cetonix.com. We return completed questionnaires within three business days and we do not charge for it.
Version 1.0 · Last updated: 1 October 2025