info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomeSecurity

Security practices and disclosure

How we protect what we find, who our testers are, and how to report a vulnerability in our own systems.

We ask clients to trust us with their most sensitive systems. This page sets out how we handle what we find, who our testers are, and how to report a problem with our own systems.

Reporting a vulnerability in Cetonix systems

If you believe you have found a security vulnerability in a Cetonix website or service, we want to hear about it.

  • Email: security@cetonix.com
  • Acknowledgement: within 2 business days
  • Triage and initial assessment: within 5 business days
  • Resolution target: 30 days for critical and high severity, 90 days for medium and low

Our machine-readable policy is published at /.well-known/security.txt.

Safe harbor

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, do not access or modify data belonging to others, and give us reasonable time to remediate before public disclosure. Please do not run automated scanning that degrades service, perform social engineering against our staff, or test physical security.

We credit researchers who report valid findings, unless you prefer to remain anonymous. We do not currently operate a paid bug bounty.

How we handle client test data

During a penetration test we hold material that would be damaging in the wrong hands: credentials, exploit detail, screenshots of live systems, and sometimes source code. Our commitments:

  • NDA before scoping. A mutual non-disclosure agreement is signed before any technical detail is exchanged. We will work under your paper if you prefer.
  • Encryption. Findings, evidence and credentials are encrypted at rest and in transit. Reports are delivered over an encrypted channel, never as an unprotected email attachment.
  • Least privilege. Access is limited to the assigned engagement team. Access is logged and reviewed.
  • Retention and destruction. Test data is retained only for the agreed retest window (60 days by default). At the end of that window, or earlier on written request, evidence and credentials are destroyed and destruction is confirmed in writing. Final reports are retained only where you ask us to.
  • No AI services. No client data — source code, configuration, traffic, credentials, findings or report content — is submitted to any AI or machine learning service, under any circumstances. Internal AI tooling unrelated to client work runs on enterprise tiers with training and retention disabled.
  • No client data in training or marketing. Findings are never reused as examples, case studies or marketing material without specific written permission.
  • Rules of engagement. Testing follows the scope, time windows, rate limits and out-of-scope systems you approve in writing. We do not deviate from agreed scope without written authorisation.

Our people

  • Testers are subject to background verification appropriate to the engagement.
  • Every tester signs an individual confidentiality undertaking in addition to the company NDA.
  • Each engagement has a named lead who is accountable for scope, conduct and delivery.

Where data is processed

Cetonix operates from India and delivers engagements for clients in the United States, Canada, the European Union and India. Engagement data is processed on infrastructure controlled by Cetonix. Where your contract, regulator or internal policy requires data to remain in a specific jurisdiction, tell us at scoping and we will confirm in writing what we can accommodate before the engagement begins.

Independence

Cetonix coordinates certification through accredited conformity assessment bodies and separately delivers penetration testing with its own in-house team. We do not issue certificates and we do not make certification decisions — the accredited CAB does. Where we arrange your certification audit and also test your systems, the same commercial party sits on both sides of the evidence; we disclose that in writing before you engage. See our Quality & Impartiality Policy.

Contacting us

Security matters: security@cetonix.com
Data protection terms: data processing agreement
Everything else: support@cetonix.com