How we protect what we find, who our testers are, and how to report a vulnerability in our own systems.
We ask clients to trust us with their most sensitive systems. This page sets out how we handle what we find, who our testers are, and how to report a problem with our own systems.
If you believe you have found a security vulnerability in a Cetonix website or service, we want to hear about it.
Our machine-readable policy is published at /.well-known/security.txt.
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, do not access or modify data belonging to others, and give us reasonable time to remediate before public disclosure. Please do not run automated scanning that degrades service, perform social engineering against our staff, or test physical security.
We credit researchers who report valid findings, unless you prefer to remain anonymous. We do not currently operate a paid bug bounty.
During a penetration test we hold material that would be damaging in the wrong hands: credentials, exploit detail, screenshots of live systems, and sometimes source code. Our commitments:
Cetonix operates from India and delivers engagements for clients in the United States, Canada, the European Union and India. Engagement data is processed on infrastructure controlled by Cetonix. Where your contract, regulator or internal policy requires data to remain in a specific jurisdiction, tell us at scoping and we will confirm in writing what we can accommodate before the engagement begins.
Cetonix coordinates certification through accredited conformity assessment bodies and separately delivers penetration testing with its own in-house team. We do not issue certificates and we do not make certification decisions — the accredited CAB does. Where we arrange your certification audit and also test your systems, the same commercial party sits on both sides of the evidence; we disclose that in writing before you engage. See our Quality & Impartiality Policy.
Security matters: security@cetonix.com
Data protection terms: data processing agreement
Everything else: support@cetonix.com