Everything your procurement, security and privacy teams will ask for, published in one place.
One page for your procurement, security and privacy teams. Every document they will ask for, published rather than sent on request — including the answers that are unflattering to us.
What we collect, why, how long we keep it, and your rights under GDPR, CCPA/CPRA and other US state laws.
Contracting, authorisation, confidentiality, liability and governing law. We also work under your MSA.
Article 28 terms, CCPA service-provider terms, security measures and data minimisation during testing.
SCCs, UK IDTA, Swiss and Canadian terms, transfer impact assessment and supplementary measures.
None with access to engagement data. Testing is delivered entirely in-house by employed personnel.
No advertising cookies, no analytics, no cross-site tracking. One third-party request, disclosed.
How we protect engagement data: encryption, access control, retention, destruction and personnel vetting.
Report a vulnerability in our systems. Response SLAs and safe harbour for good-faith researchers.
Forty common questions answered in advance, including insurance, accreditation and AI.
What we agree in writing before any test begins: authorisation, scope, windows, prohibited techniques.
Machine-readable disclosure policy at the standard location.
How we manage conflicts, including the one created when we arrange your audit and also test your systems.
Authorised testing only, anti-bribery, honesty about findings and about ourselves, non-retaliation.
Cetonix is not a conformity assessment body. What we do, what the CAB does, and how to verify it.
WCAG 2.2 AA position for this site and for deliverables, with known limitations stated.
Four complete penetration test reports, ~50 pages each, published without a form.
PTES, NIST SP 800-115, OWASP WSTG/ASVS/MASVS and the API Security Top 10.
If you are triaging vendors and want the material facts without reading further:
| Testers employed or subcontracted? | Employed. No subcontractors. |
| Client data to AI services? | Never. No source code, findings or client material, under any circumstances. |
| Where is data processed? | India. Localisation options available — raise at scoping. |
| Will you sign our NDA and DPA? | Yes, and your MSA. |
| Retest included? | Yes, 60 days, with a reissued report. |
| Breach notification? | Within 24 hours. |
| Are you an accredited certification body? | No. We coordinate certification through accredited CABs. |
| CREST or ASSURE accredited? | No. |
| Professional indemnity insurance? | Not currently. Tell us at scoping if you require it. |
Email it to security@cetonix.com. We return completed vendor security questionnaires within three business days and we do not charge for it.