info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomeTrust centre

Trust centre

Everything your procurement, security and privacy teams will ask for, published in one place.

One page for your procurement, security and privacy teams. Every document they will ask for, published rather than sent on request — including the answers that are unflattering to us.

Legal and data protection

Privacy Policy

What we collect, why, how long we keep it, and your rights under GDPR, CCPA/CPRA and other US state laws.

Terms of Service

Contracting, authorisation, confidentiality, liability and governing law. We also work under your MSA.

Data Processing Agreement

Article 28 terms, CCPA service-provider terms, security measures and data minimisation during testing.

Data Transfer Addendum

SCCs, UK IDTA, Swiss and Canadian terms, transfer impact assessment and supplementary measures.

Sub-processors

None with access to engagement data. Testing is delivered entirely in-house by employed personnel.

Cookie Policy

No advertising cookies, no analytics, no cross-site tracking. One third-party request, disclosed.

Security

Security Practices

How we protect engagement data: encryption, access control, retention, destruction and personnel vetting.

Vulnerability Disclosure

Report a vulnerability in our systems. Response SLAs and safe harbour for good-faith researchers.

Vendor Security Questionnaire

Forty common questions answered in advance, including insurance, accreditation and AI.

Rules of Engagement

What we agree in writing before any test begins: authorisation, scope, windows, prohibited techniques.

security.txt

Machine-readable disclosure policy at the standard location.

Governance

Impartiality Policy

How we manage conflicts, including the one created when we arrange your audit and also test your systems.

Code of Conduct

Authorised testing only, anti-bribery, honesty about findings and about ourselves, non-retaliation.

How Certification Works

Cetonix is not a conformity assessment body. What we do, what the CAB does, and how to verify it.

Accessibility Statement

WCAG 2.2 AA position for this site and for deliverables, with known limitations stated.

Evidence of the work

Sample Reports

Four complete penetration test reports, ~50 pages each, published without a form.

Methodology

PTES, NIST SP 800-115, OWASP WSTG/ASVS/MASVS and the API Security Top 10.

The short answers

If you are triaging vendors and want the material facts without reading further:

Testers employed or subcontracted?Employed. No subcontractors.
Client data to AI services?Never. No source code, findings or client material, under any circumstances.
Where is data processed?India. Localisation options available — raise at scoping.
Will you sign our NDA and DPA?Yes, and your MSA.
Retest included?Yes, 60 days, with a reissued report.
Breach notification?Within 24 hours.
Are you an accredited certification body?No. We coordinate certification through accredited CABs.
CREST or ASSURE accredited?No.
Professional indemnity insurance?Not currently. Tell us at scoping if you require it.

Sending us a questionnaire

Email it to security@cetonix.com. We return completed vendor security questionnaires within three business days and we do not charge for it.