Trust
Security practices
How Truehat approaches confidentiality and control for authorized assessment work — separate from this marketing site’s Free Brief flow.
Engagement separation
Marketing leads and Free Brief requests are handled apart from paid engagement environments. Active testing begins only after qualification and written Rules of Engagement.
Minimum necessary data
We collect and retain only what the engagement needs — agreed targets, authorization, findings evidence, and delivery artefacts — not unrelated personal data.
Encryption
Client communications and engagement materials are protected in transit with modern TLS. Stored artefacts use access-controlled storage appropriate to the engagement.
Controlled evidence access
Evidence and reports stay inside the engagement. Access is limited to people who need them to deliver the work. We do not publish client findings.
Scope enforcement
Paid work stays within agreed hosts, methods, and boundaries. Out-of-scope activity, destructive testing, and social engineering are excluded unless explicitly contracted.
Logging and auditability
Engagement activity is logged enough to support delivery quality and dispute clarity — without turning the engagement into unnecessary surveillance of your users.
Retention and deletion
We keep engagement materials as needed to deliver the work and meet ordinary business or legal needs, then delete or archive under the engagement’s agreed practice.
Credential revocation and teardown
Client-provided accounts and temporary access are revoked when no longer needed. Engagement environments are torn down when the work ends.
Incident contact
Security or confidentiality concerns about an engagement or this website: security@truehat.net. Commercial / Brief questions: engagements@truehat.net. Privacy requests: hello@truehat.net.
