Trust
You are hiring an attacker. Here is how we are safe to hire.
Procurement should not have to guess. This is where your data goes, who touches it, and how to report a problem.
-
Data stays in South Africa
Engagement data is processed and stored on infrastructure in South Africa. It does not leave the country as part of normal operation.
-
Encrypted and time-boxed
Findings and evidence are encrypted at rest, retained for the period we agree, and deleted on request.
-
Certified operators
Every report is reviewed and signed by an operator holding a recognised offensive-security certification.
-
Least privilege
The agent works from your rules of engagement with the narrowest access needed to test, and nothing more.
Compliance
Frameworks we map to.
Reports are written so the evidence lines up with the controls your auditor already checks.
- ISO 27001
- NIST
- GDPR
- POPIA
- PCI DSS
| ISO 27001 mapping | Findings mapped |
|---|---|
| SOC 2 | Roadmap |
| CREST | Roadmap |
| POPIA | Aligned |
Responsible disclosure
Found something in ours?
If you believe you have found a vulnerability in BreachAgent's own systems, tell us before you tell anyone else. Email admin@breachagent.ai with enough detail to reproduce it. We will acknowledge receipt, keep you updated, and will not pursue action against good-faith research that respects our users' data and stays within the law.
Our machine-readable policy is published at /.well-known/security.txt.
Send security review our way.
Have a questionnaire, a DPA, or a data-residency requirement? Send it over and we will turn it around.