Skip to content

Trust

You are hiring an attacker. Here is how we are safe to hire.

Procurement should not have to guess. This is where your data goes, who touches it, and how to report a problem.

Compliance

Frameworks we map to.

Reports are written so the evidence lines up with the controls your auditor already checks.

  • ISO 27001
  • NIST
  • GDPR
  • POPIA
  • PCI DSS
Attestation status
ISO 27001 mapping Findings mapped
SOC 2 Roadmap
CREST Roadmap
POPIA Aligned

Responsible disclosure

Found something in ours?

If you believe you have found a vulnerability in BreachAgent's own systems, tell us before you tell anyone else. Email admin@breachagent.ai with enough detail to reproduce it. We will acknowledge receipt, keep you updated, and will not pursue action against good-faith research that respects our users' data and stays within the law.

Our machine-readable policy is published at /.well-known/security.txt.

Send security review our way.

Have a questionnaire, a DPA, or a data-residency requirement? Send it over and we will turn it around.