Security

How we secure your engagement data.

CyVigilant handles your most sensitive security information — vulnerability findings, network diagrams, source code. Here is a transparent account of the operational-security controls we apply to every engagement.

Our Security Posture

ISO 27001:2022 certified. Operationally hardened.

ISO 27001:2022 Certified

CyVigilant maintains ISO 27001:2022 certification, independently audited each year. Our Information Security Management System covers all aspects of client engagement data — from scoping to secure destruction.

NDA on Every Engagement

A mutual NDA and a formal rules-of-engagement document are signed before any testing begins. Findings, credentials, and evidence are treated as strictly confidential and are never shared with third parties without written Client consent.

Least-Privilege, Time-Boxed Access

All test credentials and access grants are scoped to the minimum required for the agreed engagement. Access is revoked immediately at engagement close. We do not retain credentials beyond the testing window.

Encrypted Evidence Handling

All vulnerability evidence — screenshots, PoC payloads, traffic captures — is encrypted in transit (TLS 1.3) and at rest (AES-256) throughout the engagement lifecycle. Evidence packages are delivered via encrypted channels only.

Secure Data Destruction

All client data — including credentials, scan outputs, and evidence files — is securely and verifiably destroyed within 30 days of final report delivery unless a longer retention period is required by the CERT-In audit process delivered through our empanelled partners or agreed in the SOW.

Responsible Disclosure Programme

We operate a formal responsible disclosure programme. If you discover a security issue in CyVigilant's own systems, report it to security@cyvigilant.com. We commit to acknowledging reports within 48 hours and resolving valid issues before public disclosure.

Last updated · May 2026

Information Security Management System

Our ISMS is built to ISO 27001:2022 and covers all operations related to client engagements — scoping, testing, reporting, and data retention. The ISMS is independently audited annually. Corrective actions from audit findings are tracked to closure and reviewed at quarterly management reviews.

Team and Personnel Security

All CyVigilant security consultants undergo background verification before joining. Engineers with client-data access complete mandatory security-awareness training on onboarding and annually thereafter. All personnel sign individual confidentiality agreements in addition to company-wide policy. Certificates held across the team: OSCP, OSWE, CRTP, CEH, CISSP.

Testing Infrastructure

Assessments are conducted from isolated, hardened testing environments. Attack tooling and exploit frameworks are used only within the agreed scope. All testing activity is logged with timestamps, source IPs, and command records, providing a full audit trail in the event of any dispute or incident. Test environments are rebuilt from clean baselines between engagements.

Engagement Data Lifecycle

Client data passes through four controlled stages: (1) Collection — captured only within agreed scope, classified as confidential from the point of creation. (2) Storage — encrypted at rest; access restricted to the assigned engagement team. (3) Delivery — reports and evidence sent via encrypted, authenticated channels; no email attachments of unencrypted evidence. (4) Destruction — all client data is securely destroyed at engagement close or per agreed schedule, with a written destruction certificate provided on request.

Cloud and Remote Testing Controls

For cloud-infrastructure assessments, CyVigilant uses temporary IAM roles or service accounts with the minimum permissions required for the assessment. All cloud credentials are revoked immediately after testing. We do not access the contents of production databases or storage buckets unless explicitly authorized and scoped in writing. Remote access sessions are recorded and retained for the engagement audit trail.

Source Code Review Controls

For secure code review engagements, source code is handled as strictly confidential. Code is processed only within isolated, internet-restricted environments. Upon completion, all local copies are securely deleted and a deletion confirmation is provided. Code is never used for purposes beyond the agreed review scope.

Subcontractor Controls

Where specialist sub-contractors are engaged, they are bound by the same confidentiality, data-handling, and NDA obligations as direct CyVigilant staff. Subcontractors are assessed against our vendor-security criteria before onboarding and are subject to the same ISO 27001:2022 requirements. Client consent is sought before any subcontractor accesses Client systems.

Incident Response

CyVigilant maintains a documented incident response procedure covering identification, containment, notification, and post-incident review. In the event of a security incident that affects Client data, we commit to: notifying the affected Client within 24 hours of confirmed impact; providing a full incident report within 72 hours; and implementing and verifying corrective actions before the engagement resumes or closes.

Responsible Disclosure

To report a vulnerability in CyVigilant's own systems: email security@cyvigilant.com with a detailed description and reproduction steps. We will acknowledge within 48 hours, provide status updates, and — with your permission — credit you once the issue is resolved. We request that you do not publish details until we have had a reasonable opportunity to remediate.

Contact Our Security Team

For security enquiries, ISO 27001 certificate requests, or to discuss our operational-security controls before an engagement: security@cyvigilant.com. For privacy and data-protection questions: privacy@cyvigilant.com.