How we secure your engagement data.
CyVigilant handles your most sensitive security information — vulnerability findings, network diagrams, source code. Here is a transparent account of the operational-security controls we apply to every engagement.
ISO 27001:2022 certified. Operationally hardened.
ISO 27001:2022 Certified
CyVigilant maintains ISO 27001:2022 certification, independently audited each year. Our Information Security Management System covers all aspects of client engagement data — from scoping to secure destruction.
NDA on Every Engagement
A mutual NDA and a formal rules-of-engagement document are signed before any testing begins. Findings, credentials, and evidence are treated as strictly confidential and are never shared with third parties without written Client consent.
Least-Privilege, Time-Boxed Access
All test credentials and access grants are scoped to the minimum required for the agreed engagement. Access is revoked immediately at engagement close. We do not retain credentials beyond the testing window.
Encrypted Evidence Handling
All vulnerability evidence — screenshots, PoC payloads, traffic captures — is encrypted in transit (TLS 1.3) and at rest (AES-256) throughout the engagement lifecycle. Evidence packages are delivered via encrypted channels only.
Secure Data Destruction
All client data — including credentials, scan outputs, and evidence files — is securely and verifiably destroyed within 30 days of final report delivery unless a longer retention period is required by the CERT-In audit process delivered through our empanelled partners or agreed in the SOW.
Responsible Disclosure Programme
We operate a formal responsible disclosure programme. If you discover a security issue in CyVigilant's own systems, report it to security@cyvigilant.com. We commit to acknowledging reports within 48 hours and resolving valid issues before public disclosure.
Last updated · May 2026
Information Security Management System
Our ISMS is built to ISO 27001:2022 and covers all operations related to client engagements — scoping, testing, reporting, and data retention. The ISMS is independently audited annually. Corrective actions from audit findings are tracked to closure and reviewed at quarterly management reviews.
Team and Personnel Security
All CyVigilant security consultants undergo background verification before joining. Engineers with client-data access complete mandatory security-awareness training on onboarding and annually thereafter. All personnel sign individual confidentiality agreements in addition to company-wide policy. Certificates held across the team: OSCP, OSWE, CRTP, CEH, CISSP.
Testing Infrastructure
Assessments are conducted from isolated, hardened testing environments. Attack tooling and exploit frameworks are used only within the agreed scope. All testing activity is logged with timestamps, source IPs, and command records, providing a full audit trail in the event of any dispute or incident. Test environments are rebuilt from clean baselines between engagements.
Engagement Data Lifecycle
Client data passes through four controlled stages: (1) Collection — captured only within agreed scope, classified as confidential from the point of creation. (2) Storage — encrypted at rest; access restricted to the assigned engagement team. (3) Delivery — reports and evidence sent via encrypted, authenticated channels; no email attachments of unencrypted evidence. (4) Destruction — all client data is securely destroyed at engagement close or per agreed schedule, with a written destruction certificate provided on request.
Cloud and Remote Testing Controls
For cloud-infrastructure assessments, CyVigilant uses temporary IAM roles or service accounts with the minimum permissions required for the assessment. All cloud credentials are revoked immediately after testing. We do not access the contents of production databases or storage buckets unless explicitly authorized and scoped in writing. Remote access sessions are recorded and retained for the engagement audit trail.
Source Code Review Controls
For secure code review engagements, source code is handled as strictly confidential. Code is processed only within isolated, internet-restricted environments. Upon completion, all local copies are securely deleted and a deletion confirmation is provided. Code is never used for purposes beyond the agreed review scope.
Subcontractor Controls
Where specialist sub-contractors are engaged, they are bound by the same confidentiality, data-handling, and NDA obligations as direct CyVigilant staff. Subcontractors are assessed against our vendor-security criteria before onboarding and are subject to the same ISO 27001:2022 requirements. Client consent is sought before any subcontractor accesses Client systems.
Incident Response
CyVigilant maintains a documented incident response procedure covering identification, containment, notification, and post-incident review. In the event of a security incident that affects Client data, we commit to: notifying the affected Client within 24 hours of confirmed impact; providing a full incident report within 72 hours; and implementing and verifying corrective actions before the engagement resumes or closes.
Responsible Disclosure
To report a vulnerability in CyVigilant's own systems: email security@cyvigilant.com with a detailed description and reproduction steps. We will acknowledge within 48 hours, provide status updates, and — with your permission — credit you once the issue is resolved. We request that you do not publish details until we have had a reasonable opportunity to remediate.
Contact Our Security Team
For security enquiries, ISO 27001 certificate requests, or to discuss our operational-security controls before an engagement: security@cyvigilant.com. For privacy and data-protection questions: privacy@cyvigilant.com.
