We sell security advice, so it is fair to ask what we do ourselves. This page answers that. It does not claim a certification we have not earned, and it does not publish an uptime figure we have not measured. Where we are not yet where we intend to be, it says so.
Nothing yet. We would rather say it here than have you find out when you ask for the certificate.
We intend to certify, and we intend to do it on our own product, which is the only honest test of it. We will publish the certificate when there is one to publish, and not before.
A Type II report requires a period of operation to observe. We are not yet operating at the scale that makes one meaningful. It follows ISO 27001, not the other way round.
This is a legal obligation rather than a certification, and it applies to us today. Our privacy policy, data processing terms, sub-processor disclosure and data-subject-rights process are published and in force.
A certificate is a third party's opinion of your controls. Until we have one, here are the controls. Each is a fact we could show you in a file.
It sets no cookies, runs no analytics, embeds no third-party content, and loads no external fonts. Browsing these pages creates no tracking identifier. The first personal data we hold about anyone arrives when they submit a company profile, and only then.
When you accept our terms, we store which document you accepted, which version of it, when, and from where. A new version of a document re-gates everyone who accepted the old one. We can tell you exactly what you agreed to, which is the only form of consent worth having.
Our consent and audit records are append-only, enforced by the database rather than by a promise in application code. Updates are refused outright and deletions require an explicit, transaction-scoped authorisation that exists only for tearing down test data. Each record carries the hash of the one before it, so a removed or altered row breaks verification and cannot be quietly repaired.
Credentials are hashed with scrypt, using parameters stored alongside the hash so they can be strengthened later without invalidating anyone's password. Our breach-exposure tool works on domains and never asks for, receives, or checks a password.
The facts on this site, the sub-processor regions, the transfer basis, our registered entity, the maturity of each product, are checked when the site is built. A production build fails if any of them is unverified or overstated. It is harder for us to publish something untrue than to publish something true.
Your website and portal data rest in Frankfurt. Correspondence you send to our mailboxes rests in the United States. In full: Frankfurt, Germany (eu-central-1) and the United States. None of our providers operates a UAE region, so personal data rests outside the State. That is a cross-border transfer and we disclose it, with its lawful basis under Article 23 of the PDPL, rather than let you assume otherwise.
4 providers, each named, with what they see and where it rests set out in full.
If you believe you have found a vulnerability in our website, our portal or any of our products, we want to hear from you, and we would rather hear from you than from someone else.
Write to security@secureedgeadvisory.com. Tell us what you found and how to reproduce it. A person reads that mailbox, and we will acknowledge you within two business days.
We ask that you do not access, modify or delete data belonging to anyone else, do not degrade the service for other users, and give us a reasonable opportunity to fix the issue before you disclose it publicly. In return we will not pursue or support any legal action against a researcher who follows those terms in good faith.
We do not currently run a paid bounty. We will say so plainly rather than imply one, and we will credit you if you would like us to.