Security and trust

Our own posture, stated plainly

We sell security advice, so it is fair to ask what we do ourselves. This page answers that. It does not claim a certification we have not earned, and it does not publish an uptime figure we have not measured. Where we are not yet where we intend to be, it says so.

What we hold

Nothing yet. We would rather say it here than have you find out when you ask for the certificate.

ISO/IEC 27001
Planned

We intend to certify, and we intend to do it on our own product, which is the only honest test of it. We will publish the certificate when there is one to publish, and not before.

SOC 2 Type II
Planned

A Type II report requires a period of operation to observe. We are not yet operating at the scale that makes one meaningful. It follows ISO 27001, not the other way round.

UAE PDPL
In progress

This is a legal obligation rather than a certification, and it applies to us today. Our privacy policy, data processing terms, sub-processor disclosure and data-subject-rights process are published and in force.

What we do instead

A certificate is a third party's opinion of your controls. Until we have one, here are the controls. Each is a fact we could show you in a file.

01

The website holds nothing about you

It sets no cookies, runs no analytics, embeds no third-party content, and loads no external fonts. Browsing these pages creates no tracking identifier. The first personal data we hold about anyone arrives when they submit a company profile, and only then.

02

Consent is a record, not a checkbox

When you accept our terms, we store which document you accepted, which version of it, when, and from where. A new version of a document re-gates everyone who accepted the old one. We can tell you exactly what you agreed to, which is the only form of consent worth having.

03

The audit trail cannot be edited

Our consent and audit records are append-only, enforced by the database rather than by a promise in application code. Updates are refused outright and deletions require an explicit, transaction-scoped authorisation that exists only for tearing down test data. Each record carries the hash of the one before it, so a removed or altered row breaks verification and cannot be quietly repaired.

04

Passwords are never stored, and never handled

Credentials are hashed with scrypt, using parameters stored alongside the hash so they can be strengthened later without invalidating anyone's password. Our breach-exposure tool works on domains and never asks for, receives, or checks a password.

05

Claims are enforced by the build

The facts on this site, the sub-processor regions, the transfer basis, our registered entity, the maturity of each product, are checked when the site is built. A production build fails if any of them is unverified or overstated. It is harder for us to publish something untrue than to publish something true.

06

Where your data rests

Your website and portal data rest in Frankfurt. Correspondence you send to our mailboxes rests in the United States. In full: Frankfurt, Germany (eu-central-1) and the United States. None of our providers operates a UAE region, so personal data rests outside the State. That is a cross-border transfer and we disclose it, with its lawful basis under Article 23 of the PDPL, rather than let you assume otherwise.

Who processes your data

4 providers, each named, with what they see and where it rests set out in full.

For security researchers

Responsible disclosure

security@secureedgeadvisory.com
Acknowledged within two business days.

If you believe you have found a vulnerability in our website, our portal or any of our products, we want to hear from you, and we would rather hear from you than from someone else.

Write to security@secureedgeadvisory.com. Tell us what you found and how to reproduce it. A person reads that mailbox, and we will acknowledge you within two business days.

We ask that you do not access, modify or delete data belonging to anyone else, do not degrade the service for other users, and give us a reasonable opportunity to fix the issue before you disclose it publicly. In return we will not pursue or support any legal action against a researcher who follows those terms in good faith.

We do not currently run a paid bounty. We will say so plainly rather than imply one, and we will credit you if you would like us to.