1. Client engagements
Findings from client engagements belong to the client. We do not disclose them to any third party without the client's prior written consent, except where legally required.
2. Reporting cadence
- Critical severity findings: reported to the designated Client contact within 24 hours of confirmation.
- High severity findings: reported within 72 hours.
- Medium and low severity findings: reported in the final engagement report.
- All findings shipped via encrypted channels agreed at engagement kickoff.
3. Third-party product vulnerabilities
If during an engagement we discover a vulnerability in a third-party product (open-source or commercial) that affects our client and others, we work with the client to coordinate disclosure to the vendor. Default timeline follows industry-standard 90-day disclosure with extensions where a vendor is actively remediating.
4. Zero-day disclosure
We do not sell, trade, or stockpile 0-day vulnerabilities. Any 0-day discovered during an engagement is (a) reported to the client, (b) reported to the vendor under coordinated-disclosure terms, and (c) never repurposed for other engagements.
5. Public writing about engagements
We do not publish blog posts, conference talks, or social-media commentary about specific client engagements without prior written approval and appropriate redaction. Generic methodology write-ups that draw on aggregate experience are permitted.
6. Regulatory notifications
Where an engagement uncovers evidence of an ongoing breach subject to regulatory notification (GDPR Article 33, HIPAA § 164.400, DPDP Section 8(6), etc.), we advise the client of their obligations and stand ready to support notification workflows. We do not directly notify authorities except where legally compelled or with the client's express instruction.
7. Post-engagement retention
Engagement artifacts (reports, exploit code, screenshots, PCAPs) are retained in encrypted storage for the contractual retention period (typically 7 years) and then securely destroyed. Destruction certificates are issued on request.