Our business rests on trust. These principles govern how we operate.
Any vulnerability discovered outside a mission's contractual scope is handled through responsible disclosure — never exploited or disclosed publicly without coordination.
Data and systems we access during an engagement are never used for any purpose beyond that engagement.
Any technical intervention (penetration test, audit) is strictly limited to the scope defined in writing with the client.
We only publicly claim certifications, qualifications, and partnerships we genuinely hold, verifiable on request.