How we protect what you trust us with
Hackurity is an offensive security firm. Customers hand us their attack surface, their employee lists, and the findings that would hurt them most if leaked. This page sets out how we protect that material, the rules we work under, and how to reach us when something goes wrong.
| Legal entity | hackurity.io B.V., Bierstraat 123, 3011 TA Rotterdam, the Netherlands. KvK 83768572 |
|---|---|
| Certification | ISO/IEC 27001:2022, certificate 202505004 |
| Data location | AWS eu-central-1, Frankfurt |
| Customer data leaving the EU | None |
| GDPR role | Processor for engagement data, controller for our own records |
| Breach notification | Affected customers within 24 hours of confirmation |
| Report a vulnerability | security@hackurity.io |
We hold ISO/IEC 27001:2022 certification for our information security management system.
| Certificate number | 202505004 - view certificate |
|---|---|
| Certification body | Sancert |
| Accreditation | UKAS Management Systems 28938; IAF Multilateral Recognition Arrangement |
| Valid until | 20 May 2027 |
| Certified scope | Information Security Management System for the provision of automated penetration testing, dark web threat intelligence monitoring, and brand protection services, through the secure development, operation, and maintenance of cloud-based cybersecurity solutions. Statement of Applicability v1, dated 5 March 2025. |
Internal audit and management review run annually between external surveillance audits.
| Instrument | Relevance |
|---|---|
| GDPR (EU 2016/679) | Art. 28 processor obligations; Art. 6(1)(f) basis for threat intelligence |
| NIS2 (EU 2022/2555) | Threat intelligence sharing and incident response |
| Wbni (Dutch Cybersecurity Act) | National framework for our operations |
| Budapest Convention | Lawful access to publicly available data for research |
We hold no SOC 2 report, FedRAMP authorization, or PCI QSA status.
Customer engagement data processed by hackurity.io B.V. is stored and processed in the European Union, in AWS region eu-central-1 (Frankfurt, Germany). Hackurity does not replicate, back up, or fail over customer engagement data outside the European Union.
| Data | Location | Leaves the EU |
|---|---|---|
| Engagement evidence and findings | AWS eu-central-1 | No |
| Employee rosters for social engineering exercises | AWS eu-central-1 | No |
| Customer credentials and test accounts | AWS eu-central-1, secrets store | No |
| Correspondence and delivered reports | Google Workspace, EU data regions | No |
| Backups | Daily hot and cold backups, neither leaving the EU | No |
Where a subprocessor's parent entity sits outside the EU, transfers rely on Standard Contractual Clauses (EU 2021/914) and, for certified US vendors, the EU-US Data Privacy Framework.
On the CLOUD Act. AWS is US-headquartered. Our data stays in Frankfurt under contractual and technical commitment, encryption at rest applies throughout customer-managed KMS keys, and we notify the affected customer of any government access request unless legally prohibited.
A subprocessor is a third party that processes customer personal data on our behalf. Under GDPR Art. 28(2) we owe you notice before adding one.
| Subprocessor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Amazon Web Services | Infrastructure hosting, evidence storage | eu-central-1 (DE) | None required |
| Workspace: email, documents, delivered reports, cold database backups | EU data regions | EU Data Boundary; SCCs for support access | |
| Anthropic | AI-assisted analysis | United States | SCCs |
| Local inference | AI-assisted analysis on Hackurity-controlled laptops | EU | SCCs |
| Plane | Engagement and ticket tracking | EU | SCCs |
AI processing. Customer data is processed by the AI subprocessors above under model training exclusions. We hold a direct contract covering this processing: submitted data is used only to serve Hackurity, is encrypted in transit and at rest, is never shared with third parties, is never used to train models, and is not reviewed by humans.
Change notification. We give 30 days' notice before a new subprocessor begins processing. Customers can object on reasonable data protection grounds, and where an objection cannot be resolved, terminate the affected service without penalty. To join the notification list, email hello@hackurity.io.
Offensive security work produces material more dangerous than the systems it describes. A finished penetration test report is a working guide to compromising the customer.
| Level | Applies to |
|---|---|
| RESTRICTED | Unremediated findings, exploitation artifacts, customer credentials, employee rosters |
| CONFIDENTIAL | Scope documents, engagement correspondence |
| INTERNAL | Tooling, runbooks, ISMS records |
| PUBLIC | Threat bulletins, this page |
| Material | Held for |
|---|---|
| Raw engagement evidence | For as long as your contract is active |
| Customer credentials and test accounts | Deleted at engagement close |
| Social engineering rosters | For as long as your contract is active |
| Final deliverable report | For as long as your contract is active |
| Engagement metadata | For as long as your contract is active |
| Deletion logs | Permanently |
Deletion uses srm, cryptographic erasure, or equivalent multi-pass overwrite, and is logged with date, analyst, method, and verification. A certificate of deletion is available on request. Customers can request earlier deletion at any time.
| Area | Control |
|---|---|
| Authentication | MFA on all systems holding customer data |
| Authorization | Least privilege, granted per engagement |
| Encryption in transit | TLS 1.2 minimum, TLS 1.3 preferred |
| Encryption at rest | AES-256 |
| Endpoint | Full-disk encryption, enforced through mobile device management |
| Patching | Enforced through mobile device management |
| Isolation | Engagement environments separated per customer |
| Monitoring | AWS infrastructure logging and alerting, reviewed through our own platform |
| Staff screening | In-house screening, plus the checks required under Dutch law |
| Confidentiality | Signed by all staff and contractors before engagement work |
| Report delivery | Through the customer portal, or by direct email on request |
| Data centers | AWS eu-central-1, ISO 27001 and SOC 2 certified |
| Data | Our role |
|---|---|
| Engagement data | Processor |
| Threat intelligence source material | Controller, Art. 6(1)(f) |
| Your staff contact details | Controller |
| Website visitors | Controller |
Your rights under Articles 15 to 21 - access, rectification, erasure, restriction, portability, objection. Submit a request to gdpr@hackurity.io. We verify identity, then respond within 30 days, extendable by 60 days for complex requests under Art. 12(3). No charge.
Complaints go to us, and to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
An Art. 28-compliant Data Processing Agreement is provided at contract stage or on request, with SCCs where transfers apply.
Full privacy notice: Privacy Policy.
We run offensive security for a living. We would rather hear about a flaw in our systems from you than from a customer.
Report to security@hackurity.io. Acknowledgment within 2 business days. Our machine-readable policy is published at /.well-known/security.txt.
| In scope | Out of scope |
|---|---|
hackurity.io and subdomains | Our customers' systems |
| Customer-facing portals and platforms | Third-party SaaS we consume |
| Public tooling and published artifacts | Social engineering of Hackurity staff |
| Email and DNS configuration | Physical attacks |
Safe harbor. Research conducted in good faith under this policy is authorized. We will not pursue civil action or refer you to law enforcement for activity that follows it, and where a third party acts against you for compliant research, we will say so. Our authorization covers our own systems and cannot extend to a customer environment.
Rules. Stop at proof of concept. Use your own test accounts. Do not access another party's data, run denial of service, or pivot further after establishing access. A report accompanied by a payment demand is handled as extortion.
| Severity (CVSS v4.0) | Triage | Remediation |
|---|---|---|
| Critical | 1 business day | 7 days |
| High | 2 business days | 30 days |
| Medium | 5 business days | 90 days |
| Low | 5 business days | Next release |
Disclosure window is 90 days, extendable by agreement. Named credit on request. A monetary bounty is offered for findings in our customer-facing portals and platforms. Findings in our honeypots do not qualify for a bounty.
Suspected exposure of your data: email security@hackurity.io with a subject line beginning INCIDENT.
| Severity | Definition | Customer notification |
|---|---|---|
| P1 Critical | Confirmed exposure of customer data, or loss of control of a production system | Within 24 hours of confirmation |
| P2 High | Suspected exposure, or compromise of an adjacent system | Within 24 hours of confirmation |
| P3 Medium | Security event with no customer data impact | If contractually required |
| P4 Low | Policy violation or minor misconfiguration | No |
As processor, we notify you; as controller, you notify your supervisory authority within 72 hours (GDPR Art. 33). Notifications state the nature of the breach, categories and approximate volume of data affected, likely consequences, measures taken, and a contact point. Where the full picture is not yet available, we send what we have within the deadline and follow up.
A post-incident review completes within 10 business days of closure, with corrective actions tracked in the ISMS register.
| Recovery time objective | 4 hours |
|---|---|
| Recovery point objective | 1 hour |
| Backup frequency | Daily retained 35 days, weekly retained 90 days, monthly retained 365 days, plus a daily cold copy of every in-scope database. Point-in-time recovery gives roughly 5-minute granularity |
| Backup location | Hot and cold backups are encrypted and stay within the EU under the same residency commitment. |
| Restore testing | Automated restore pipeline |
Our footprint sits in cloud compute and staff working arrangements. Infrastructure runs in AWS eu-central-1. Amazon reports matching 100% of the electricity consumed across its operations with renewable energy, and targets net-zero carbon by 2040.
Source: sustainability.aboutamazon.com
Our broader commitments are set out in our Environmental Policy.
Public: this page, our Threat Intelligence Data Handling Policy, the vulnerability disclosure policy, security.txt, and the subprocessor list.
Under NDA: ISO 27001 Statement of Applicability, surveillance audit summary, third-party penetration test attestation, business continuity and restore test evidence, Transfer Impact Assessments, insurance certificates.
Request them from hello@hackurity.io, stating the requesting entity, the documents needed, and the purpose. Released within 5 business days of NDA execution.
We complete customer security questionnaires. Most answers are already on this page, so linking the relevant section is usually faster than a spreadsheet.
| Security vulnerabilities | security@hackurity.io |
|---|---|
| Privacy and data subject requests | gdpr@hackurity.io |
| Compliance documents | hello@hackurity.io |
| Suspected incident | security@hackurity.io, subject INCIDENT |
Last updated: 7 August 2026