Trust Center

How we protect what you trust us with

Hackurity is an offensive security firm. Customers hand us their attack surface, their employee lists, and the findings that would hurt them most if leaked. This page sets out how we protect that material, the rules we work under, and how to reach us when something goes wrong.

At a glance

Legal entityhackurity.io B.V., Bierstraat 123, 3011 TA Rotterdam, the Netherlands. KvK 83768572
CertificationISO/IEC 27001:2022, certificate 202505004
Data locationAWS eu-central-1, Frankfurt
Customer data leaving the EUNone
GDPR roleProcessor for engagement data, controller for our own records
Breach notificationAffected customers within 24 hours of confirmation
Report a vulnerabilitysecurity@hackurity.io

Certifications & compliance

We hold ISO/IEC 27001:2022 certification for our information security management system.

ISO/IEC 27001:2022 certificate
Certificate number202505004 - view certificate
Certification bodySancert
AccreditationUKAS Management Systems 28938; IAF Multilateral Recognition Arrangement
Valid until20 May 2027
Certified scopeInformation Security Management System for the provision of automated penetration testing, dark web threat intelligence monitoring, and brand protection services, through the secure development, operation, and maintenance of cloud-based cybersecurity solutions. Statement of Applicability v1, dated 5 March 2025.

Internal audit and management review run annually between external surveillance audits.

Regulatory framework

InstrumentRelevance
GDPR (EU 2016/679)Art. 28 processor obligations; Art. 6(1)(f) basis for threat intelligence
NIS2 (EU 2022/2555)Threat intelligence sharing and incident response
Wbni (Dutch Cybersecurity Act)National framework for our operations
Budapest ConventionLawful access to publicly available data for research

We hold no SOC 2 report, FedRAMP authorization, or PCI QSA status.

Data residency

Customer engagement data processed by hackurity.io B.V. is stored and processed in the European Union, in AWS region eu-central-1 (Frankfurt, Germany). Hackurity does not replicate, back up, or fail over customer engagement data outside the European Union.

DataLocationLeaves the EU
Engagement evidence and findingsAWS eu-central-1No
Employee rosters for social engineering exercisesAWS eu-central-1No
Customer credentials and test accountsAWS eu-central-1, secrets storeNo
Correspondence and delivered reportsGoogle Workspace, EU data regionsNo
BackupsDaily hot and cold backups, neither leaving the EUNo

Where a subprocessor's parent entity sits outside the EU, transfers rely on Standard Contractual Clauses (EU 2021/914) and, for certified US vendors, the EU-US Data Privacy Framework.

On the CLOUD Act. AWS is US-headquartered. Our data stays in Frankfurt under contractual and technical commitment, encryption at rest applies throughout customer-managed KMS keys, and we notify the affected customer of any government access request unless legally prohibited.

Subprocessors

A subprocessor is a third party that processes customer personal data on our behalf. Under GDPR Art. 28(2) we owe you notice before adding one.

SubprocessorPurposeLocationTransfer basis
Amazon Web ServicesInfrastructure hosting, evidence storageeu-central-1 (DE)None required
GoogleWorkspace: email, documents, delivered reports, cold database backupsEU data regionsEU Data Boundary; SCCs for support access
AnthropicAI-assisted analysisUnited StatesSCCs
Local inferenceAI-assisted analysis on Hackurity-controlled laptopsEUSCCs
PlaneEngagement and ticket trackingEUSCCs

AI processing. Customer data is processed by the AI subprocessors above under model training exclusions. We hold a direct contract covering this processing: submitted data is used only to serve Hackurity, is encrypted in transit and at rest, is never shared with third parties, is never used to train models, and is not reviewed by humans.

Change notification. We give 30 days' notice before a new subprocessor begins processing. Customers can object on reasonable data protection grounds, and where an objection cannot be resolved, terminate the affected service without penalty. To join the notification list, email hello@hackurity.io.

Data handling & retention

Offensive security work produces material more dangerous than the systems it describes. A finished penetration test report is a working guide to compromising the customer.

Classification

LevelApplies to
RESTRICTEDUnremediated findings, exploitation artifacts, customer credentials, employee rosters
CONFIDENTIALScope documents, engagement correspondence
INTERNALTooling, runbooks, ISMS records
PUBLICThreat bulletins, this page

Retention

MaterialHeld for
Raw engagement evidenceFor as long as your contract is active
Customer credentials and test accountsDeleted at engagement close
Social engineering rostersFor as long as your contract is active
Final deliverable reportFor as long as your contract is active
Engagement metadataFor as long as your contract is active
Deletion logsPermanently

Deletion uses srm, cryptographic erasure, or equivalent multi-pass overwrite, and is logged with date, analyst, method, and verification. A certificate of deletion is available on request. Customers can request earlier deletion at any time.

Security practices

AreaControl
AuthenticationMFA on all systems holding customer data
AuthorizationLeast privilege, granted per engagement
Encryption in transitTLS 1.2 minimum, TLS 1.3 preferred
Encryption at restAES-256
EndpointFull-disk encryption, enforced through mobile device management
PatchingEnforced through mobile device management
IsolationEngagement environments separated per customer
MonitoringAWS infrastructure logging and alerting, reviewed through our own platform
Staff screeningIn-house screening, plus the checks required under Dutch law
ConfidentialitySigned by all staff and contractors before engagement work
Report deliveryThrough the customer portal, or by direct email on request
Data centersAWS eu-central-1, ISO 27001 and SOC 2 certified

Privacy & GDPR

DataOur role
Engagement dataProcessor
Threat intelligence source materialController, Art. 6(1)(f)
Your staff contact detailsController
Website visitorsController

Your rights under Articles 15 to 21 - access, rectification, erasure, restriction, portability, objection. Submit a request to gdpr@hackurity.io. We verify identity, then respond within 30 days, extendable by 60 days for complex requests under Art. 12(3). No charge.

Complaints go to us, and to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

An Art. 28-compliant Data Processing Agreement is provided at contract stage or on request, with SCCs where transfers apply.

Full privacy notice: Privacy Policy.

Vulnerability disclosure

We run offensive security for a living. We would rather hear about a flaw in our systems from you than from a customer.

Report to security@hackurity.io. Acknowledgment within 2 business days. Our machine-readable policy is published at /.well-known/security.txt.

In scopeOut of scope
hackurity.io and subdomainsOur customers' systems
Customer-facing portals and platformsThird-party SaaS we consume
Public tooling and published artifactsSocial engineering of Hackurity staff
Email and DNS configurationPhysical attacks

Safe harbor. Research conducted in good faith under this policy is authorized. We will not pursue civil action or refer you to law enforcement for activity that follows it, and where a third party acts against you for compliant research, we will say so. Our authorization covers our own systems and cannot extend to a customer environment.

Rules. Stop at proof of concept. Use your own test accounts. Do not access another party's data, run denial of service, or pivot further after establishing access. A report accompanied by a payment demand is handled as extortion.

Severity (CVSS v4.0)TriageRemediation
Critical1 business day7 days
High2 business days30 days
Medium5 business days90 days
Low5 business daysNext release

Disclosure window is 90 days, extendable by agreement. Named credit on request. A monetary bounty is offered for findings in our customer-facing portals and platforms. Findings in our honeypots do not qualify for a bounty.

Incident response

Suspected exposure of your data: email security@hackurity.io with a subject line beginning INCIDENT.

SeverityDefinitionCustomer notification
P1 CriticalConfirmed exposure of customer data, or loss of control of a production systemWithin 24 hours of confirmation
P2 HighSuspected exposure, or compromise of an adjacent systemWithin 24 hours of confirmation
P3 MediumSecurity event with no customer data impactIf contractually required
P4 LowPolicy violation or minor misconfigurationNo

As processor, we notify you; as controller, you notify your supervisory authority within 72 hours (GDPR Art. 33). Notifications state the nature of the breach, categories and approximate volume of data affected, likely consequences, measures taken, and a contact point. Where the full picture is not yet available, we send what we have within the deadline and follow up.

A post-incident review completes within 10 business days of closure, with corrective actions tracked in the ISMS register.

Business continuity

Recovery time objective4 hours
Recovery point objective1 hour
Backup frequencyDaily retained 35 days, weekly retained 90 days, monthly retained 365 days, plus a daily cold copy of every in-scope database. Point-in-time recovery gives roughly 5-minute granularity
Backup locationHot and cold backups are encrypted and stay within the EU under the same residency commitment.
Restore testingAutomated restore pipeline

Environmental

Our footprint sits in cloud compute and staff working arrangements. Infrastructure runs in AWS eu-central-1. Amazon reports matching 100% of the electricity consumed across its operations with renewable energy, and targets net-zero carbon by 2040. (Source: sustainability.aboutamazon.com)

Our broader commitments are set out in our Environmental Policy.

Compliance documents

Public: this page, our Threat Intelligence Data Handling Policy, the vulnerability disclosure policy, security.txt, and the subprocessor list.

Under NDA: ISO 27001 Statement of Applicability, surveillance audit summary, third-party penetration test attestation, business continuity and restore test evidence, Transfer Impact Assessments, insurance certificates.

Request them from hello@hackurity.io, stating the requesting entity, the documents needed, and the purpose. Released within 5 business days of NDA execution.

We complete customer security questionnaires. Most answers are already on this page, so linking the relevant section is usually faster than a spreadsheet.

Contact

Security vulnerabilitiessecurity@hackurity.io
Privacy and data subject requestsgdpr@hackurity.io
Compliance documentshello@hackurity.io
Suspected incidentsecurity@hackurity.io, subject INCIDENT

Last updated: 7 August 2026