Trust Center

How we protect what you trust us with

Hackurity is an offensive security firm. Customers hand us their attack surface, their employee lists, and the findings that would hurt them most if leaked. This page sets out how we protect that material, the rules we work under, and how to reach us when something goes wrong.

At a glance

Legal entity hackurity.io B.V., Bierstraat 123, 3011 TA Rotterdam, the Netherlands. KvK 83768572
Certification ISO/IEC 27001:2022, certificate 202505004
Data location AWS eu-central-1, Frankfurt
Customer data leaving the EU None
GDPR role Processor for engagement data, controller for our own records
Breach notification Affected customers within 24 hours of confirmation
Report a vulnerability security@hackurity.io

Certifications & compliance

We hold ISO/IEC 27001:2022 certification for our information security management system.

Certificate number 202505004 - view certificate
Certification body Sancert
Accreditation UKAS Management Systems 28938; IAF Multilateral Recognition Arrangement
Valid until 20 May 2027
Certified scope Information Security Management System for the provision of automated penetration testing, dark web threat intelligence monitoring, and brand protection services, through the secure development, operation, and maintenance of cloud-based cybersecurity solutions. Statement of Applicability v1, dated 5 March 2025.

Internal audit and management review run annually between external surveillance audits.

Regulatory framework

Instrument Relevance
GDPR (EU 2016/679) Art. 28 processor obligations; Art. 6(1)(f) basis for threat intelligence
NIS2 (EU 2022/2555) Threat intelligence sharing and incident response
Wbni (Dutch Cybersecurity Act) National framework for our operations
Budapest Convention Lawful access to publicly available data for research

We hold no SOC 2 report, FedRAMP authorization, or PCI QSA status.

Data residency

Customer engagement data processed by hackurity.io B.V. is stored and processed in the European Union, in AWS region eu-central-1 (Frankfurt, Germany). Hackurity does not replicate, back up, or fail over customer engagement data outside the European Union.

Data Location Leaves the EU
Engagement evidence and findings AWS eu-central-1 No
Employee rosters for social engineering exercises AWS eu-central-1 No
Customer credentials and test accounts AWS eu-central-1, secrets store No
Correspondence and delivered reports Google Workspace, EU data regions No
Backups Daily hot and cold backups, neither leaving the EU No

Where a subprocessor's parent entity sits outside the EU, transfers rely on Standard Contractual Clauses (EU 2021/914) and, for certified US vendors, the EU-US Data Privacy Framework.

On the CLOUD Act. AWS is US-headquartered. Our data stays in Frankfurt under contractual and technical commitment, encryption at rest applies throughout customer-managed KMS keys, and we notify the affected customer of any government access request unless legally prohibited.

Subprocessors

A subprocessor is a third party that processes customer personal data on our behalf. Under GDPR Art. 28(2) we owe you notice before adding one.

Subprocessor Purpose Location Transfer basis
Amazon Web Services Infrastructure hosting, evidence storage eu-central-1 (DE) None required
Google Workspace: email, documents, delivered reports, cold database backups EU data regions EU Data Boundary; SCCs for support access
Anthropic AI-assisted analysis United States SCCs
Local inference AI-assisted analysis on Hackurity-controlled laptops EU SCCs
Plane Engagement and ticket tracking EU SCCs

AI processing. Customer data is processed by the AI subprocessors above under model training exclusions. We hold a direct contract covering this processing: submitted data is used only to serve Hackurity, is encrypted in transit and at rest, is never shared with third parties, is never used to train models, and is not reviewed by humans.

Change notification. We give 30 days' notice before a new subprocessor begins processing. Customers can object on reasonable data protection grounds, and where an objection cannot be resolved, terminate the affected service without penalty. To join the notification list, email hello@hackurity.io.

Data handling & retention

Offensive security work produces material more dangerous than the systems it describes. A finished penetration test report is a working guide to compromising the customer.

Classification

Level Applies to
RESTRICTED Unremediated findings, exploitation artifacts, customer credentials, employee rosters
CONFIDENTIAL Scope documents, engagement correspondence
INTERNAL Tooling, runbooks, ISMS records
PUBLIC Threat bulletins, this page

Retention

Material Held for
Raw engagement evidence For as long as your contract is active
Customer credentials and test accounts Deleted at engagement close
Social engineering rosters For as long as your contract is active
Final deliverable report For as long as your contract is active
Engagement metadata For as long as your contract is active
Deletion logs Permanently

Deletion uses srm, cryptographic erasure, or equivalent multi-pass overwrite, and is logged with date, analyst, method, and verification. A certificate of deletion is available on request. Customers can request earlier deletion at any time.

Security practices

Area Control
Authentication MFA on all systems holding customer data
Authorization Least privilege, granted per engagement
Encryption in transit TLS 1.2 minimum, TLS 1.3 preferred
Encryption at rest AES-256
Endpoint Full-disk encryption, enforced through mobile device management
Patching Enforced through mobile device management
Isolation Engagement environments separated per customer
Monitoring AWS infrastructure logging and alerting, reviewed through our own platform
Staff screening In-house screening, plus the checks required under Dutch law
Confidentiality Signed by all staff and contractors before engagement work
Report delivery Through the customer portal, or by direct email on request
Data centers AWS eu-central-1, ISO 27001 and SOC 2 certified

Privacy & GDPR

Data Our role
Engagement data Processor
Threat intelligence source material Controller, Art. 6(1)(f)
Your staff contact details Controller
Website visitors Controller

Your rights under Articles 15 to 21 - access, rectification, erasure, restriction, portability, objection. Submit a request to gdpr@hackurity.io. We verify identity, then respond within 30 days, extendable by 60 days for complex requests under Art. 12(3). No charge.

Complaints go to us, and to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

An Art. 28-compliant Data Processing Agreement is provided at contract stage or on request, with SCCs where transfers apply.

Full privacy notice: Privacy Policy.

Vulnerability disclosure

We run offensive security for a living. We would rather hear about a flaw in our systems from you than from a customer.

Report to security@hackurity.io. Acknowledgment within 2 business days. Our machine-readable policy is published at /.well-known/security.txt.

In scope Out of scope
hackurity.io and subdomains Our customers' systems
Customer-facing portals and platforms Third-party SaaS we consume
Public tooling and published artifacts Social engineering of Hackurity staff
Email and DNS configuration Physical attacks

Safe harbor. Research conducted in good faith under this policy is authorized. We will not pursue civil action or refer you to law enforcement for activity that follows it, and where a third party acts against you for compliant research, we will say so. Our authorization covers our own systems and cannot extend to a customer environment.

Rules. Stop at proof of concept. Use your own test accounts. Do not access another party's data, run denial of service, or pivot further after establishing access. A report accompanied by a payment demand is handled as extortion.

Severity (CVSS v4.0) Triage Remediation
Critical 1 business day 7 days
High 2 business days 30 days
Medium 5 business days 90 days
Low 5 business days Next release

Disclosure window is 90 days, extendable by agreement. Named credit on request. A monetary bounty is offered for findings in our customer-facing portals and platforms. Findings in our honeypots do not qualify for a bounty.

Incident response

Suspected exposure of your data: email security@hackurity.io with a subject line beginning INCIDENT.

Severity Definition Customer notification
P1 Critical Confirmed exposure of customer data, or loss of control of a production system Within 24 hours of confirmation
P2 High Suspected exposure, or compromise of an adjacent system Within 24 hours of confirmation
P3 Medium Security event with no customer data impact If contractually required
P4 Low Policy violation or minor misconfiguration No

As processor, we notify you; as controller, you notify your supervisory authority within 72 hours (GDPR Art. 33). Notifications state the nature of the breach, categories and approximate volume of data affected, likely consequences, measures taken, and a contact point. Where the full picture is not yet available, we send what we have within the deadline and follow up.

A post-incident review completes within 10 business days of closure, with corrective actions tracked in the ISMS register.

Business continuity

Recovery time objective 4 hours
Recovery point objective 1 hour
Backup frequency Daily retained 35 days, weekly retained 90 days, monthly retained 365 days, plus a daily cold copy of every in-scope database. Point-in-time recovery gives roughly 5-minute granularity
Backup location Hot and cold backups are encrypted and stay within the EU under the same residency commitment.
Restore testing Automated restore pipeline

Environmental

Our footprint sits in cloud compute and staff working arrangements. Infrastructure runs in AWS eu-central-1. Amazon reports matching 100% of the electricity consumed across its operations with renewable energy, and targets net-zero carbon by 2040.

Source: sustainability.aboutamazon.com

Our broader commitments are set out in our Environmental Policy.

Compliance documents

Public: this page, our Threat Intelligence Data Handling Policy, the vulnerability disclosure policy, security.txt, and the subprocessor list.

Under NDA: ISO 27001 Statement of Applicability, surveillance audit summary, third-party penetration test attestation, business continuity and restore test evidence, Transfer Impact Assessments, insurance certificates.

Request them from hello@hackurity.io, stating the requesting entity, the documents needed, and the purpose. Released within 5 business days of NDA execution.

We complete customer security questionnaires. Most answers are already on this page, so linking the relevant section is usually faster than a spreadsheet.

Contact

Security vulnerabilities security@hackurity.io
Privacy and data subject requests gdpr@hackurity.io
Compliance documents hello@hackurity.io
Suspected incident security@hackurity.io, subject INCIDENT

Last updated: 7 August 2026