Skip to main content
davque

Security & trust

How we handle your data

What happens to your source code and test data, and the conditions under which we test.

Commitments

What we promise and what we do not

What we promise

  • Your source code and test data are not transmitted to cloud AI providers.
  • Source code you hand over is analysed in an isolated, offline environment on hardware we operate ourselves.
  • Online targets are tested from our own infrastructure, only within the agreed scope and time window.
  • Only the people named in the contract have access.
  • Every finding is reproduced by a human before it enters the report.
  • All artifacts are deleted after the agreed period; the deletion is logged.

What we explicitly do not promise

  • No guarantee of finding all vulnerabilities. Nobody can credibly give that promise.
  • No certificate – we are not a certification body, we deliver the technical test evidence.
  • No tests on systems without written authorization, not even on a trial basis.
  • No statement about periods outside the test window; a report describes a state, not a permanent condition.
  • No publication of findings without your written consent.

Infrastructure

How the analysis environment is built.

What is stated here can be included in the contract on request.

Operations

Analysis infrastructure at a single site in Germany, operated and administered by ourselves. No cloud hyperscaler in the analysis chain.

Offline analysis of source code

Source code you hand over is analysed in an isolated environment without internet access. Nothing can leave it – not even by accident.

Testing online targets

For blackbox runs against systems that are online, our test traffic comes from our own infrastructure and only touches the targets in the signed scope, within the agreed time window.

Access and logging

Access exclusively via personal accounts with multi-factor authentication. No shared accounts, no permanent logins. All test activity and access is logged, and you receive the log on request.

Encryption

Encryption in transit (TLS 1.3) and at rest. Reports delivered PGP-encrypted or through an agreed secure channel.

Retention

By default 30 days after report handover, so that follow-up questions and retest remain possible. Shorter periods can be agreed by contract.

Status of the information: 21 September 2026. Binding are the details in the contract and annexes.

Legal framework

Written authorization before every test

Written authorization

Before every test you sign a test authorization naming the test target, domains and IP ranges, test window, permitted and excluded techniques and an emergency contact. Without this document no test starts.

Authority to commission

We check whether you may commission testing of the named target. If parts of the system belong to third parties – such as a hosting provider or a SaaS vendor – we need their approval in addition.

Criminal-law framework

Unauthorized access to third-party systems is a criminal offence under sections 202a–c of the German Criminal Code. We therefore do not offer self-service testing of arbitrary domains and do not accept engagements where authority remains unclear.

Handling of findings

Findings are confidential and stay between you and us. If we come across a vulnerability in a third-party component, such as an open-source library, we agree the further procedure with you under responsible-disclosure principles before doing anything.

The information on this page describes our way of working and does not constitute legal advice. For an assessment of your specific case please consult your legal department or a lawyer.

FAQ

Questions from privacy and legal

How can I verify that no data really goes to cloud AI?

Before the contract you receive a description of how your data is handled, including the components used and the subprocessor list. On request we contractually stipulate that transmission to third-party AI services is excluded, and supply the network configuration of the offline analysis environment as an annex. Independent reviews by your team or a third party you commission are possible.

Which subprocessors do you use?

None for the analysis itself. For business operations – such as sending email or booking appointments – we use providers with their seat and processing in the EU. The complete, current list is an annex to the contract and is handed to you before signature.

How do you secure your own infrastructure?

Separate environments for analysis, business operations and this website. Personal accounts with multi-factor authentication, encryption in transit and at rest, logged access, regular patching and our own security tests of our own systems. You can report a vulnerability on our side via our security.txt.

Do you have insurance in case of damage?

Ask in the intro call for the current status of professional liability and cyber cover; we name the insurer and the sum insured on request. In addition we reduce risk through clear abort criteria, tests against staging instead of production and a reachable emergency contact on both sides.

Open points with your legal department?

We can provide sample contracts and the subprocessor list in advance.

  • No test without written authorization and a defined scope.
  • Source code and test data never go to cloud AI providers.
  • Every finding is verified by a person before delivery.