Back to home
Trust
You are handing us the keys to something that moves money. Here is what we do with them.
No badges on this page. We do not currently hold SOC 2 or ISO 27001 certification, and we will say so until we do. What follows is what we actually practise, in plain language, and every line of it is something you can hold us to in the engagement agreement.
Access
- We test against a staging or sandbox environment wherever one exists. Production testing happens only with written agreement on scope, hours, and kill switch.
- Credentials are scoped to the engagement and issued by you. You can revoke them at any moment without telling us first.
- We never test outside the agreed scope. If we find a path into something out of scope, we stop and tell you.
Your data
- Attack prompts, agent responses, and tool call logs from your engagement are used for your engagement. They are not used to train models, ours or anyone else’s.
- Findings are visible to your account and to Oreset staff working the engagement. Nothing is shared with other clients, published, or used as a reference without your written consent.
- Engagement data is retained for the engagement plus the retest window, then deleted on request. Regression exports you download are yours.
Our people
- Every tester signs a non-disclosure agreement, a code of conduct, and a data handling policy before they see a single scenario. Signatures are recorded with time and IP.
- Testers pass calibration against scenarios with known correct answers before working a live engagement, and their accuracy is tracked continuously.
- Testers see the scenario, not your business. Client identity is limited to what the scenario needs.
Reporting
- Every finding carries reproduction steps so your engineers can confirm it independently. We do not ask you to take our word for it.
- Every critical and high finding is reproduced by a lead auditor before it appears in your dashboard. False positives are recorded and never shown to you.
- An audit log records who saw what and when, across testers, auditors, and staff.
Disclosure
- We do not disclose findings publicly. Ever. Case studies happen only with your approval of every word.
- If we discover a vulnerability in a third-party model or platform during your engagement, we coordinate disclosure with you before contacting the vendor.
Questions about any of this, or requirements we have not covered, go to security@oreset.africa. A person reads it.