Trust

How we work, what we promise, and what we will not do.

Trust is earned with boundaries, not brochures. This page is the version of our terms you can read in five minutes. The signed engagement letter says the same thing in more words.

Who we work with

Private-sector organizations, and provincial and municipal public bodies, mainly in Ontario. We do not take on federal government work, and we screen every intake for conflicts before a discovery call is booked.

Authorization first

No testing starts without an engagement letter and rules of engagement signed by someone authorized to arrange it. The free snapshot runs only against a domain the requester attests they are authorized to have assessed, and it is read-only.

Capacity you can plan around

At most 4 concurrent engagements across the team. Each engagement has a named practitioner and a named backup, a report due date and a retest date. If we cannot start within the tier you chose, we say so before you sign.

Business hours, honestly

We respond within defined business-hours windows written into the retainer. We do not claim round-the-clock coverage. When a client needs it, a disclosed partner SOC provides it under its own terms, and we do the onboarding, tuning and reporting.

Not during an incident

We do not begin testing, tuning or evidence collection while an incident is active. We will refer you to an incident-response firm and pick up the hardening and the attestation afterwards.

Readiness, not certification

Compliance readiness packs prepare you for an audit or a certification body. The certificate is theirs to issue. Our attestation letters describe the work performed and the state observed at the retest, with evidence hashes.

Evidence and privacy

  • Findings, screenshots and logs are stored in an engagement workspace with access limited to the practitioners named in the letter.
  • Credentials are used only for the authenticated review and are rotated or revoked by you when the retest is done.
  • Client evidence is never used to train a model. Agent drafts are generated from the engagement record and validated evidence only.
  • Reports and letters are delivered to the contacts named in the letter, and to your Vanta or Drata workspace or Jira project when you ask.
  • Intake data is used to run the conflict screen and to contact you about your request. You can ask us to delete it at any time.

Insurance and standing

Professional liability and cyber liability coverage is arranged before the first paid engagement; certificates are provided with the engagement letter on request. We follow OWASP WSTG and ASVS for application work and reference the framework version in every attestation.

Partner ecosystem

Relationships in place today. Partner SOC, compliance-platform and broker relationships are disclosed in writing on each engagement; partner services are contracted with the partner directly.

PartnerRoleStatus
OWASP Toronto COMMUNITY ACTIVE