We rate other people’s security.
Here is ours.
A company that scores security postures should expect its own to be examined. This page sets out how the platform is secured, what data we hold, where it sits, and who is behind the research.
How the platform is secured
The controls a reviewer asks about first.
Authentication and tenancy
Multi-tenant by design, with JWT authentication and OTP two-factor. A tenant sees its own portfolio and nothing else.
Full activity audit trail
Every action is recorded, triage decisions, accepted-risk rationales, integration changes and report generation. Who did what, and when.
What we hold, and what we do not
The short version of the privacy policy, in the terms a security reviewer works in.
| What we hold about you | Name, work email, IP address at sign-in, and audit-log entries for actions taken in the dashboard. |
| What we do not hold | We do not scan your internal systems or ingest personal data from your platforms. |
| What assessment touches | Only what is published to the public internet, plus any cloud account you explicitly connect with read-only scoped access. |
| Sub-processors | Maintained in the customer DPA, with advance notice of changes through the contractual notice channel. |
| Retention | Set out in the customer order form and DPA. Website analytics and contact submissions are kept only as long as needed to respond. |
| Your rights | Access, rectification, erasure, restriction, portability and objection. See the privacy policy. |
Framework alignment
The platform maps findings to ISO 27001, NIST, PCI DSS and GDPR, and we hold ourselves to the same controls we report on. Current certification and attestation status is confirmed in writing during procurement rather than asserted with a badge here, ask and we will send the current position, including anything in progress.
What we can evidence today
- Tenant isolation with JWT authentication and OTP two-factor
- Full activity audit trail across every tenant action
- UK default data residency, other regions by agreement
- Sub-processor list maintained in the customer DPA
- A published, versioned scoring rubric anyone can interrogate
What we do not claim
- That an external rating covers internal controls
- That findings are validated by exploitation: they are observed
- That any takedown outcome can be guaranteed
- Raw vulnerability counts inflated to look comprehensive
Common questions
You assess other companies without asking them. How is that legitimate?
Assessment observes what an organisation publishes to the public internet, the same vantage point any visitor or attacker has. Nothing is exploited and no system is accessed. Where a scan incidentally surfaces already-published personal data, we process it on a legitimate-interests basis and you can object; that is set out in the privacy policy.
Who is behind the research?
GuardianGaze is built by the team at RedSecLabs, a London security research practice with a background in offensive security. Brand-protection indicators are analyst-verified before they reach a report rather than published straight from automation.
Do you exploit anything to confirm a finding?
No. Every finding is observed rather than proven by attack. That is a deliberate limit: it keeps assessment safe to run against third parties without their permission, and it is why we describe findings as evidence-backed rather than validated by exploitation.
Can we get a DPA?
Yes. The Data Processing Addendum covers processing terms, sub-processors and residency, and is the document that governs where it conflicts with the public pages.
Security review questions welcome
If your review needs something not covered here, ask. We would rather answer it directly than have you infer it from a badge.
Procurement and DPA questions: [email protected]