Trust · Enterprise

We rate other people’s security.
Here is ours.

A company that scores security postures should expect its own to be examined. This page sets out how the platform is secured, what data we hold, where it sits, and who is behind the research.

Platform security

How the platform is secured

The controls a reviewer asks about first.

Access

Authentication and tenancy

Multi-tenant by design, with JWT authentication and OTP two-factor. A tenant sees its own portfolio and nothing else.

Accountability

Full activity audit trail

Every action is recorded, triage decisions, accepted-risk rationales, integration changes and report generation. Who did what, and when.

Data handling

What we hold, and what we do not

The short version of the privacy policy, in the terms a security reviewer works in.

What we hold about youName, work email, IP address at sign-in, and audit-log entries for actions taken in the dashboard.
What we do not holdWe do not scan your internal systems or ingest personal data from your platforms.
What assessment touchesOnly what is published to the public internet, plus any cloud account you explicitly connect with read-only scoped access.
Sub-processorsMaintained in the customer DPA, with advance notice of changes through the contractual notice channel.
RetentionSet out in the customer order form and DPA. Website analytics and contact submissions are kept only as long as needed to respond.
Your rightsAccess, rectification, erasure, restriction, portability and objection. See the privacy policy.
Certifications

Framework alignment

The platform maps findings to ISO 27001, NIST, PCI DSS and GDPR, and we hold ourselves to the same controls we report on. Current certification and attestation status is confirmed in writing during procurement rather than asserted with a badge here, ask and we will send the current position, including anything in progress.

What we can evidence today

  • Tenant isolation with JWT authentication and OTP two-factor
  • Full activity audit trail across every tenant action
  • UK default data residency, other regions by agreement
  • Sub-processor list maintained in the customer DPA
  • A published, versioned scoring rubric anyone can interrogate

What we do not claim

  • That an external rating covers internal controls
  • That findings are validated by exploitation: they are observed
  • That any takedown outcome can be guaranteed
  • Raw vulnerability counts inflated to look comprehensive
Questions

Common questions

You assess other companies without asking them. How is that legitimate?

Assessment observes what an organisation publishes to the public internet, the same vantage point any visitor or attacker has. Nothing is exploited and no system is accessed. Where a scan incidentally surfaces already-published personal data, we process it on a legitimate-interests basis and you can object; that is set out in the privacy policy.

Who is behind the research?

GuardianGaze is built by the team at RedSecLabs, a London security research practice with a background in offensive security. Brand-protection indicators are analyst-verified before they reach a report rather than published straight from automation.

Do you exploit anything to confirm a finding?

No. Every finding is observed rather than proven by attack. That is a deliberate limit: it keeps assessment safe to run against third parties without their permission, and it is why we describe findings as evidence-backed rather than validated by exploitation.

Can we get a DPA?

Yes. The Data Processing Addendum covers processing terms, sub-processors and residency, and is the document that governs where it conflicts with the public pages.

Security review questions welcome

If your review needs something not covered here, ask. We would rather answer it directly than have you infer it from a badge.

Procurement and DPA questions: [email protected]