Trust / Security

Trust is a system property.

We design security, privacy, reliability, and human accountability into our work from discovery through operations.

01 / CONTROL AREAS

Defence in depth, explained plainly.

S01

Data

Purpose limitation, minimisation, encryption, retention controls, and environment separation.

S02

Identity

Least privilege, strong authentication, workload identity, and access review.

S03

Software

Peer review, dependency controls, testing, provenance, and change traceability.

S04

Infrastructure

Hardened configuration, network boundaries, secrets management, and recoverability.

S05

AI systems

Evaluation, input/output controls, human oversight, model and prompt change management.

S06

Operations

Actionable logging, incident response, supplier review, and continuous improvement.

02 / RESPONSIBLE DISCLOSURE

Found a security issue?

Send a clear report to security@sekoia.site. Include the affected surface, reproduction steps, potential impact, and a safe way to contact you.

Our commitment

  • Acknowledge valid reports within 24 hours
  • Keep you informed as we investigate and remediate
  • Not pursue good-faith research that avoids privacy harm, service disruption, and data destruction
  • Credit researchers when requested and appropriate

Do not test on client environments, access data beyond what is necessary to demonstrate the issue, or use social engineering.

SEKOIA / START

Need assurance for an evaluation?

Contact our team for architecture, risk, privacy, and supplier-security information relevant to your engagement.

Start a conversation