Skip to main content

CONFIDENTIALITY & GOVERNANCE

RajSecure Trust Center

Trust, confidentiality, and legal integrity are central to our offensive security practice. Learn how we protect client environments, handle sensitive vulnerability data, and enforce strict testing boundaries.

Bilateral NDAs

We routinely execute mutual Non-Disclosure Agreements with international clients prior to reviewing architectural documentation, technical scopes, or testing credentials.

Authorized Testing Only

Security assessments begin only after receiving documented, written authorization from verified asset owners. We strictly reject unauthorized or unverified testing requests.

Data Sanitization & Retention

Temporary test credentials and raw vulnerability capture data are purged following engagement sign-off, retaining only finalized deliverables and necessary billing records.

Operating Standards & Policies

1. Secure Deliverable Handling

All vulnerability findings, technical assessments, and executive deliverables are delivered through secure, access-controlled channels (e.g. encrypted archives or secure client portal links). We avoid sharing unencrypted vulnerability reports via standard public email.

2. Clear Rules of Engagement (RoE)

Prior to testing, a defined Rules of Engagement document outlines explicit IP address ranges, allowed testing schedules, out-of-scope production assets, emergency contact trees, and escalation paths for critical vulnerabilities.

3. Non-Destructive Proof of Concepts

Our offensive specialists validate vulnerabilities using safe, non-destructive methodologies. We do not destroy production data, disrupt live customer traffic, or execute denial-of-service tests against operational business systems.

4. Need-to-Know Access Controls

Client engagement details and technical notes are restricted strictly to assigned security researchers on a need-to-know basis. Testing environments and consultant workstations utilize encrypted storage and multi-factor authentication.

5. Responsible Disclosure Alignment

We support coordinated responsible disclosure. All findings identified during private client assessments remain confidential between RajSecure and the client organization, with zero public disclosure without prior written client approval.

6. Corporate Entity & Legal Governance

RajSecure is operated by RajSecureNexa Cyvexa Private Limited. Contractual terms, statements of work, and billing procedures follow established B2B standards.

Responsible Disclosure

Read our responsible vulnerability reporting guidelines and coordinated disclosure timeline principles.

View Policy

Website Privacy Policy

Understand how we handle website visitor inquiries, contact forms, cookies, and order processing information.

View Privacy Policy

Terms of Service

Review our standard terms governing assessment ordering, payment processing, scope boundaries, and authorization.

View Terms

Have an NDA or Compliance Question?

Our leadership is available to review and execute your mutual NDA or discuss specific vendor assessment requirements.