Scoped engagements
Every engagement starts with a written scope, rules of engagement, and a signed NDA. Testing stays inside agreed boundaries and the client owns all findings.
ShadowCore handles sensitive systems and findings for clients across regulated sectors. This page sets out the security practices, data handling, and compliance alignment we hold ourselves to — the same standards we audit against.
Every engagement starts with a written scope, rules of engagement, and a signed NDA. Testing stays inside agreed boundaries and the client owns all findings.
Reports, proof-of-concept artifacts, and screenshots are encrypted in transit and at rest. Access is restricted to the assigned engagement team.
Multi-factor authentication, hardware-backed keys for production tooling, least-privilege access, and timely revocation when engagements close.
Defined retention windows for client data and artifacts. Secure destruction at the end of the agreed retention period or on client request.
The technical and organizational controls behind every engagement.
Engagement devices run full-disk encryption, EDR coverage, automatic patching, and managed configuration baselines.
Testing infrastructure is isolated from corporate systems. Dedicated environments are used for client engagements when required.
API keys, credentials, and client-provided secrets are stored in a vault with auditable access and short-lived tokens where supported.
Centralized logging across engagement tooling and infrastructure to support investigation, audit, and continuous improvement.
Code, configuration, and policy changes are peer-reviewed before deployment. Production tooling is versioned and reproducible.
Background-appropriate vetting, signed confidentiality obligations, and ongoing security awareness for all delivery team members.
How client data, findings, and engagement artifacts are protected.
Client data is handled under strict need-to-know access. Findings, evidence, and reports are not shared with third parties without written consent.
We collect only the data required to deliver the engagement. Where sample data is sufficient, production data is avoided.
EU-based delivery focus. Where transfers outside the EEA are necessary, recognized transfer mechanisms are applied and documented.
Engagement reports and artifacts remain client property. Anonymized references are used in case studies only with prior written approval.
How our practices map to the frameworks our clients rely on.
GDPR. ShadowCore processes personal data only as necessary to deliver agreed engagements, under documented legal bases and the General Data Protection Regulation (EU) 2016/679. Standard Contractual Clauses are supported for cross-border transfers where applicable.
NIS2. Our team has hands-on experience implementing and auditing NIS2 Directive (EU) 2022/2555 requirements for Essential and Important Entities — including gap analysis, policy development, incident reporting procedures, and management body accountability.
ISO 27001. Internal controls, policies, and evidence are structured to align with ISO/IEC 27001:2022 — including risk management, access control, supplier security, incident handling, and continual improvement.
Client confidentiality. Engagement data is handled under strict need-to-know access. Non-disclosure agreements are standard for every engagement, and pentest reports and findings are encrypted in transit and at rest.
Key internal policies governing our operations and service delivery.
Comprehensive security framework governing all operations, data handling, and personnel.
GDPR-compliant DPA available for all clients. Standard Contractual Clauses supported.
Documented IR procedures with <1h SLA for critical incidents. Tested quarterly.
BCP/DR procedures ensuring service continuity. RPO <1h, RTO <4h for all critical systems.
All third-party vendors undergo security assessment before onboarding.
Vulnerability disclosure program for reporting security issues. Contact security@shadowcore.io.
Industry-recognized certifications and practical experience held by our delivery team.
Offensive Security Certified Professional and Web Expert. Advanced penetration testing and web application exploitation.
eLearnSecurity Certified Professional Penetration Tester and Web Application Penetration Tester eXtreme.
Industry-recognized certifications covering penetration testing methodology, vulnerability management, and security fundamentals.
Burp Suite Certified Practitioner. Specialized in web application security testing with industry-standard tools.
Practical experience implementing and auditing NIS2 Directive requirements for Essential and Important Entities.
Audit and implementation experience for GDPR compliance and ISO 27001 information security management systems.
A coordinated path for reporting security issues that affect ShadowCore systems or services.
If you believe you have found a security issue affecting ShadowCore — our website, public infrastructure, or delivery tooling — please contact us privately so we can investigate and remediate before any public discussion.
Reach out for a Data Processing Agreement, security questionnaire response, or a deeper conversation about how we operate.
Contact ShadowCore