TRUST CENTER

Trust, earned by
how we operate

ShadowCore handles sensitive systems and findings for clients across regulated sectors. This page sets out the security practices, data handling, and compliance alignment we hold ourselves to — the same standards we audit against.

50+
Pentests Delivered
15+
Team Certifications
5+
NIS2 Audits Completed
26+ yrs
Combined Experience
Engagement discipline

How we operate

Scoped engagements

Every engagement starts with a written scope, rules of engagement, and a signed NDA. Testing stays inside agreed boundaries and the client owns all findings.

Evidence handling

Reports, proof-of-concept artifacts, and screenshots are encrypted in transit and at rest. Access is restricted to the assigned engagement team.

  • Encryption
  • Need-to-know

Identity & access

Multi-factor authentication, hardware-backed keys for production tooling, least-privilege access, and timely revocation when engagements close.

Retention & destruction

Defined retention windows for client data and artifacts. Secure destruction at the end of the agreed retention period or on client request.

Security practices

Operational Safeguards

The technical and organizational controls behind every engagement.

Endpoint hardening

Engagement devices run full-disk encryption, EDR coverage, automatic patching, and managed configuration baselines.

Network segregation

Testing infrastructure is isolated from corporate systems. Dedicated environments are used for client engagements when required.

Secrets management

API keys, credentials, and client-provided secrets are stored in a vault with auditable access and short-lived tokens where supported.

Logging & monitoring

Centralized logging across engagement tooling and infrastructure to support investigation, audit, and continuous improvement.

Change management

Code, configuration, and policy changes are peer-reviewed before deployment. Production tooling is versioned and reproducible.

Personnel security

Background-appropriate vetting, signed confidentiality obligations, and ongoing security awareness for all delivery team members.

Data protection

Confidentiality & Data Handling

How client data, findings, and engagement artifacts are protected.

Confidentiality

Client data is handled under strict need-to-know access. Findings, evidence, and reports are not shared with third parties without written consent.

Data minimization

We collect only the data required to deliver the engagement. Where sample data is sufficient, production data is avoided.

Cross-border transfers

EU-based delivery focus. Where transfers outside the EEA are necessary, recognized transfer mechanisms are applied and documented.

Client-controlled outputs

Engagement reports and artifacts remain client property. Anonymized references are used in case studies only with prior written approval.

GDPR · NIS2 · ISO 27001

Compliance Alignment

How our practices map to the frameworks our clients rely on.

GDPR. ShadowCore processes personal data only as necessary to deliver agreed engagements, under documented legal bases and the General Data Protection Regulation (EU) 2016/679. Standard Contractual Clauses are supported for cross-border transfers where applicable.

NIS2. Our team has hands-on experience implementing and auditing NIS2 Directive (EU) 2022/2555 requirements for Essential and Important Entities — including gap analysis, policy development, incident reporting procedures, and management body accountability.

ISO 27001. Internal controls, policies, and evidence are structured to align with ISO/IEC 27001:2022 — including risk management, access control, supplier security, incident handling, and continual improvement.

Client confidentiality. Engagement data is handled under strict need-to-know access. Non-disclosure agreements are standard for every engagement, and pentest reports and findings are encrypted in transit and at rest.

Governance

Security Policies

Key internal policies governing our operations and service delivery.

§

Information Security Policy

Comprehensive security framework governing all operations, data handling, and personnel.

§

Data Processing Agreement

GDPR-compliant DPA available for all clients. Standard Contractual Clauses supported.

§

Incident Response Plan

Documented IR procedures with <1h SLA for critical incidents. Tested quarterly.

§

Business Continuity Plan

BCP/DR procedures ensuring service continuity. RPO <1h, RTO <4h for all critical systems.

§

Vendor Security Policy

All third-party vendors undergo security assessment before onboarding.

§

Responsible Disclosure

Vulnerability disclosure program for reporting security issues. Contact security@shadowcore.io.

Credentials

Team Certifications & Expertise

Industry-recognized certifications and practical experience held by our delivery team.

OSCP / OSWE

Offensive Security Certified Professional and Web Expert. Advanced penetration testing and web application exploitation.

eCPPT / eWPTX

eLearnSecurity Certified Professional Penetration Tester and Web Application Penetration Tester eXtreme.

CompTIA Pentest+ / Security+

Industry-recognized certifications covering penetration testing methodology, vulnerability management, and security fundamentals.

BSCP

Burp Suite Certified Practitioner. Specialized in web application security testing with industry-standard tools.

NIS2 Expertise

Practical experience implementing and auditing NIS2 Directive requirements for Essential and Important Entities.

GDPR / ISO 27001

Audit and implementation experience for GDPR compliance and ISO 27001 information security management systems.

Security contact

Responsible Disclosure

A coordinated path for reporting security issues that affect ShadowCore systems or services.

If you believe you have found a security issue affecting ShadowCore — our website, public infrastructure, or delivery tooling — please contact us privately so we can investigate and remediate before any public discussion.

  • Email support@shadowcore.pro with a clear description, reproduction steps, and any supporting evidence.
  • Please avoid testing that disrupts service availability or accesses data that is not your own.
  • We aim to acknowledge submissions promptly and keep reporters informed through remediation.
Report a security issue

Questions about our practices?

Reach out for a Data Processing Agreement, security questionnaire response, or a deeper conversation about how we operate.

Contact ShadowCore