Security & Compliance at SecurityBoat
We hold ourselves to the standard we test against.
You're trusting us with your attack surface. Here's the posture, the paper, and the process that earn that trust.
Certifications & empanelments
The paper — all real, all current.
CERT-In Empanelled
Empanelled by India's national CERT to perform security audits — required for much of Indian government and regulated-sector work.
CREST Member
Our testing methodology and personnel meet CREST's internationally recognized standards.
ISO 27001
Our own information-security management system is independently certified.
ISO 9001
Certified quality management across how we run engagements.
SOC 2 Type 2
Independently audited controls, tested for operating effectiveness over time — not a point-in-time snapshot.
Our practices
How we protect what you share with us.
Least-privilege access to customer data and engagement records
Vetted researchers under binding confidentiality terms
Engagement data segregated per customer within TriNetra
Encrypted in transit and at rest
Documentation
Request our documentation.
Need the full SOC 2 report, ISO certificates, or our policies for a vendor review? Request access and our team will respond with the documents under the appropriate terms.
Responsible disclosure
Found something? Tell us — researcher to researcher.
Found a security issue in something SecurityBoat runs? We want to hear it. Report it and we'll acknowledge, investigate, and credit you where wanted.
Looking for the customer-facing trust portal your own prospects would use? That's the Trust Center module in TriNetra →
Ready when you are
Trust is earned in the open.
Questions about our posture, our certifications, or how we handle your data? Ask directly — we'll answer with specifics.
