Seccuti
Trust

What we hold, and for how long.

A penetration test produces sensitive material by design. This page says what is kept, who can read it, and how to get it removed.

Data handling
Engagement data
Scope, authorization record, findings, evidence and reports, held against your organization.
Who can read it
Members of your organization, and any client you explicitly grant portal access to.
Evidence
Screenshots, requests and responses captured during testing, stored privately and served only after a permission check.
Credentials you supply
Held as sealed ciphertext and used only against the engagement they were supplied for.
Deletion
Ask and we remove an engagement and its evidence. The audit record that an engagement existed is retained, because an append-only log that can be edited is not an audit log.
Responsible disclosure
If you believe you have found a vulnerability in Seccuti, contact us before publishing and we will work with you.

Company registration details, the legal entity and the contact address are recorded on the contact page.

Ask before you buy.

Trust questions are easier to answer early.