// Trust & Security
We hold your access — so how we handle it matters
Offensive-security work means trusting us with sensitive systems and data. Here's how we earn and protect that trust on every engagement.
Data handling & retention
We collect the minimum data required to do the work, keep it encrypted in transit and at rest, and never share it with third parties. Client data and findings are deleted after a short, agreed retention window once the engagement closes.
NDA & confidentiality
Engagements run under a mutual NDA agreed before any scoping. What we find stays between us — your findings are never referenced, published, or used as a case study without your explicit written consent.
Secure communications
Sensitive material — credentials, reports, evidence — is exchanged over encrypted channels and delivered through a secure portal, not email attachments. A PGP key is available for high-sensitivity correspondence.
Rules of engagement
All testing is authorized, scoped, and non-destructive, run in coordinated windows agreed with you in advance. We stop and escalate immediately on any critical finding or unexpected impact — you are never surprised.
Access & credentials
We use least-privilege test accounts wherever possible. Any credentials you provide are stored in a secrets manager, used only for the engagement, and revoked or rotated on completion. We ask you to treat them as burnable.
Scoped, least-impact testing
We test only what’s in scope. Destructive techniques, denial-of-service, and social engineering are excluded unless explicitly authorized in writing. Production testing, when needed, is planned to minimize any risk to your users.
Found an issue in our own systems?
We practice what we sell. If you've found a security issue in Shura Labs' own website or infrastructure, we want to hear from you. Email security@shuralabs.io — we'll acknowledge promptly and work with you in good faith. Our machine-readable policy lives at /.well-known/security.txt.
Need something specific for a vendor security review — SOC 2 report, certificate of insurance, DPA, or a completed questionnaire? Just ask and we'll turn it around quickly.