Trust, Governance and How We Handle Your Data
A security company that cannot answer questions about its own controls should not be asking about yours. Here is how we operate.
How does Cipher Knights protect client data during an engagement?
Client data is handled under a written engagement agreement with defined access, encrypted storage and a stated retention period. Findings and reports are treated as confidential, access is limited to consultants working on your engagement, and evidence is securely destroyed at the end of the agreed retention window.
Access we ask for, and access we do not
Security work requires access, and that access is exactly what makes a consultancy a risk to its clients. We keep it proportionate: read-only wherever read-only will do, scoped to the systems in the engagement, time-limited to the engagement period, and using named individual accounts rather than a shared credential.
You are entitled to know which of our consultants will hold access, to have that access revoked at any point, and to see a record of what was accessed. We ask clients to remove our access at the end of an engagement, and we will remind you if you have not.
- Read-only access wherever the work permits it
- Named individual accounts, never shared logins
- Access scoped to the systems in the agreed engagement
- Time-limited and revoked at engagement close
- MFA enforced on every account we hold in your environment
Confidentiality and reporting
Reports describing your weaknesses are among the most sensitive documents your business will ever hold, and they are equally sensitive in our hands. They are stored encrypted, shared through a secure route rather than as email attachments, and never used as marketing material.
We publish case studies only with written client consent, and by default they are anonymised by sector and size. If you would prefer we never reference the engagement at all, that is the default position unless you tell us otherwise.
Commercial independence
We do not take commission from security product vendors. That matters because a recommendation is worth nothing if the recommender is paid by the outcome. Where we suggest a product we will tell you why, what the alternatives are, and whether something you already own would do the job.
Where an assessment finds that a client needs less than they are currently buying, we say so, including where that reduces our own revenue.
Included in every engagement
Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.
Trust & Governance — your questions answered
Are you insured?
Will you sign an NDA?
How long do you keep our reports and evidence?
Can we see your own security certifications?
Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.
You might also need
Ready to talk about trust & governance?
Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.