Trust Centre

Trust you can verify

If you're vetting us as a supplier, our accreditations and company details can be checked independently, and certificates are available on request. A penetration test gives us access to your systems and your data, so you should know exactly who you're working with before it starts.

Accreditations and memberships

Accreditations

Accreditations & memberships

Our accreditations cover how we test and the security of our own environment.

CREST member company

Since September 2026 Exploitr has been a CREST member company, accredited for penetration testing. CREST assesses our processes, methodology and quality assurance at company level.

Cyber Essentials

We hold Cyber Essentials, the UK government-backed certification covering baseline security controls in our own environment.

UK Cyber Security Council

Exploitr joined the UK Cyber Security Council as a Corporate Member in January 2026.

CREST AI Charter

We are a signatory of the CREST AI Charter. Our AI policy sets out how we address each of the CREST principles for AI-enabled activities.

OSCP and OSCE

Every engagement is led by an OSCP and OSCE-certified consultant. Both are practical offensive security certifications earned in live, proctored exams.

No subcontracting

Every assessment is carried out in-house. The consultant assigned at scoping tests your environment and writes your report.

Data handling

How we protect your data during an engagement

Testing produces sensitive material: credentials, infrastructure details, and evidence of exploitable weaknesses. This is how we look after it.

Encrypted and stored in the UK

Testing data is held in the UK, on encrypted storage, and shared with you over encrypted channels.

Seen only by the people who need it

Your data is accessed by the consultant working on your engagement. Findings and reports are shared only with the contacts you agree with us at the start.

Never passed to third-party AI

Client data, findings and testing artefacts are not passed into third-party or cloud-based AI systems at any stage. Our AI policy explains this in full, and we can confirm it in writing if you operate a no-AI policy.

Deleted when it's no longer needed

Testing data is securely deleted at the end of the retention period set out in your engagement terms. You can raise specific retention or deletion requirements when we scope the work.

Controller and processor roles

When we process personal data on your behalf during testing, you will generally be the controller and we act as processor. Exploitr is registered with the ICO, and our privacy policy covers how we handle personal data.

Company details

Who you're contracting with

The details your procurement or supplier onboarding team will usually ask for.

Registered company

Exploitr Limited, registered in England and Wales under company number 15939324.

Registered office

Bradbury House, Mission Court, Newport, NP20 2DW.

VAT registration

GB 476701277. Quoted prices exclude VAT unless stated otherwise.

ICO registration

Registered with the Information Commissioner's Office under ZB815039.

Insurance

We hold public and products liability, professional indemnity and cyber insurance.

Trademark

Exploitr® is a registered trademark owned by Exploitr Limited.

Policies

Our published policies

01

Privacy policy

What personal data we collect, why, who we share it with, and your rights. Read our privacy policy.
02

Security policy

How to report a vulnerability in our own systems to security@exploitr.com, and what to expect when you do. Read our security policy.
03

AI policy

How we use AI, and why client data never goes into third-party AI systems. Read our AI policy.
04

Cookie policy

The cookies this website uses and how to manage your consent. Read our cookie policy.
05

Testing methodology

The standards we test against and how every engagement runs from scoping to retest. See our penetration testing methodology.

Documents

Documents available on request

If you're completing supplier due diligence, we can send you:

  • our CREST membership and Cyber Essentials certificates
  • our insurance certificates
  • a sample penetration test report, so you can see the standard of reporting before you commit

We can put an NDA in place before sharing where needed.

How to request

Email sales@exploitr.com

Tell us which documents you need and who they're for, and we'll send them over. You can also reach us through our contact page.

Ready to scope your assessment?

A 30 minute call is enough for us to understand your requirements and prepare a fixed-price quote.