Trust Centre
Trust you can verify
If you're vetting us as a supplier, our accreditations and company details can be checked independently, and certificates are available on request. A penetration test gives us access to your systems and your data, so you should know exactly who you're working with before it starts.
Data handling
How we protect your data during an engagement
Testing produces sensitive material: credentials, infrastructure details, and evidence of exploitable weaknesses. This is how we look after it.
Encrypted and stored in the UK
Testing data is held in the UK, on encrypted storage, and shared with you over encrypted channels.
Seen only by the people who need it
Your data is accessed by the consultant working on your engagement. Findings and reports are shared only with the contacts you agree with us at the start.
Never passed to third-party AI
Client data, findings and testing artefacts are not passed into third-party or cloud-based AI systems at any stage. Our AI policy explains this in full, and we can confirm it in writing if you operate a no-AI policy.
Deleted when it's no longer needed
Testing data is securely deleted at the end of the retention period set out in your engagement terms. You can raise specific retention or deletion requirements when we scope the work.
Controller and processor roles
When we process personal data on your behalf during testing, you will generally be the controller and we act as processor. Exploitr is registered with the ICO, and our privacy policy covers how we handle personal data.
Company details
Who you're contracting with
The details your procurement or supplier onboarding team will usually ask for.
Registered company
Exploitr Limited, registered in England and Wales under company number 15939324.
Registered office
Bradbury House, Mission Court, Newport, NP20 2DW.
VAT registration
GB 476701277. Quoted prices exclude VAT unless stated otherwise.
ICO registration
Registered with the Information Commissioner's Office under ZB815039.
Insurance
We hold public and products liability, professional indemnity and cyber insurance.
Trademark
Exploitr® is a registered trademark owned by Exploitr Limited.
Policies
Our published policies
01
Privacy policy
What personal data we collect, why, who we share it with, and your rights. Read our privacy policy.
02
Security policy
How to report a vulnerability in our own systems to security@exploitr.com, and what to expect when you do. Read our security policy.
03
AI policy
How we use AI, and why client data never goes into third-party AI systems. Read our AI policy.
04
Cookie policy
The cookies this website uses and how to manage your consent. Read our cookie policy.
05
Testing methodology
The standards we test against and how every engagement runs from scoping to retest. See our penetration testing methodology.
Documents
Documents available on request
If you're completing supplier due diligence, we can send you:
- our CREST membership and Cyber Essentials certificates
- our insurance certificates
- a sample penetration test report, so you can see the standard of reporting before you commit
We can put an NDA in place before sharing where needed.
How to request
Email sales@exploitr.com
Tell us which documents you need and who they're for, and we'll send them over. You can also reach us through our contact page.
Ready to scope your assessment?
A 30 minute call is enough for us to understand your requirements and prepare a fixed-price quote.
