BROOT SECURITY
Compliance & Governance

Privacy Policy

Whether we are building your product or breaking it, the same rule applies: your briefs, source code, scopes and findings stay sealed, localized and yours.

Scope Minimization

We only collect target technical configurations required for manual audits. No unnecessary logs, payloads, or credentials are cached or processed.

NDA-First Policy

Briefs, designs, source code, credentials and draft reports — for build and security engagements alike — are protected under mutual non-disclosure covenants, housed on encrypted local drives.

Data Isolation

Vulnerability scans and exploit code sequences are executed from air-gapped systems, ensuring zero exposure to third-party providers.

Auto-Deletion Schedules

Scan sequences and payload records are permanently purged 90 days following patch verification, retaining only non-technical metadata.

1. Information You Send Through This Site

The contact form collects your name, work email, organization, optional phone number, the service you need and your project or scope details. Submitting it opens a pre-filled message in your own email client — we run no form backend, so nothing is stored by this website. What you send is used solely to scope and answer your enquiry, and is never sold or shared with third parties.

2. Engagement Target Scoping

BROOT SECURITY collects specific digital assets (IP addresses, API endpoints, domain profiles, and git targets) only after explicit, bilateral client authorization. We do not inspect, scrap, or index systems outside the approved scope of work.

3. Credentials, Source Code & Build Material

Temporary credentials provided during white-box assessments are stored exclusively in memory or within isolated, password-protected local environments, and are revoked when testing completes. Repositories, designs and briefs handed to us for development work are reviewed under NDA on isolated machines, and access is returned or destroyed when the engagement ends. Your intellectual property remains yours.

4. Vulnerability Logs & Deliverables

Draft pentesting reports, raw exploit outputs, and proof-of-concept scripts are stored in encrypted environments utilizing AES-256 standard protocols. No vulnerability logs are ever distributed across public cloud platforms or shared systems.

5. Analytics & Cookies

This website uses Vercel Analytics to collect aggregate, anonymized usage metrics — page views and general performance data. We run no advertising trackers and build no visitor profiles. See the Cookie Policy for details.

6. Compliance Standards

All data processing protocols conform directly to OSSTMM guidelines, OWASP security specifications, and global data privacy protections. For questions regarding audit trails or data retention, contact the BROOT Compliance Team at contact@brootsec.com.