Security Evidence and Data Handling Policy
This policy describes how ThreatNest handles credentials, assessment evidence, reports, and sensitive client information.
Terms for a specific engagement may impose stricter requirements.
1. Data minimization
ThreatNest collects and retains only the information reasonably necessary to:
- perform the agreed assessment;
- validate findings;
- prepare the report;
- complete the included retest;
- and satisfy contractual or legal obligations.
2. Secure exchange
Credentials, access tokens, private repository invitations, and sensitive documents must not be submitted through the public website form.
ThreatNest will provide an approved method for secure exchange after the engagement is confirmed.
Clients should provide temporary, dedicated test accounts with the least privilege needed whenever possible.
3. Credentials
Credentials are used only for the authorized engagement.
ThreatNest will not intentionally reuse credentials for another purpose or share them with personnel who do not require access.
Temporary credentials should be disabled, rotated, or deleted after testing.
4. Evidence collection
Evidence may include:
- screenshots;
- relevant HTTP requests and responses;
- sanitized logs;
- affected URLs or parameters;
- version information;
- proof of concept output;
- and notes necessary to reproduce or remediate a finding.
ThreatNest avoids collecting full records where a partial or redacted example is sufficient.
5. Sensitive information encountered during testing
If patient information, credentials, personal information, or other sensitive records are unexpectedly exposed, ThreatNest will:
- stop unnecessary access;
- collect only the minimum evidence needed;
- avoid further disclosure;
- notify the designated client contact where appropriate;
- and handle the evidence according to the engagement requirements.
ThreatNest does not determine whether the event legally constitutes a reportable breach.
6. Access control
Evidence and reports are available only to approved personnel who require access for testing, verification, reporting, delivery, retesting, or necessary administration.
Access may be removed when a person’s role ends or the engagement no longer requires it.
7. Delivery
Reports are delivered through an agreed channel.
The client is responsible for protecting downloaded reports and controlling who receives them after delivery.
Email delivery may be used for ordinary documents only where the parties consider it appropriate. More sensitive reports may require a restricted link or another approved secure method.
8. Retention and deletion
Unless otherwise agreed:
- raw evidence is deleted within 30 days after the later of final report delivery or completion of the included retest;
- temporary credentials and tokens are removed as soon as no longer required;
- delivery copies of final reports are removed within 90 days after completion;
- and signed agreements, authorizations, invoices, and legally relevant records may be retained for the required business or legal period.
Deletion from active storage may not immediately remove information from encrypted backups that are kept for a limited period. Backup copies expire according to the applicable backup cycle and are not restored for ordinary business use after deletion.
9. Team members and service providers
Approved team members must follow the same confidentiality and evidence handling requirements applicable to the engagement.
Third party service providers receive only the information reasonably necessary for their function.
ThreatNest does not intentionally place client evidence into public artificial intelligence systems, public repositories, or unrestricted collaboration spaces.
10. Incidents
If ThreatNest becomes aware of unauthorized access to client evidence under its control, ThreatNest will investigate, contain the issue, preserve relevant information, and notify the affected client without unreasonable delay where notification is appropriate.
11. Client deletion requests
Clients may request earlier deletion of report delivery copies or raw evidence, subject to legal, contractual, payment, dispute, and backup limitations.
Requests may be sent to threatnest@threatnest.com.