Home Services Penetration Testing Work About Research Contact Cyber Range BytePatch Labs Our Security Posture Call +91 98836 53673 WhatsApp
Trust · Our own security posture

A security firm should be the easiest vendor you ever review.

If you are about to hand us credentials, a codebase or a production environment, you are entitled to know exactly how we handle it. This page is the answer, written out in full so you do not have to send a questionnaire to get it.

It is also the standard we hold ourselves to. We sell this posture to clients; publishing it means you can hold us to it too.

Send us your security questionnaire→ security.txt
01

Data handling

We ask for the minimum data an engagement needs, and we say no to the rest. A penetration test does not need your production customer database; it needs credentials for test accounts at each privilege level, and a scope document.

Where testing genuinely requires production data, it is accessed in place under your supervision and never copied to our machines. Where a copy is unavoidable, it is agreed in writing first, kept encrypted, and destroyed on the schedule below.

Findings, screenshots and request/response captures are stored only for as long as the engagement and its retest window run.

02

Confidentiality

Every engagement is confidential by default. Your name, your logo, your findings and the fact that you hired us at all stay private unless you give written permission otherwise.

We sign your NDA. If you do not have one, we provide ours before the scoping call rather than after it.

Nothing from an engagement appears in a case study, a talk, a blog post or a sales conversation without your written sign-off on the exact wording.

03

Access controls

Access to client material is granted per engagement, to the named people working on it, and revoked when the engagement closes.

Multi-factor authentication is required on every account that can reach client data, source code, infrastructure or the mailbox those things arrive in.

Credentials you issue us are treated as production secrets: stored in a password manager, never in a chat message, a ticket, a spreadsheet or a repository.

04

Data retention & destruction

Engagement artefacts — raw captures, tooling output, exported data, screenshots containing your data — are destroyed within 30 days of the retest being signed off, unless you ask us in writing to hold them longer.

The final report and its evidence appendix are retained for 12 months so we can support a re-engagement or an auditor question, then destroyed.

We issue a written destruction confirmation on request, naming what was held and what was deleted.

05

Encryption

Data in transit: TLS on everything. Reports and any file containing your data are delivered encrypted, with the passphrase sent over a different channel from the file.

Data at rest: full-disk encryption on every machine used for client work, and encryption on any cloud storage holding engagement material.

This site enforces HTTPS, sets HSTS, and ships a content security policy that blocks inline script — the same controls we ask you to put in place.

06

Secure development

Our own builds get the process we sell: threat modelling before the first commit, hardened defaults in the template, dependency scanning in the pipeline, and an OWASP Top 10 review before launch.

Secrets never live in source control. Deploys are reproducible and reviewable, and production access is separate from development access.

We do not ship code we have not read. Generated or third-party code is reviewed on the same terms as our own.

07

Incident response

If we suffer an incident that could affect your data, you are told — not managed. Initial notification within 72 hours of confirming the incident, with what we know, what we do not yet know, and what we are doing about it.

We keep a written incident plan for our own environment and rehearse it, because a firm that sells incident-response plans and does not hold one is not credible.

Post-incident, you get a written account of cause, impact and remediation, with no charge attached to it.

08

Responsible disclosure

Found something in this site or in a system we operate? Report it to developer@bytepatch.tech. We acknowledge within 72 hours and keep you updated until it is closed.

Please do not run automated scans against production, do not access or modify data that is not yours, and give us reasonable time to remediate before public disclosure.

We do not threaten researchers who follow those terms, and we credit you in the fix note if you want the credit.

09

Third-party vendors

We keep the supplier list short on purpose. Every service that can touch client data is chosen for its own security posture, not its price.

We do not subcontract security testing to an unnamed third party. If a specialist is ever brought onto an engagement, you are told who and why before they start, and they sign the same terms we do.

Client data is not fed to third-party AI services. Tooling that would transmit your code or your data off our machines is not used on client work.

10

Backup & continuity

Business records and project material are backed up, encrypted, and — the part most firms skip — restore-tested, because an untested backup is a hope, not a control.

Your deliverables are not held hostage by our infrastructure. Reports are yours, delivered to you, and independently retained on your side.

11

Employee & contractor access

BytePatch is deliberately small and founder-led. The person who scopes your engagement is the person who runs it, which removes most of the access-sprawl a larger vendor has to manage.

Anyone who works on client material is under a written confidentiality agreement before they get access, and access ends when their part of the work ends.

Devices used for client work are managed, encrypted and screen-locked. Personal devices are not used for client data.

The other half of a posture

Things we will not do, in writing.

We will not test outside scope

Not an adjacent subdomain, not a system that looks related, not "while we were in there". Scope is the document, and the document is the boundary.

We will not exfiltrate to prove a point

Proving access does not require taking the data. We demonstrate reach with the minimum evidence that establishes impact, and we say so in the report.

We will not sit on a critical finding

Anything critical is reported to your named contact the day we confirm it, not saved for the final report and the read-out call.

We will not resell your findings

Your vulnerabilities are not our marketing material, our training content, or a lead for a follow-on sale to someone else in your sector.

Questions your procurement team needs answered?

Send the questionnaire. We fill them in ourselves, we do not charge for it, and we do not leave a row blank to make the sheet look better. If the honest answer to a control is "not yet", that is what we write.

Talk to us→ Read the terms Privacy policy

Last reviewed: August 2026 · Owner: Mayank Minda, Founder