[{"data":1,"prerenderedAt":251},["ShallowReactive",2],{"legal-data-security":3},{"id":4,"title":5,"body":6,"date":242,"description":243,"extension":244,"meta":245,"navigation":246,"path":247,"seo":248,"stem":249,"__hash__":250},"legal\u002Flegal\u002Fdata-security.md","Trust Centre",{"type":7,"value":8,"toc":230},"minimark",[9,14,18,21,50,53,57,60,82,96,100,103,132,135,139,142,156,159,162,165,169,172,175,179,182,185,189,192,195,199,202,205],[10,11,13],"h2",{"id":12},"our-assurance-position","Our assurance position",[15,16,17],"p",{},"Pensure handles sensitive information as part of authorised penetration testing. Our security model combines controls operated by Pensure with controls inherited from independently assessed cloud infrastructure.",[15,19,20],{},"Core platform workloads use Amazon Web Services (AWS). Selected managed services, including AI-enabled services where required, may use Google Cloud. The relevant cloud services are operated within the providers' independently audited control environments.",[15,22,23,24,31,32,37,38,43,44,49],{},"AWS is certified to ",[25,26,30],"a",{"href":27,"rel":28},"https:\u002F\u002Faws.amazon.com\u002Fcompliance\u002Fiso-27001-faqs\u002F",[29],"nofollow","ISO\u002FIEC 27001:2022"," and maintains ",[25,33,36],{"href":34,"rel":35},"https:\u002F\u002Faws.amazon.com\u002Fcompliance\u002Fservices-in-scope\u002FSOC\u002F",[29],"SOC 1, SOC 2 and SOC 3 reports"," for in-scope services. Google Cloud's ISMS is independently certified to ",[25,39,42],{"href":40,"rel":41},"https:\u002F\u002Fcloud.google.com\u002Fsecurity\u002Fcompliance\u002Fiso-27001",[29],"ISO\u002FIEC 27001",", and its core services are covered by regularly issued ",[25,45,48],{"href":46,"rel":47},"https:\u002F\u002Fcloud.google.com\u002Fsecurity\u002Fcompliance\u002Fsoc-2",[29],"SOC 2 Type II reports",".",[15,51,52],{},"These certifications and attestations apply to the providers and their in-scope services. They do not mean Pensure itself is certified to ISO\u002FIEC 27001 or has completed its own SOC 2 examination. Pensure uses the providers' assessed controls as part of a shared-responsibility model and remains accountable for the controls it operates.",[10,54,56],{"id":55},"what-pensure-inherits-from-its-cloud-providers","What Pensure inherits from its cloud providers",[15,58,59],{},"Depending on the service used, Pensure inherits independently assessed controls covering areas such as:",[61,62,63,67,70,73,76,79],"ul",{},[64,65,66],"li",{},"physical data-centre security;",[64,68,69],{},"underlying compute, storage and network infrastructure;",[64,71,72],{},"environmental safeguards and hardware lifecycle management;",[64,74,75],{},"resilience of managed cloud services;",[64,77,78],{},"provider identity, change-management and operational processes; and",[64,80,81],{},"encryption capabilities for managed services.",[15,83,84,85,90,91,49],{},"AWS describes this boundary through its ",[25,86,89],{"href":87,"rel":88},"https:\u002F\u002Faws.amazon.com\u002Fcompliance\u002Fshared-responsibility-model\u002F",[29],"shared responsibility model",". Google Cloud describes the same principle through its ",[25,92,95],{"href":93,"rel":94},"https:\u002F\u002Fdocs.cloud.google.com\u002Farchitecture\u002Fframework\u002Fsecurity\u002Fshared-responsibility-shared-fate",[29],"shared responsibility and shared fate guidance",[10,97,99],{"id":98},"controls-operated-by-pensure","Controls operated by Pensure",[15,101,102],{},"Pensure remains responsible for the security of its applications, identities, access policies, engagement data, testing workflows and reporting. The platform uses a defence-in-depth architecture that includes:",[61,104,105,108,111,114,117,120,123,126,129],{},[64,106,107],{},"private network boundaries for platform and data services;",[64,109,110],{},"role-based access and separate application, execution and operational responsibilities;",[64,112,113],{},"encrypted secrets management rather than credentials stored in source code;",[64,115,116],{},"KMS-backed encryption for private report, evidence and artefact storage;",[64,118,119],{},"public-access blocks and restrictive storage policies;",[64,121,122],{},"encrypted application, infrastructure and audit logs;",[64,124,125],{},"cloud audit trails for management activity;",[64,127,128],{},"service-health monitoring and operational alerting; and",[64,130,131],{},"controlled report release and time-limited customer access.",[15,133,134],{},"Controls are selected and operated according to the service, environment and sensitivity of the information involved.",[10,136,138],{"id":137},"data-and-evidence-handling","Data and evidence handling",[15,140,141],{},"Penetration-testing information is treated as sensitive. Depending on the agreed scope, an engagement may contain:",[61,143,144,147,150,153],{},[64,145,146],{},"targets and application or API information;",[64,148,149],{},"agreed access arrangements for authenticated testing;",[64,151,152],{},"vulnerability evidence, screenshots and request-response evidence;",[64,154,155],{},"reports and remediation information.",[15,157,158],{},"Connections to Pensure services use TLS\u002FHTTPS. Stored reports, evidence and operational records use cloud-provider encryption controls, including AWS KMS-backed encryption where applicable.",[15,160,161],{},"Pensure's public scoping flow does not collect passwords, API keys, access tokens, session cookies or other authentication secrets. If authenticated testing is selected, Pensure coordinates an appropriate secure access method after the target, scope and authority have been reviewed.",[15,163,164],{},"Access to customer information is limited to authorised people and services with an operational need. Customer reports are not made available merely because a file has been created; release is a separate controlled step.",[10,166,168],{"id":167},"authorised-and-controlled-testing","Authorised and controlled testing",[15,170,171],{},"Pensure requires authority for the exact target and acceptance of the applicable engagement terms before testing begins. Scope, safeguards, exclusions, schedule, access method and customer contacts are confirmed before execution.",[15,173,174],{},"Testing is designed to exercise realistic attack paths within controlled conditions. SafeGuard remains active throughout the engagement, operational intensity is agreed with the customer and material operating constraints can be recorded before testing.",[10,176,178],{"id":177},"ai-enabled-services-and-human-access","AI-enabled services and human access",[15,180,181],{},"Pensure uses AI-led workflows to support penetration testing. Core Plus adds human validation of material findings and human report quality assurance. Qualified personnel may access relevant engagement information when required to validate findings, assess exploitability, remove false positives, review evidence, finalise reporting or support remediation and retesting.",[15,183,184],{},"Where a managed AI service is used, Pensure applies the provider's enterprise service terms and security controls relevant to that service. Specific data-location, retention or customer-configured assurance requirements should be confirmed during scope review.",[10,186,188],{"id":187},"retention-and-deletion","Retention and deletion",[15,190,191],{},"Pensure retains engagement and business records only for as long as reasonably required to deliver the service, support remediation, meet contractual or legal obligations, secure the platform and resolve disputes. The applicable agreement or statement of work may set additional requirements.",[15,193,194],{},"Customers with specific retention, deletion, residency or supplier-assurance requirements should raise them during scope review so they can be confirmed before testing begins.",[10,196,198],{"id":197},"security-enquiries","Security enquiries",[15,200,201],{},"Security concerns and assurance requests are handled directly by Pensure. If you believe you have identified a security issue affecting Pensure, please include enough detail for us to investigate, but do not send credentials or sensitive customer evidence by ordinary email.",[15,203,204],{},"For security and assurance enquiries:",[61,206,207,214,224],{},[64,208,209,213],{},[210,211,212],"strong",{},"Contact:"," Pensure Pty Ltd (ABN 87 688 512 334)",[64,215,216,219,220],{},[210,217,218],{},"Email:"," ",[25,221,223],{"href":222},"mailto:josh@pensure.ai","josh@pensure.ai",[64,225,226,229],{},[210,227,228],{},"Address:"," 30-03, 201 Elizabeth Street, Sydney NSW 2000, Australia",{"title":231,"searchDepth":232,"depth":232,"links":233},"",2,[234,235,236,237,238,239,240,241],{"id":12,"depth":232,"text":13},{"id":55,"depth":232,"text":56},{"id":98,"depth":232,"text":99},{"id":137,"depth":232,"text":138},{"id":167,"depth":232,"text":168},{"id":177,"depth":232,"text":178},{"id":187,"depth":232,"text":188},{"id":197,"depth":232,"text":198},"26 August 2026","How Pensure protects penetration-testing data using Pensure-operated controls and independently assessed AWS and Google Cloud infrastructure.","md",{},true,"\u002Flegal\u002Fdata-security",{"title":5,"description":243},"legal\u002Fdata-security","7ZPZbv7Z9lfzrdhlgtuXCPbMlcQL7hfInQTyen_cWmA",1788789305858]