BreachrrSecurity
Open for engagements

§Trust

Trust & Disclosure

How we handle the essentials — confidentiality, insurance, disclosure, and the tools we work with.

Effective 27 July 2026

§01

Non-disclosure

A mutual non-disclosure agreement is signed before every scoping conversation. Client information covered under NDA remains confidential indefinitely.

Our standard NDA template is available on request. We are comfortable working under yours if you prefer.

§02

Responsible disclosure

Vulnerabilities identified in third-party systems during our work are disclosed to the affected party through their published disclosure channel. We do not publish client-specific findings without explicit written permission.

Our full responsible disclosure policy is available on request.

§03

Incident notification

If we become aware of a data incident affecting a client, we notify the client within 24 hours with all the information they need for their own regulatory notifications.

§04

Insurance

Professional indemnity insurance is held with Hiscox, with coverage of £2,000,000 per claim. A certificate of insurance is available on request.

§05

Sub-processors

The tools that may touch client data during engagements are listed below. This list is kept current.

  • GitHub — code and issue tracking
  • 1Password — secrets and credentials
  • Notion — engagement documentation
  • Google Workspace — email and file collaboration
  • Slack — channel-based communication
§06

Contact

For any trust or disclosure question: info@breachrrsecurity.com.

Talk to us

Ready when you are. Open for engagements.

An intro conversation to talk through your situation. We'll ask about your stage, your compliance target, and what forced the conversation. Then we tell you honestly whether we're the right fit.