Company
Trust & Security
Clients give us access to systems and information that matter to them. This page describes how we handle that access, and states plainly what we do not claim.
On this page
How we handle client information
The practices below apply to every engagement. Specific terms are set in the agreement for each engagement, which takes precedence over this summary.
Non-disclosure agreements
Engagements are governed by a non-disclosure agreement. Details of a client environment, findings and deliverables stay within the engagement and are shared only with the people the client names.
Least-privilege access
We ask for the minimum access the work requires, for the period it requires. Access is tied to named individuals, is logged where the platform supports it, and is removed when the work ends.
Encryption in transit
Client information is encrypted in transit when it moves between the client and Onion Infosec. Deliverables and evidence are exchanged through channels agreed with the client at the start of the engagement.
Data minimization
We collect only the data an engagement needs. Where a sample, a redacted extract or a read-only view is enough, we do not take a full copy.
Telemetry stays in the client’s tenant
In security operations and managed services, telemetry stays in the client’s tenant wherever the platform allows. Our analysts work inside the client’s SIEM, EDR or cloud console in preference to exporting logs to systems we run.
End of engagement
At the end of an engagement, access is handed back and client information is returned or deleted as agreed with the client.
Security of this website
This website is a static site served over HTTPS. It does not offer user accounts. The website security page describes how the site is built and hosted and how to report a problem with it.
Privacy and data protection
The privacy policy explains what personal data we collect, why we collect it and the rights you have over it.
The data protection page gives more detail on how we approach our data protection obligations.
Responsible disclosure
If you believe you have found a vulnerability in this website or in anything Onion Infosec operates, please tell us. The vulnerability disclosure page explains how to report it and what to expect from us.
What we do not claim
Onion Infosec does not claim any company-level certification or accreditation at present. If that changes, this page will say so, with the scope and the issuing body.
Members of our team hold OSCP, CISSP, CISM, CEH, CHFI and more. These are individual certifications, not company accreditations.
We work to frameworks such as ISO/IEC 27001, SOC 2, NIST CSF and IEC 62443 in client engagements. That describes our method. It is not a statement that Onion Infosec is certified or attested against them.
