Minimum necessary access
We request the least privilege that allows the agreed testing, for the shortest window that works.
We ask clients to trust us with access to their systems. This page sets out what we do with it, and how to tell us if something we run is broken.
We request the least privilege that allows the agreed testing, for the shortest window that works.
Where a finding involves personal or confidential data, we evidence that access was possible. We do not extract or retain the data itself.
Engagement data is encrypted at rest and in transit, and is accessible only to the testers assigned to your engagement.
Engagement data is destroyed on the schedule set in the contract. You can request earlier destruction in writing at any time.
Reports and findings are never shared, published or reused as marketing material without your written consent.
We will tell you before any third party is involved in delivering your engagement.
If you have found a security issue in this website or any Root64-operated system, we want to hear about it.
We do not currently run a paid bug bounty. Reports made in good faith under these guidelines will not result in legal action from us.
Security claims should be visible in the implementation, not hidden in a policy document.