root64Offensive Security. Cyber Resilience. Trusted Expertise.
Trust centre

Trust centre and responsible disclosure

We ask clients to trust us with access to their systems. This page sets out what we do with it, and how to tell us if something we run is broken.

CONTROL / 01Authorise.Minimise.Destroy.
Evidence handling

How we handle your data during an engagement

01

Minimum necessary access

We request the least privilege that allows the agreed testing, for the shortest window that works.

02

Evidence is proof, not collection

Where a finding involves personal or confidential data, we evidence that access was possible. We do not extract or retain the data itself.

03

Encrypted storage and transfer

Engagement data is encrypted at rest and in transit, and is accessible only to the testers assigned to your engagement.

04

Defined retention

Engagement data is destroyed on the schedule set in the contract. You can request earlier destruction in writing at any time.

05

Confidentiality

Reports and findings are never shared, published or reused as marketing material without your written consent.

06

Sub-processors

We will tell you before any third party is involved in delivering your engagement.

Responsible disclosure

Responsible disclosure

If you have found a security issue in this website or any Root64-operated system, we want to hear about it.

How to report

  1. Email the disclosure address below with enough detail to reproduce the issue.
  2. Give us a reasonable window to fix it before disclosing publicly.
  3. Do not access, modify or delete data that is not yours, and do not degrade the service for anyone else.
  4. Automated scanning at volume, denial of service and social engineering of our staff are not in scope.

[email protected]

What we commit to

Acknowledgement
Within 3 working days
Initial assessment
Within 10 working days
Progress updates
Until the issue is closed
Credit
Named acknowledgement if you want it

We do not currently run a paid bug bounty. Reports made in good faith under these guidelines will not result in legal action from us.

security.txt

This website

About this website

Security claims should be visible in the implementation, not hidden in a policy document.

How this site is built

  • Static content. No customer login, no database of visitor records, no file upload.
  • No third-party analytics, advertising or tracking scripts.
  • Fonts are self-hosted. This site makes no requests to a font CDN.
  • Served over HTTPS with a restrictive Content-Security-Policy.
  • Enquiries reach us through WhatsApp or email — both external services, and neither is treated as confidential.
Contact us