Security Policy
A security company’s own website should be open to scrutiny. This page sets out the protections applied to Kunan’s systems, and how external researchers can report an issue.
Last updated
1. How our own systems are protected
Kunan applies the same principles internally that it recommends to clients: management interfaces are not exposed to the public internet, access is identity-based and least-privilege, and the control plane is separated from the data plane.
- Internal management and operations interfaces are not publicly reachable, and are accessed only over a verified zero trust channel.
- Multi-factor authentication is enabled on all accounts, with role-based permissions reviewed periodically.
- This website is statically generated and runs no server-side application code, which keeps the exploitable surface small.
- HTTPS is enforced site-wide, with security response headers configured.
2. Data protection
- Data in transit is encrypted with TLS.
- Contact form submissions are stored in an access-controlled environment reachable only by authorised personnel.
- The purpose of collection, retention periods and data subject rights are set out in the privacy policy.
- Data generated during client testing engagements is destroyed within the period agreed in the contract.
3. Responsible disclosure
If you find a security issue in a Kunan website or service, please report it using the details below. Kunan will not pursue legal action against good-faith reporters.
- Email contact@kunansec.com with "Security Report" in the subject line.
- Please include reproduction steps, an assessment of impact, and any supporting evidence.
- Receipt is acknowledged within three business days, with an update on handling once assessed.
- Please do not disclose details publicly until the issue is fixed and disclosure has been agreed.
4. Boundaries for testing
When carrying out security research, please avoid the following, which affect other users or create legal exposure:
- Denial of service testing of any kind, or anything that interrupts the service.
- Social engineering, physical intrusion, or attacks directed at Kunan staff.
- Accessing, modifying or deleting data that is not yours.
- High-volume automated scanning.
5. Certifications and audits
Certification details will be published on this page once obtained. If your procurement process requires a specific audit report or questionnaire response, please raise it through the contact page and it will be handled individually.