Skip to main content
Transparency
How We Protect You

Trust Center

Before you share your environment with us, you deserve to know exactly how we operate, how we protect your data, and the standards we hold ourselves to.

๐Ÿ”’

Strict Confidentiality

  • โœ“All client engagements are covered by Non-Disclosure Agreements (NDAs) signed before any work begins.
  • โœ“Findings, recommendations, and client data are never shared with third parties without explicit written consent.
  • โœ“Client identity and engagement details are never used in marketing materials without written approval.
  • โœ“All team members are bound by confidentiality obligations throughout and after their engagement.
๐Ÿ›ก๏ธ

Secure Data Handling

  • โœ“Sensitive client data is encrypted at rest (AES-256) and in transit (TLS 1.3) at all times.
  • โœ“Data collected during engagements is retained only as long as needed and securely deleted upon project closure.
  • โœ“Credentials, network diagrams, vulnerability data, and assessment artifacts are stored in encrypted, access-controlled systems.
  • โœ“We do not use client data to train AI models or for any purpose beyond the contracted engagement.
๐Ÿ“‹

Professional Methodology

  • โœ“All assessments follow recognized industry frameworks including NIST CSF, OWASP, CIS Controls, and PTES.
  • โœ“We conduct scoping calls to define authorized systems and rules of engagement before any testing begins.
  • โœ“Findings are verified before reporting โ€” we do not include unconfirmed or theoretical vulnerabilities.
  • โœ“All consultants maintain relevant certifications (CISSP, CISM, AWS Security, Azure Security, etc.).
๐Ÿ“

Supported Frameworks

  • โœ“NIST Cybersecurity Framework (CSF) 2.0
  • โœ“SOC 2 Type I and Type II
  • โœ“ISO/IEC 27001:2022
  • โœ“HIPAA Security Rule
  • โœ“PCI DSS v4.0
  • โœ“CMMC 2.0 (Levels 1โ€“3)
  • โœ“CIS Controls v8
  • โœ“OWASP Top 10 and ASVS
๐Ÿข

Operational Security

  • โœ“DiTconsult operates a documented information security program covering access control, incident response, and data protection.
  • โœ“Privileged access to client environments is managed through role-based access controls and removed immediately upon project completion.
  • โœ“Client system access is documented, time-bounded, and reviewed throughout each engagement.
  • โœ“Penetration testing engagements require signed authorization letters and scoping agreements before work begins.
โœ…

Ethical Standards

  • โœ“We adhere to professional codes of ethics including (ISC)ยฒ Code of Ethics and EC-Council Code of Ethics.
  • โœ“We do not perform offensive security work without written authorization โ€” every engagement has a defined scope.
  • โœ“Conflicts of interest are disclosed and managed transparently.
  • โœ“We decline engagements that conflict with our ethical standards, regardless of compensation.

Our Security Commitment

DiTconsult was built by cybersecurity practitioners who understand the sensitivity of the work. We apply the same security rigor to our own operations that we recommend to clients. When you engage with us, your environment, your data, and your reputation are in the hands of professionals who take security personally.

If you have questions about our security practices, require specific contractual protections, or need a completed vendor security questionnaire, please reach out โ€” we are happy to provide complete documentation.

Secure ยท Transform ยท Protect

Get a clear next step for your security posture

Book a DiTconsult consultation to review your cloud, compliance, or remediation priorities. After you submit the form, we confirm receipt, schedule a short discovery call, and recommend the right packaged engagement.

  • Specific reason to reach out: cloud risk, compliance readiness, or remediation backlog
  • What happens next: confirmation, discovery call, scoped recommendation
  • No passwords, access keys, or incident evidence needed in the form