Trust Center
Before you share your environment with us, you deserve to know exactly how we operate, how we protect your data, and the standards we hold ourselves to.
Strict Confidentiality
- โAll client engagements are covered by Non-Disclosure Agreements (NDAs) signed before any work begins.
- โFindings, recommendations, and client data are never shared with third parties without explicit written consent.
- โClient identity and engagement details are never used in marketing materials without written approval.
- โAll team members are bound by confidentiality obligations throughout and after their engagement.
Secure Data Handling
- โSensitive client data is encrypted at rest (AES-256) and in transit (TLS 1.3) at all times.
- โData collected during engagements is retained only as long as needed and securely deleted upon project closure.
- โCredentials, network diagrams, vulnerability data, and assessment artifacts are stored in encrypted, access-controlled systems.
- โWe do not use client data to train AI models or for any purpose beyond the contracted engagement.
Professional Methodology
- โAll assessments follow recognized industry frameworks including NIST CSF, OWASP, CIS Controls, and PTES.
- โWe conduct scoping calls to define authorized systems and rules of engagement before any testing begins.
- โFindings are verified before reporting โ we do not include unconfirmed or theoretical vulnerabilities.
- โAll consultants maintain relevant certifications (CISSP, CISM, AWS Security, Azure Security, etc.).
Supported Frameworks
- โNIST Cybersecurity Framework (CSF) 2.0
- โSOC 2 Type I and Type II
- โISO/IEC 27001:2022
- โHIPAA Security Rule
- โPCI DSS v4.0
- โCMMC 2.0 (Levels 1โ3)
- โCIS Controls v8
- โOWASP Top 10 and ASVS
Operational Security
- โDiTconsult operates a documented information security program covering access control, incident response, and data protection.
- โPrivileged access to client environments is managed through role-based access controls and removed immediately upon project completion.
- โClient system access is documented, time-bounded, and reviewed throughout each engagement.
- โPenetration testing engagements require signed authorization letters and scoping agreements before work begins.
Ethical Standards
- โWe adhere to professional codes of ethics including (ISC)ยฒ Code of Ethics and EC-Council Code of Ethics.
- โWe do not perform offensive security work without written authorization โ every engagement has a defined scope.
- โConflicts of interest are disclosed and managed transparently.
- โWe decline engagements that conflict with our ethical standards, regardless of compensation.
Our Security Commitment
DiTconsult was built by cybersecurity practitioners who understand the sensitivity of the work. We apply the same security rigor to our own operations that we recommend to clients. When you engage with us, your environment, your data, and your reputation are in the hands of professionals who take security personally.
If you have questions about our security practices, require specific contractual protections, or need a completed vendor security questionnaire, please reach out โ we are happy to provide complete documentation.
Secure ยท Transform ยท Protect
Get a clear next step for your security posture
Book a DiTconsult consultation to review your cloud, compliance, or remediation priorities. After you submit the form, we confirm receipt, schedule a short discovery call, and recommend the right packaged engagement.
- Specific reason to reach out: cloud risk, compliance readiness, or remediation backlog
- What happens next: confirmation, discovery call, scoped recommendation
- No passwords, access keys, or incident evidence needed in the form