As of: September 2026
Procurement, security and legal all check a vendor before they buy. This page is the short version; the full report, policy and references follow under NDA. We are a small, named team, not a certified enterprise. So here is exactly what we run, what we can evidence, and where we are not there yet.
At a glance
We test our own infrastructure continuously and re-test after every release. To be straight: we don't hold an ISO 27001 or a SOC 2 certificate today. So we show what we run and what it is evidence for, which is NIS2- and ISO-27001-aligned. Certification is a plan, not a promise.
Samir Abis runs the hunt and signs every report with his name and the written scope. You know who did the work, and who to call when a finding comes back.
Before a test runs, you authorize it in writing with the rules of engagement: scope, techniques, rate limits, no-gos, contact and deputy. The authorization is valid for 90 days. Nothing runs without a current one.
You are the controller, we are the processor (DPA, Art. 28 GDPR). Processing stays in the EU. Measures: encryption in transit and at rest, least-privilege access, append-only logging, secure deletion. Sub-processors: Google Cloud (EU region) and PostHog Cloud EU (Frankfurt), and only after your consent. In a data-protection incident we notify you within 24 hours.
We share the full (redacted) report, policy and references under NDA. Write to sales@rheono.dev and we reply within one business day.