Trust

What we run, and what we can prove.

As of: September 2026

Procurement, security and legal all check a vendor before they buy. This page is the short version; the full report, policy and references follow under NDA. We are a small, named team, not a certified enterprise. So here is exactly what we run, what we can evidence, and where we are not there yet.

At a glance

Researcher
Samir Abis, named in every contract
Signature
Advanced e-signature (PAdES-B-T) + qualified timestamp (RFC 3161)
Insurance
EUR 50M per event, no deductible (T&Cs §14)
Reports kept
10 years
Data residency
EU only
Breach notice
within 24 hours
Authorization
Written scope + rules of engagement, 90 days

How we test ourselves

We test our own infrastructure continuously and re-test after every release. To be straight: we don't hold an ISO 27001 or a SOC 2 certificate today. So we show what we run and what it is evidence for, which is NIS2- and ISO-27001-aligned. Certification is a plan, not a promise.

The person behind the hunt

Samir Abis runs the hunt and signs every report with his name and the written scope. You know who did the work, and who to call when a finding comes back.

Written authorization and rules of engagement

Before a test runs, you authorize it in writing with the rules of engagement: scope, techniques, rate limits, no-gos, contact and deputy. The authorization is valid for 90 days. Nothing runs without a current one.

Data protection (GDPR)

You are the controller, we are the processor (DPA, Art. 28 GDPR). Processing stays in the EU. Measures: encryption in transit and at rest, least-privilege access, append-only logging, secure deletion. Sub-processors: Google Cloud (EU region) and PostHog Cloud EU (Frankfurt), and only after your consent. In a data-protection incident we notify you within 24 hours.

Request the full documentation

We share the full (redacted) report, policy and references under NDA. Write to sales@rheono.dev and we reply within one business day.