TRUST & SECURITY

Your security is only as trustworthy as ours.

You're inviting us to look at your systems — so you deserve to know exactly how we handle that access, where your data lives, and what we do (and never do) with it. No vague assurances. Here's the whole picture.

ISO 27001Information security
Cyber EssentialsUK NCSC scheme
UK GDPRData protection
NCSC-alignedUK guidance

The agent: read-only, and you can read it too

Our server agent is the deepest access we ask for — so it's the most locked-down thing we build. Four hard guarantees:

Read-only

It observes — checks patches, config, logs, running processes. It does not change your system. The only actions it can ever take are a short list of reversible containment steps, and only when a human on your side approves each one.

Outbound only

The agent opens no ports and accepts no inbound connections. It reaches out to us — never the other way around — so it never widens your attack surface.

Source published

The install script is served in the open and its source is published. You (or your engineers) can read exactly what will run on your machine before you run it — no black box.

Nothing hoarded

A scan reads what it needs, reports the findings, and moves on. We don't keep copies of your source, your files, or your logs sitting on disk after the work is done.

Where your data lives

Straight answers on hosting, encryption, and retention — the questions any security-conscious buyer asks first.

Hosting regionUK/EU — our application and database run in AWS eu-west-1 (Ireland). Your data does not leave the region.
Encryption in transitEverything is served over TLS. The agent's connection back to us is encrypted end to end.
Encryption at restOur managed database (AWS RDS) encrypts stored data at rest.
Scan artefactsFindings are stored against your account so you can see your history. Raw material a scan reads (page source, file contents, logs) is not retained after the scan completes.
AuthenticationPasswordless — we email you a one-time 6-digit code. We never store a password to your account because there isn't one.
PaymentsHandled entirely by Stripe. We never see or store your card details.
Sub-processorsAWS (hosting), Stripe (payments), Cloudflare (DNS/edge), Resend (transactional email). That's the full list.

How we test — and stay in scope

Active and pentest work can touch your systems, so consent and scope are built into the flow, not an afterthought.

We prove you own it first

Active checks (open ports, deeper probing) only run once you've verified ownership of a domain with a DNS record. This protects you — and everyone else — from being scanned without permission.

Pentests are scoped & authorised

Every human pentest starts with a written scope and an explicit authorisation that you own or may permit testing of the targets. We only touch what's on the list.

RESPONSIBLE DISCLOSURE

Found a vulnerability in Solvbeat?

We're a security company — we take our own security seriously and we welcome reports. If you believe you've found a vulnerability in our systems, tell us privately first and give us a reasonable window to fix it before any public disclosure. We'll respond, keep you updated, and credit you if you'd like.

Email support@solvbeat.co.uk with "Security" in the subject.