Security & Responsible Disclosure
As a security company, we hold ourselves to the same standard we hold our clients to.
Responsible disclosure
If you've found a security issue in our own platform or website, we want to hear about it before anyone else does. Email us at support@alastorinfosec.com with:
- A description of the issue and its potential impact
- Steps to reproduce it
- Any proof-of-concept material (screenshots, requests, scripts)
We aim to acknowledge reports within one business day and will keep you updated as we investigate and remediate.
Data handling
Client engagement data — scan results, findings, credentials shared for testing scope — is encrypted in transit and at rest, access-controlled on a least-privilege basis, and retained only as long as required for the engagement and any applicable compliance obligations (including DPDP Act / DPDPA requirements for personal data processed in India).
Cookies & bot protection
We use Cloudflare Turnstile, an invisible challenge that runs silently in the background on our forms to block automated abuse without showing visitors a CAPTCHA. Turnstile's own data handling is governed by Cloudflare's Turnstile Privacy Policy Addendum, which supplements this policy for any data Turnstile itself processes. We also use analytics cookies to understand site usage, which you can decline via the cookie banner shown on your first visit.
Our own compliance posture
Our platform's controls are mapped against SOC 2, ISO 27001, and India's DPDP Act (DPDPA). Details are available on request through our Trust Center.