Alastor InfoSec

Security & Responsible Disclosure

As a security company, we hold ourselves to the same standard we hold our clients to.

Responsible disclosure

If you've found a security issue in our own platform or website, we want to hear about it before anyone else does. Email us at support@alastorinfosec.com with:

  • A description of the issue and its potential impact
  • Steps to reproduce it
  • Any proof-of-concept material (screenshots, requests, scripts)

We aim to acknowledge reports within one business day and will keep you updated as we investigate and remediate.

Data handling

Client engagement data — scan results, findings, credentials shared for testing scope — is encrypted in transit and at rest, access-controlled on a least-privilege basis, and retained only as long as required for the engagement and any applicable compliance obligations (including DPDP Act / DPDPA requirements for personal data processed in India).

Cookies & bot protection

We use Cloudflare Turnstile, an invisible challenge that runs silently in the background on our forms to block automated abuse without showing visitors a CAPTCHA. Turnstile's own data handling is governed by Cloudflare's Turnstile Privacy Policy Addendum, which supplements this policy for any data Turnstile itself processes. We also use analytics cookies to understand site usage, which you can decline via the cookie banner shown on your first visit.

Our own compliance posture

Our platform's controls are mapped against SOC 2, ISO 27001, and India's DPDP Act (DPDPA). Details are available on request through our Trust Center.

We use cookies to keep the platform secure and understand how our site is used. See our Security & Data policy for details.