Skip to content
Invadel

Invadel Trust Center

Request access to review our security posture, policies, and compliance documentation.

What's inside

  • Information security and data-handling policies
  • Evidence-handling and data-retention practices
  • Certificate of insurance (professional and cyber liability)
  • Sub-processor and tooling list
  • Background-check and personnel-security policy
  • Latest independent security assessment of Invadel, under NDA

I have read and agreed to Invadel's Privacy Policy. If you do not want to submit your information, contact info [at] invadel [dot] com.

How we protect your data

Who tests the testers

Handling a client's vulnerabilities means holding some of their most sensitive information. We treat it accordingly.

NDA by default

Every engagement runs under a mutual NDA, agreed before any scope details are shared.

Encrypted evidence

Findings, reports, and testing artifacts are encrypted in transit and at rest, and access is limited to the assigned team.

Defined retention

Engagement data is retained only as long as needed for delivery and retest, then securely destroyed on a defined schedule.

Senior-only, no offshoring

Testing is performed by our in-house senior team. We do not subcontract or offshore your engagement.

Least-privilege access

We request the minimum access needed for the agreed scope, and hand back or revoke it when the engagement closes.

Independently assessed

Invadel is subject to its own independent security assessment, available under NDA through the Trust Center above.