CYBERSECURITY FOR SMALL & GROWING BUSINESSESClarity. Control. Confidence.

REDSOCCYBER

Our security principles

The access, authorization, reporting, and ownership principles behind RedSocCyber engagements.

Define the work before requesting access.

Each engagement should identify covered systems, permitted activities, service hours, approval requirements, and the people responsible for key decisions. An initial conversation does not require passwords or a technical connection to your environment.

Use named, limited access.

Provider access should have an agreed purpose, appropriate permissions, and a defined removal process. Your business retains ownership of its accounts and systems. We do not ask you to place passwords or secret keys into a public inquiry form.

Make actions accountable.

Reports should distinguish completed work, open findings, customer decisions, and exceptions. Assessments and changes stay within their authorized scope. Work that needs another provider or a separate project is made explicit.

Match the promise to the coverage.

Business-hours support, automated tools, and staffed after-hours response are different things. Your agreement should make that distinction clear and identify escalation routes before they are needed.

Report a website security concern responsibly.

Please use our contact channel to describe a suspected issue on this website. Include the affected page and a brief description, without confidential data or exploit payloads. Do not access other users’ information, disrupt services, conduct social engineering, or test systems outside an expressly authorized scope.

A message reporting a concern does not authorize additional testing or establish a bounty program.