Understand how we scope testing, handle evidence, and keep you in control. Explore our operating practices and the details to agree for your engagement.
The status of each practice is shown below. Engagement-specific terms are agreed before testing.
01
Testing under control
What is tested, how it runs, and how to stop it.
Every engagement starts with written scope: assets, exclusions, owners. Nothing outside it is touched.
Validation runs in isolated environments with bounded load, windows, and techniques.
A documented stop procedure and escalation contact before any execution starts.
02
Evidence & data
Who can access the results and how they are handled.
Requests, responses, and reproduction steps captured per finding, shared only with named recipients.
Encryption in transit and at rest for evidence and reports.
Every action timestamped and attributable, exportable on request.
Defined retention per engagement, deletion on request and at close.
03
Your engagement
Access, hosting, providers, and security contacts.
Dedicated short-lived credentials with a defined lifecycle. Full process to be published.
Local residency when the scope requires it. Architecture still being defined.
Any third-party models involved in analysis will be listed here with what they process.
No subprocessors at this stage. This list will grow here if that changes.
A coordinated disclosure path for issues found outside an engagement. Process being defined.
Something urgent? Reach us through the contact page and mark it security-sensitive.
[MOROCCAN FRAMEWORK]
The right framework for your organization.
Official references to consider when defining your engagement.
01 / CNDP · 09-08
Personal-data protection
Scope the engagement around applicable personal-data obligations: purpose, access, retention, and CNDP formalities. Review cross-border transfers before choosing where evidence is hosted or who receives it.
For entities in scope and sensitive information systems of critical infrastructure, assess Law 05-20 and its implementing requirements. Continuous validation does not replace a regulated audit that requires a DGSSI-qualified provider.
Applicable requirements depend on your organization and the proposed processing. These scoping considerations are not a certification or a guarantee of compliance.
Questions before you start?
Let’s review your assets, data requirements, and testing limits together.