This English text is provided for convenience. The authoritative version is the Romanian one and, in the event of any divergence, it prevails.
1Purpose, scope and principles
1.1.Purpose.This policy sets the binding rules by which TECHCORNER S.R.L. (“4Tify”) collects, stores, uses, transmits and destroys client data and data obtained in the course of the security services. It puts into practice the obligations in the Terms and Conditions (Sections 3 and 11, Annex G) and in the Privacy Policy.
1.2.Who it applies to.This policy is binding on all 4Tify employees, contributors, subcontractors and external researchers (the “Personnel”). It covers all data, whatever its format (electronic, paper, screenshots, recordings) and wherever it is stored (the platform, workstations, testing environments, cloud services).
1.3.Principles.All activities observe the following principles:
- Necessity: we collect only what is needed for the service ordered and the authorised Scope.
- Minimisation: we demonstrate a vulnerability with the smallest possible amount of data (proof of concept, not extraction).
- Purpose limitation: a client's data is used exclusively for that client's services.
- Least access: each person sees only the data their task requires.
- Security by default: encryption, logging and strong authentication are mandatory, not optional.
- Limited retention: data is kept only for the periods set in Section 8, then destroyed verifiably.
- Traceability: every access to data classified “Confidential” or “Strictly confidential” is logged.
1.4.Relationship with other documents.If this policy conflicts with a contract or with a client's Authorisation Letter, the rule more protective of the data applies — unless the client, as controller, gives different written instructions that comply with the law.
2Data classification
Every piece of data is assigned one of the four levels below. Where there is doubt, the higher level applies.
| Level | Examples | Minimum rules |
|---|---|---|
| Public | The website, newsroom articles, published prices | No restrictions; publication is approved internally |
| Internal | Internal procedures, empty report templates, platform technical documentation | Personnel only; not sent outside the organisation without approval |
| Confidential | Client account and billing data, the asset inventory (ASM), remediated Findings, contracts, offers | Encryption in transit and at rest; role-based access; transmission only over the channels in Section 7 |
| Strictly confidential | Credentials and access received from the client, unremediated Findings, exploitation evidence, source code, secrets found, leaked data (Dark Web), personal data accessed during a pentest | All of the above, plus named access limited to the project team; MFA; mandatory logging; copying to personal devices or unapproved services is prohibited; verified destruction on expiry |
2.1.Marking.Reports and documents containing “Confidential” or “Strictly confidential” data carry the level marking on every page or in the file header.
2.2.Reclassification.A Finding moves from “Strictly confidential” to “Confidential” only once the client confirms remediation and a retest validates it.
3Collection and minimisation, by service
No data is collected before the Targets are validated and, where applicable, before the Authorisation Letter is signed.
| Service | What is collected | What is prohibited | Minimisation rule |
|---|---|---|---|
| Vulnerability scanning | Scanner results, banners, versions, relevant HTTP responses | Downloading application content beyond proof of the vulnerability | Only the request/response proving the Finding is kept |
| Pentest | Exploitation evidence, screenshots, test logs | Extracting databases, bulk reading of emails or files, unauthorised persistence | At most 5–10 records as a masked sample; the rest described only |
| AI code analysis | A working copy of the code, SAST/SCA results, relevant excerpts | Sending code to unapproved AI tools; keeping the code after the analysis | Only the minimal excerpt in the Report, with secrets masked |
| Deep/Dark Web | The exposure metadata: source, date, type of data, the identifier affected | Buying the data, downloading leaked archives in full, interacting with malicious actors | Passwords only as a hash or the first/last characters; raw archives are not stored |
| Attack Surface | The asset inventory, DNS, certificates, ports, technologies | Active testing of assets the client has not confirmed | Third-party assets identified are excluded and deleted |
| Bug Hunting | Researchers' reports and the associated evidence | Disclosure to third parties; researchers keeping data after triage | Researchers delete the evidence once a report is accepted and confirm this in writing |
3.1.Personal data accessed incidentally.If, during testing, Personnel reach personal data (in particular special categories or financial data), they stop at proof of access, do not copy the data, note only the type and estimated volume, and immediately inform the project coordinator, who notifies the client.
4Storage, encryption and segregation
4.1.Approved locations.Client data is stored only in: the 4Tify platform; the encrypted project workspace on approved infrastructure; the approved secrets vault (for credentials). Storage on personal devices, in email, in messaging apps or in unapproved cloud services is prohibited.
4.2.Location.Client data is stored in the European Economic Area. Storage outside the EEA takes place only with the safeguards set out in Annex G (G.11) to the Terms and Conditions, or at the client's written request.
4.3.Encryption.
- In transit: TLS 1.2 or above for every transfer; administrative access only over VPN or Zero Trust, with multi-factor authentication.
- At rest: encryption of volumes, databases and backups (AES-256 or equivalent).
- Keys: encryption keys are kept separately from the data, with restricted access and periodic rotation.
4.4.Segregation.Each client's data is logically separated in the platform and in a dedicated project workspace on the testing environments. Testing environments are not used for different clients at the same time without being cleaned between projects.
4.5.Workstations.The workstations used for testing have full-disk encryption, automatic screen locking, an up-to-date operating system and endpoint protection, and are not used for personal purposes.
4.6.Backups.Platform backups are encrypted, have restricted access, are tested periodically by restoring them, and observe the same retention periods through rotation (Section 8).
5Access control and personnel
5.1.Granting access.Access to a client's data is granted by name, only to members of the project team, by the project coordinator, and is revoked within 24 hours of the project ending or of the person leaving.
5.2.Authentication.All Personnel accounts with access to “Confidential” or “Strictly confidential” data use multi-factor authentication. Shared accounts are prohibited.
5.3.Review.Access rights are reviewed at least quarterly; access that is no longer needed is removed.
5.4.Logging.Access to “Strictly confidential” data, the export of Reports and changes to access rights are logged. The logs are protected against modification and kept for 12 months.
5.5.Personnel obligations.Before being granted access, every member of Personnel:
- signs a confidentiality undertaking that survives the end of the engagement;
- confirms in writing that they have read and comply with this policy;
- completes the initial and annual training on data protection and security.
5.6.External researchers and subcontractors.They are vetted before being involved, sign confidentiality and data processing agreements, and are given access only to the programme's Scope. At the end of the engagement they confirm in writing that the data has been deleted.
5.7.Breaches.Failure by Personnel to comply with this policy may lead to disciplinary sanctions or the end of the engagement, without excluding civil or criminal liability.
6Credentials, secrets found and testing evidence
6.1.Credentials received from the client.Test accounts, API keys and VPN access are received only over the channels in Section 7, never in clear text by email or chat. They are kept exclusively in the approved secrets vault, used only within the testing window, and deleted or handed back to the client for deactivation at the end. We recommend that clients use dedicated test accounts, with least privilege and automatic expiry.
6.2.Secrets discovered.Passwords, keys or tokens discovered in code, in systems or in leaks:
- are used only for minimal confirmation of validity, and only where the Authorisation Letter permits it;
- are reported to the client as a priority, with the value masked;
- are never kept in clear text in the Report, in logs or in notes.
6.3.Testing evidence.Screenshots, requests/responses and logs kept as evidence:
- are stored only in the encrypted project workspace;
- have personal data and secrets masked (redacted) before being included in the Report;
- are identified by project, date, author and the associated Finding;
- are kept separately from the Report, only for the period set in Section 8.
6.4.Artefacts in client systems.Any account, file, web shell or other artefact created in the client's systems is recorded in an artefact log, removed at the end of the testing, and the removal is confirmed in the Report. Where removal is not possible, the client is informed with exact instructions.
6.5.Chain of custody.For projects where the evidence may be used in legal proceedings or in incident response, a custody register is kept (who collected it, when, how, hash fingerprint, who accessed it) and non-altering collection procedures are applied.
7Delivering reports and secure communication
7.1.Primary channel.Reports and Findings are delivered through the 4Tify platform, with authenticated and logged access. This is the default method.
7.2.Alternative channels.Where the platform cannot be used, only the following are accepted: encrypted files (e.g. a PDF or an AES-256 encrypted archive), with the password sent over a separate channel (SMS, phone call); encrypted email (PGP / S/MIME); or a secure sharing link, with expiry and named access.
7.3.Prohibitions.Unremediated Findings, credentials and exploitation evidence are never sent in clear text by email, through public messaging apps, or via sharing services without access control.
7.4.Recipients.Reports are sent only to the people designated by the client in the Offer or in the Authorisation Letter. Sending them to anyone else requires the client's written consent.
7.5.Critical alerts.Critical vulnerabilities and signs of an active compromise are communicated by telephone to the emergency contact, followed by written confirmation over the secure channel, without exploitation details in clear text.
8Retention and destruction
8.1.Platform data follows your subscription.Everything held in the 4Tify platform — scan results, Findings, the asset inventory (ASM) and exposure alerts — is retained for the retention window of the client's active plan. Each plan states its own window, and a higher plan keeps history for longer; after a downgrade, the longer window is honoured for a grace period before the shorter one applies. When the subscription ends, the data is kept for a further 12 months so it can be exported, then deleted.
8.2.Everything else.Data held outside the platform follows the periods below.
| Type of data | Retention period | On expiry |
|---|---|---|
| Credentials and access received from the client | Until the end of the testing window | Deleted from the vault + the client is asked to deactivate them |
| Working copies of source code | At most 30 days from the end of the analysis | Secure deletion |
| Raw testing evidence (screenshots, logs, requests/responses) | 90 days from delivery of the final Report or of the retest | Secure deletion |
| Pentest and bug hunting Reports | The term of the contract + 12 months | Deletion or return, at the client's choice |
| Raw leaked data (Dark Web) | Not stored; only the exposure metadata is kept | — |
| Access and security logs | 12 months | Automatic deletion |
| Backups | A rotation cycle of at most 90 days | Overwritten by rotation |
| Billing data and contracts | The periods required by accounting and tax legislation | Destroyed on expiry |
8.3.Legal hold.These periods are suspended for data needed for litigation, an investigation or a request from the authorities, until the reason ceases.
8.4.Methods of destruction.Electronic data is deleted by methods that prevent recovery, following the principles of NIST SP 800-88 (cryptographic erasure, overwriting or physical destruction of the medium). Paper documents are shredded.
8.5.Confirmation.At the client's request, 4Tify issues written confirmation that its data has been deleted. The destruction of physical media that held “Strictly confidential” data is recorded in a register.
9Incidents, responsibilities and review
9.1.Internal reporting.Any suspicion of loss, unauthorised access, misdirected transmission or exposure of data is reported immediately, within 1 hour of discovery, to the security officer.
9.2.Response.The officer assesses the incident, orders containment measures and documents: what happened, which data is affected, what measures were taken. If a client's data is affected, the client is notified within 48 hours (Annex G, G.12). Where 4Tify is the controller, art. 33–34 GDPR apply (notification of the ANSPDCP within 72 hours and, where the risk is high, of the data subjects).
9.3.Register.All incidents, including those that are not notifiable, are recorded in an internal register, in accordance with art. 33(5) GDPR.
9.4.Responsibilities.
| Role | Responsibilities |
|---|---|
| Technical Lead | Approves the policy, allocates resources, decides on major incidents |
| Security and data protection officer | Maintains the policy, trains Personnel, handles incidents, reviews access |
| Project coordinator | Grants and revokes project access, checks retention and destruction at the end |
| Personnel and researchers | Comply with the policy, report incidents, flag risks |
9.5.Review.The policy is reviewed at least annually and whenever the services, the infrastructure or the applicable law change. Previous versions are archived.
9.6.Exceptions.Any departure from this policy is approved in writing by the Technical Lead, is limited in time, and is documented together with the risk accepted.
Questions about this document?
Write to us and a real person will answer — contract, data protection or scope.