Credentials & authorizations
How credentials and authorizations work, and how to check them
Assurance
We separate advisory work from independent assessment where program rules require it. Credentials and organizational authorizations appear on this website only with their issuer, scope, status, and verification source, so buyers can validate them for themselves.
A statement about a credential, an authorization, a price, or a boundary is only useful if you can check it.
Individual credentials belong to the practitioner who holds them. An individual credential doesn't give Security Inspect any organization-level authorization.
How to verify a credential or authorization with the body that issued it
Each page below explains one part of how we work, so you can judge it for yourself before you talk to us.
How credentials and authorizations work, and how to check them
How engagements are scoped, run, and reported
How advisory work stays separate from formal assessment
How to report a security issue in our website or systems
An enforced Content Security Policy limits scripts, styles, images, fonts, forms, frames, plugins, and network connections to the sources this website needs. It blocks third-party framing, plugins, workers, and inline event handlers.
# Response header status for this websiteenforced Content-Security-Policyenforced X-Content-Type-Optionsenforced X-Frame-Optionsenforced Referrer-Policyenforced Permissions-Policyenforced Cross-Origin-Opener-Policyenforced Cross-Origin-Resource-Policynot-sent X-Powered-By| Header | What it does | Status |
|---|---|---|
Content-Security-Policy | Scripts can come only from this site's own files or the page itself, never from another site, and styles, images, fonts, and connections are limited to this site. Other sites can't frame these pages, plugins are blocked, and forms and the page's base address can only point back to this site. | Enforced |
X-Content-Type-Options | Stops browsers from guessing a file's type, which closes off some ways of sneaking in scripts. | Enforced |
X-Frame-Options | Blocks other sites from embedding these pages in a frame (clickjacking protection for older browsers). | Enforced |
Referrer-Policy | When you follow a link to another site, it learns only our domain, not the full address of the page you were on. | Enforced |
Permissions-Policy | Turns off browser features the site doesn't use: camera, microphone, location, payments, USB, serial, Bluetooth, and interest-based advertising interfaces. | Enforced |
Cross-Origin-Opener-Policy | Keeps this site's windows separate from pages on other sites that open them or that they open. | Enforced |
Cross-Origin-Resource-Policy | Stops other sites from loading this site's files into their own pages. | Enforced |
X-Powered-By | Removed, so responses don't advertise the web framework the site is built with. | Not sent |
We don't collect sensitive evidence through this website. Please don't send passwords or other credentials, sensitive incident details, payment card data, health information, or controlled defense information through a website form. When an engagement needs sensitive evidence, we arrange a secure channel with you after initial contact.
Website and inquiry data is processed by the service providers named under Subprocessors on this page. Any location commitments for engagement data are defined in the applicable contract.
Read the privacy notice for your rights and how to make a request
Policy
How to report a security issue you find on this website.
Policy
What we collect, why, how long we keep it, and how to make a privacy request.
Policy
Our approach to accessibility and how to tell us about a barrier.
Policy
How this website uses cookies and browser storage, in the privacy notice.
Policy
The terms that apply when you use this website.
A subprocessor is a company that handles website or inquiry data on our behalf, such as a hosting or email provider.
Vercel provides website hosting and content delivery. Supabase provides database and authentication services for the inquiry system and staff portal.
The website practices above are how we run this site. They aren’t certifications or authorizations. Firm authorizations and individual credentials are different things, and the credentials page explains how to check either one with the body that issued it.
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Security Inspect isn't a managed SOC, an MDR provider, or a round-the-clock emergency-response provider. We don't offer ASV scanning, PCI forensic investigations, or P2PE, SSF, PIN, or 3DS assessments, and we don't perform CMMC certification assessments or HITRUST assessments.