Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Assurance

Assurance and trust center

How to check our credentials, methods, and independence, how this website protects you, and how we handle what you send us.

Our trust statement

We separate advisory work from independent assessment where program rules require it. Credentials and organizational authorizations appear on this website only with their issuer, scope, status, and verification source, so buyers can validate them for themselves.

How to check what we claim

A statement about a credential, an authorization, a price, or a boundary is only useful if you can check it.

Individual credentials belong to the practitioner who holds them. An individual credential doesn't give Security Inspect any organization-level authorization.

How to verify a credential or authorization with the body that issued it

Check our work

Each page below explains one part of how we work, so you can judge it for yourself before you talk to us.

How this website protects you

  • Every page on this website is sent with security headers that stop other sites from framing it, stop browsers from guessing file types, limit the referrer information shared with other sites, and turn off browser features the site doesn't use, such as the camera, microphone, and location.
  • This website doesn't use advertising pixels, session replay, cross-site tracking, or third-party analytics.
  • We use first-party, cookieless measurement to maintain daily aggregate counts of page views and selected website actions. Analytics records don't contain IP addresses, device identifiers, form contents, search text, or individual browsing histories.
  • This website doesn't accept file uploads, and what you type into a form isn't put in page addresses, logs, or notification emails.

Security headers

An enforced Content Security Policy limits scripts, styles, images, fonts, forms, frames, plugins, and network connections to the sources this website needs. It blocks third-party framing, plugins, workers, and inline event handlers.

Security headers · site configuration

status readout

# Response header status for this websiteenforced  Content-Security-Policyenforced  X-Content-Type-Optionsenforced  X-Frame-Optionsenforced  Referrer-Policyenforced  Permissions-Policyenforced  Cross-Origin-Opener-Policyenforced  Cross-Origin-Resource-Policynot-sent  X-Powered-By
A compact readout of the table below: each header's status, then its name.
Response headers and their status on this website
HeaderWhat it doesStatus
Content-Security-PolicyScripts can come only from this site's own files or the page itself, never from another site, and styles, images, fonts, and connections are limited to this site. Other sites can't frame these pages, plugins are blocked, and forms and the page's base address can only point back to this site.Enforced
X-Content-Type-OptionsStops browsers from guessing a file's type, which closes off some ways of sneaking in scripts.Enforced
X-Frame-OptionsBlocks other sites from embedding these pages in a frame (clickjacking protection for older browsers).Enforced
Referrer-PolicyWhen you follow a link to another site, it learns only our domain, not the full address of the page you were on.Enforced
Permissions-PolicyTurns off browser features the site doesn't use: camera, microphone, location, payments, USB, serial, Bluetooth, and interest-based advertising interfaces.Enforced
Cross-Origin-Opener-PolicyKeeps this site's windows separate from pages on other sites that open them or that they open.Enforced
Cross-Origin-Resource-PolicyStops other sites from loading this site's files into their own pages.Enforced
X-Powered-ByRemoved, so responses don't advertise the web framework the site is built with.Not sent

How we handle what you send us

Keep sensitive information out of website forms

We don't collect sensitive evidence through this website. Please don't send passwords or other credentials, sensitive incident details, payment card data, health information, or controlled defense information through a website form. When an engagement needs sensitive evidence, we arrange a secure channel with you after initial contact.

Website and inquiry data is processed by the service providers named under Subprocessors on this page. Any location commitments for engagement data are defined in the applicable contract.

How long we keep it

Form entries before you press Send
Nothing you type in the contact form is sent to or stored on our servers until you press Send.
Spam and rejected submissions
Spam and rejected submissions are deleted after 30 days.
Inquiries that don't become engagements
Inquiries that don't become engagements are deleted 12 months after the last meaningful interaction.
Client records
Active client records follow the signed contract and applicable legal and accounting schedules.
Website and security logs
Raw website and security logs are kept for 90 days.
Analytics events
Daily aggregate analytics totals are kept for up to 14 months. We don't create identifiable analytics-event records.
Backups
Encrypted backups expire on a rolling basis within 35 days.
Opt-out requests
If you opt out, we keep only the minimum record needed to honor that request.
Legal holds
Legal holds and documented statutory obligations override routine deletion.

Read the privacy notice for your rights and how to make a request

Policies and reports

Subprocessors

A subprocessor is a company that handles website or inquiry data on our behalf, such as a hosting or email provider.

Vercel provides website hosting and content delivery. Supabase provides database and authentication services for the inquiry system and staff portal.

What this page doesn’t claim

The website practices above are how we run this site. They aren’t certifications or authorizations. Firm authorizations and individual credentials are different things, and the credentials page explains how to check either one with the body that issued it.

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Security Inspect isn't a managed SOC, an MDR provider, or a round-the-clock emergency-response provider. We don't offer ASV scanning, PCI forensic investigations, or P2PE, SSF, PIN, or 3DS assessments, and we don't perform CMMC certification assessments or HITRUST assessments.

How we keep readiness and assessment apart