What Data Grid32 Accesses
During a penetration test, our engineers may access data as a natural consequence of testing, for example demonstrating that a vulnerability allows access to a database or file share. We document findings as proof of exploitability but do not copy, retain, or transmit client data beyond what is necessary to demonstrate the finding.
Confidentiality and Data Handling
All Grid32 engagements are subject to mutual non-disclosure agreements. Testing notes, screenshots, and evidence are retained only for the duration of the engagement and report production, then securely destroyed. Deliverables are transmitted via encrypted channels.
Background-Checked, U.S.-Based Staff Only
Every Grid32 engineer undergoes a thorough background check before joining our team. All staff are U.S.-based direct employees — no offshore contractors, subcontractors, or third parties. Your data never leaves a controlled environment staffed by vetted professionals.
We Never Share Your Information
Grid32 does not share, sell, or disclose any client information, including the fact that you're a client, to any third party. Contact information is never used for marketing or solicitations.
Questions about how your data is handled?
We're happy to discuss our data handling practices, NDA terms, and security measures before you engage.
Contact Us →