Security
This page describes the security practices and principles that apply to ROO Secure (including the application or service identified as roosecure.com) operated by ROO Secure IT Solutions.
1. Our Approach
Security is foundational to everything we do. We combine offensive security thinking with practical engineering controls. All testing and assessment work is performed only under explicit written authorisation and defined scope.
2. Authorised Testing Only
- We never perform unsolicited or unscoped scanning or testing.
- Every engagement begins with clear rules of engagement and target definitions.
- Findings are human-validated before they are reported.
3. Data Protection
- Client data and assessment findings are treated as confidential.
- Access is limited to personnel with a need to know.
- Data is encrypted in transit (TLS) and protected at rest using industry-standard controls.
- We retain engagement data only as long as required by the contract or applicable law.
4. Infrastructure & Application Security
- Systems hosting ROO Secure are hardened and monitored.
- We apply least-privilege access, regular patching, and secure configuration baselines.
- Secrets and credentials are managed through controlled mechanisms and never hard-coded.
5. Use of Automation and AI
Automation and AI may assist with analysis, triage, and reporting. All security-relevant decisions that affect risk remain under human oversight and are subject to explicit scope and authorisation.
6. Vulnerability Reporting
If you believe you have discovered a security vulnerability in ROO Secure or related systems, please report it responsibly to legal@roosecure.com. We ask that you:
- Provide sufficient detail to reproduce the issue.
- Allow us reasonable time to investigate and remediate before public disclosure.
- Avoid accessing or modifying data that does not belong to you.
We will acknowledge receipt and work with you in good faith.
7. Third-Party Dependencies
We monitor and manage third-party components and cloud services used by ROO Secure. We expect our providers to maintain appropriate security standards.
8. Continuous Improvement
Security is an ongoing process. We regularly review controls, learn from engagements, and improve our practices. Frameworks such as NIST CSF, OWASP, and CIS Controls inform our approach where relevant.
9. Contact
For security-related questions or to report a vulnerability:
ROO Secure IT Solutions
Email: legal@roosecure.com