What Data Grid32 Accesses

During a penetration test, our engineers may access data as a natural consequence of testing, for example demonstrating that a vulnerability allows access to a database or file share. We document findings as proof of exploitability but do not copy, retain, or transmit client data beyond what is necessary to demonstrate the finding.

Confidentiality and Data Handling

All Grid32 engagements are subject to mutual non-disclosure agreements. Testing notes, screenshots, and evidence are retained only for the duration of the engagement and report production, then securely destroyed. Deliverables are transmitted via encrypted channels.

Background-Checked, U.S.-Based Staff Only

Every Grid32 engineer undergoes a thorough background check before joining our team. All staff are U.S.-based direct employees, no offshore contractors, subcontractors, or third parties. Your data never leaves a controlled environment staffed by vetted professionals.

We Never Share Your Information

Grid32 does not share, sell, or disclose any client information, including the fact that you're a client, to any third party. Contact information is never used for marketing or solicitations.

What Happens to Your Data After the Engagement

Data protection does not end when testing does. Grid32 retains only what is needed to support your report and any required compliance documentation, stores it securely, and does not repurpose or share it. Evidence collected during testing is handled as confidential, and sensitive artifacts are disposed of according to the engagement agreement. If your compliance program requires specific retention or destruction terms, we align to them in writing before testing begins.

Frequently Asked Questions

How does Grid32 protect client data during a penetration test?

Grid32 accesses only what the scope requires, handles findings under strict confidentiality, uses background-checked U.S.-based engineers, stores engagement data securely, and never shares client information. Data handling is treated as part of the engagement, not an afterthought.

Who at Grid32 has access to my data during testing?

Only the assigned, background-checked, U.S.-based engineers working your engagement. Grid32 does not use offshore subcontractors, and access is limited to the systems and information within the agreed scope.

Does Grid32 share or sell client information?

No. Grid32 never shares or sells client information. Engagement data is kept confidential and secured, and reporting is delivered only to your authorized contacts.

Questions about how your data is handled?

We're happy to discuss our data handling practices, NDA terms, and security measures before you engage.

Contact Us →