A Policy We Never Compromise On

Every Grid32 engineer is a U.S.-based direct employee. We do not use offshore contractors, subcontractors, staffing agencies, or any third-party delivery model. Every person who accesses your network, tests your applications, or contacts your staff during a social engineering engagement is a full-time Grid32 team member who has passed a comprehensive background check.

Why This Matters for Security

Penetration testing requires privileged access to your most sensitive systems. During an internal network test, our engineers have domain-level access equivalent to a privileged insider. The integrity of everyone who touches your engagement is not a secondary concern. It is the foundation of the entire trust relationship.

Compliance Implications

For organizations subject to ITAR, CMMC, FedRAMP, or other government contracting requirements, the use of offshore personnel in security testing may create compliance violations. For financial institutions, healthcare organizations, and legal firms handling highly confidential data, the chain of custody over that data during a test matters.

Background Checks and Vetting

Every Grid32 engineer undergoes a thorough background check as a condition of employment. Many of our engineers come from backgrounds in government, defense, and critical infrastructure where security clearances are standard.

Why Offshore Testing Creates Compliance Risk

Using U.S.-based engineers is not only a trust preference, it is often a compliance requirement. Many financial, healthcare, and government contracts restrict where sensitive data may be accessed, and some prohibit foreign access outright. When a penetration test is performed by offshore staff, your most sensitive systems are exposed to exactly the access those contracts forbid. Grid32's U.S.-only, no-subcontractor policy keeps your engagement inside those boundaries and simplifies the answers on your vendor security questionnaires.

Frequently Asked Questions

Does Grid32 use only U.S.-based engineers?

Yes. Every Grid32 engagement is performed by U.S.-based, background-checked engineers, with no offshore subcontractors. This is a policy the firm does not compromise on, and it matters for both security and compliance.

Why does using U.S.-based testers matter?

Your most sensitive systems and data are exposed during testing, so who does the work matters. U.S.-based, vetted engineers reduce data-handling risk and satisfy compliance and contractual requirements that restrict where data can be accessed.

Are Grid32 engineers background-checked?

Yes. Grid32 engineers are background-checked and vetted before they work on client engagements, reflecting the trust required to test sensitive environments.

Know exactly who's on your network.

Grid32's team is vetted, certified, and U.S.-based, every time, without exception.

Get a Quote →