PXL Security LTD, Sofia, Bulgaria Offensive security since 2014[email protected]

Trust & security

We hold ourselves to the standard we test for.

Security testing means handling sensitive information about your systems. Here's how we protect it, how we run securely, and how to report an issue to us.

How we handle your data

We collect only what an engagement needs, keep it for only as long as we need it, and handle every client's data under strict confidentiality.

  • NDAs and DPAs firstWe sign confidentiality and data-processing agreements before scoping details change hands.
  • Least dataWe request only the access and information a given engagement requires.
  • Encrypted in transit and at restReports and evidence are stored encrypted and shared over secure channels.
  • Defined retentionEngagement data is deleted on an agreed schedule after delivery. [Confirm your standard retention period.]
  • EU-basedPXL Security LTD is registered in Bulgaria; data handling is aligned to the GDPR.

How we run securely

The same practices we recommend to clients, applied to ourselves.

  • Hardened endpointsManaged, encrypted devices with MFA on every account.
  • Separation of client dataEngagement data is compartmentalised per client.
  • Least privilegeAccess to client material is limited to the testers on the engagement.
  • We eat our own cookingWe test our own tooling and infrastructure, and disclose what we find in others.

Responsible disclosure

If you believe you've found a security vulnerability in a PXL Security website or in software we publish, we want to hear from you.

How to report

Email [email protected] with a description of the issue, the affected asset, and steps to reproduce. Our security.txt has the machine-readable details. If you need to share sensitive details, ask us for a secure channel.

Our commitment

  • We'll acknowledge your report and keep you updated on our progress.
  • We won't pursue legal action for good-faith research that follows this policy.
  • We'll credit you for valid reports, if you'd like to be named.

Please do

  • Give us reasonable time to investigate and fix before any public disclosure.
  • Avoid privacy violations, data destruction, and service disruption.
  • Only test assets that belong to us — not our clients' systems.

This is a disclosure policy, not a paid bug-bounty programme.