Security, Privacy and Compliance at FireCompass.
Our certifications, AI Agents Safety and Governance, and the policies and practices that govern how we operate.
Security and privacy, governed as a system.
FireCompass is an Agentic AI platform for autonomous penetration testing and red teaming across Web, API and infrastructure. It discovers shadow assets and web applications, safely validates what is exploitable, and connects findings into multi-stage attack paths with near-zero false positives. It can operate autonomously or with expert-in-the-loop validation.
Because the platform runs offensive testing against customer systems, its information security, data privacy and AI governance are independently assessed and governed by the policies set out in this Trust Center.
Scope
The FireCompass SaaS penetration testing platform and the functions that build and operate it, including software engineering, SaaS DevOps, IT infrastructure, HR and administration, are in scope of our information security and privacy management systems.
The controls that protect customer data.
- ✓Certified to ISO/IEC 27001:2022 and ISO/IEC 27701:2019 by TÜV SÜD, and SOC 2 Type II compliant.
- ✓Customer data encrypted at rest and in transit.
- ✓Customer data logically separated between tenants.
- ✓Defined retention periods and secure disposal for every data type.
- ✓Hosted in cloud environments operated by providers certified to ISO 27001 and SOC 2.
- ✓Testing restricted to customer-approved scope, with stop controls and kill-switch mechanisms.
- ✓Human oversight across scoping, execution, validation and reporting.
- ✓Security program owned by a Chief Information Security Officer.
- ✓Regular security audits and penetration testing of our own systems.
- ✓Privacy Notice published.
Independently assessed and certified.
Independent assessments of our information security, privacy and operating controls. Certificates and reports are available through Request Access.
SOC 2 Type II
An independent auditor examined whether our controls are suitably designed and operated effectively over a full audit period, under AICPA standards.
ISO/IEC 27001:2022
The international standard for information security management systems. Certifies that we identify, manage and reduce information security risk through a defined, audited system.
ISO/IEC 27701:2019
The privacy extension to ISO/IEC 27001. Certifies our privacy information management system for handling personal data in the roles of both PII Controller and PII Processor.
These certifications govern a live offensive testing platform.
Documents for your security review.
Documents available to customers and prospective customers. Items marked NDA are shared with named recipients under a mutual non-disclosure agreement. Use Request Access to ask for any of them.
Audits and Certificates
- SOC 2 Type II ReportNDAIndependent service auditor's report, including the system description and tests of controls.
- ISO/IEC 27001:2022 CertificateNDACertificate of registration issued by TÜV SÜD for our information security management system.
- ISO/IEC 27701:2019 CertificateNDACertificate of registration issued by TÜV SÜD for our privacy information management system.
Policies
- Information Security PolicyNDAHow information is classified, handled and protected across the company.
- Data Protection PolicyNDAPrinciples, security measures, data subject rights and breach response for personal and business-sensitive data.
- Data Retention PolicyNDARetention periods by data type, storage security and secure disposal.
- Privacy NoticePublicHow we collect and use personal data on our website and services.
AI Governance
- AI Governance & Safe Autonomous Testing ArchitectureNDACustomer assurance note on scope control, guardrails, human oversight, auditability and data handling for AI-assisted testing.
- Customer Assurance SummaryNDAOne-page summary of FireCompass positions on AI use, autonomy, scope, exclusions, kill switch, auditability and data handling.
- Controlled audit discussionOn requestA session with your risk, compliance or security team covering the governance model, access controls, logging, evidence and human oversight.
How the program is operated.
Drawn from our Information Security, Data Protection and Data Retention policies. Owned by the Chief Information Security Officer and subject to periodic independent assessment.
Cloud and Infrastructure
- Certified cloud hostingSystems and data are hosted in secure cloud environments operated by providers certified to ISO 27001 and SOC 2.
- Encryption at rest and in transitAll data is encrypted using industry-standard protocols such as AES-256 and TLS 1.2 or 1.3.
- Tenant separationCustomer data is logically separated to prevent unauthorized access between tenants.
- Cloud access controlledAccess to cloud resources is controlled through identity and access management policies.
- Backups automatedAutomated backups are encrypted and maintained across resilient, multi-zone cloud infrastructure.
- Network segregationGroups of information services, users and systems are segregated on networks, with routing controls enforcing the access policy.
Access Control
- Role-based access enforcedAccess to customer data is restricted to authorized personnel under role-based access control and zero-trust principles.
- Unique authentication requiredEvery user has a unique user ID for personal use only, with a suitable authentication technique.
- Multi-factor authenticationSecure authentication mechanisms such as multi-factor authentication protect data from unauthorized access.
- Access reviewed periodicallyAccess restrictions and classifications are reviewed periodically against applicable access policies.
- Access removed on exitAccess rights are removed or adjusted on separation, termination or reassignment.
- Segregation of dutiesDuties are segregated so that no single individual can compromise an application, policy or process.
Operations and Development
- Change management enforcedChanges to production systems and source code are formally authorized, tested and documented.
- Environments separatedDevelopment, test and production facilities are separated to reduce the risk of unauthorized changes.
- Security tested before releaseNew systems and enhancements undergo formal testing, including testing of security requirements, before promotion to production.
- Vulnerabilities managedTechnical vulnerabilities are monitored, evaluated for exposure and addressed, with periodic risk assessments across systems and facilities.
- Penetration testing performedRegular security audits and penetration testing are conducted on our own systems.
- Activity loggedUser activities, exceptions and security events are logged, protected against tampering and retained for review.
People and Organization
- Pre-employment verificationIdentity, qualifications, employment history and references are verified in proportion to the sensitivity of the role.
- Confidentiality agreementsEmployees and third-party service providers are bound by confidentiality agreements.
- Security training deliveredStaff are briefed on security responsibilities before access to sensitive systems and complete data protection awareness training, with regular updates.
- Information classifiedInformation is classified and handled according to its value, sensitivity and criticality.
- Third parties managedService levels and security controls of third-party providers are monitored against contractual obligations, and cloud providers handling retained data undergo regular security assessments.
- Independent assessmentExternal audit consultants provide senior management with periodic independent assessment of the security program.
Resilience and Incident Response
- Business continuity plan establishedA business continuity plan is in place to ensure timely resumption of critical processes after disruption.
- Backups testedBackup arrangements are maintained and tested so critical information assets can be recovered.
- Incident procedures documentedReporting and escalation procedures ensure security events are communicated in time for corrective action.
- Breach response planSuspected breaches are reported to the CISO, investigated, contained, and notified to authorities and affected individuals within regulatory timeframes.
Data and Privacy
- Data protection principles appliedLawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability.
- Personal data minimizedCustomer personal data is not collected as a practice, except where required to complete a security assessment.
- Retention periods definedRetention periods are defined by data category, contractual requirements and applicable law. Security and audit logs are retained for at least 90 days, and backups are retained for 30 days by default.
- Secure deletionExpired data is permanently deleted or anonymized using methods aligned to NIST 800-88, including cryptographic erasure, with a record kept of each deletion.
- Early deletion honoredCustomer requests for early deletion are honored per contract and applicable regulation.
- Data subject rights supportedAccess, rectification, erasure, restriction, portability and objection, requested through the customer's authorized person.
The providers behind the platform.
FireCompass uses carefully selected service providers to deliver and support the platform. Providers used for a customer may vary by contracted hosting region, enabled features and integrations. Contractual data protection and security requirements apply to providers that process customer data.
Google Cloud Platform
Primary hosting, storage, networking, monitoring and managed platform services.
Amazon Web Services
Regional hosting and supporting cloud services where included in the contracted deployment.
Microsoft Azure
Used where required for regional deployment or customer-authorized integrations.
OpenAI
Used for approved platform functions subject to data minimization, redaction and model-use controls.
Anthropic
Used for approved platform functions subject to data minimization, redaction and model-use controls.
Customer-selected integrations
Ticketing, CI/CD, SIEM, SOAR and related integrations are enabled and controlled by the customer.
Autonomous testing is never unrestricted.
FireCompass does not treat autonomous testing as unrestricted activity. All testing is governed by defined scope boundaries, customer-approved targets, execution controls, exclusions, safety checks, rate limits, logging and operational oversight.
- ✓Authorized Scope OnlyTesting is performed only against customer-approved assets, applications, APIs, domains, IP ranges and environments. The customer and FireCompass define the authorized scope before testing begins, and assets outside it are excluded from testing.
- ✓Exclusion ControlsCustomers can define exclusions such as URLs, hostnames, IP addresses, CIDR ranges, sensitive endpoints and business-critical paths. Exclusions limit the blast radius of testing and prevent unintended activity.
- ✓Controlled AutonomyAI-assisted actions are constrained by platform guardrails, test policies, execution controls and customer-defined exclusions. Test policies govern which test types are permitted, rate limits, time windows and production safety constraints.
- ✓Execution GuardrailsThe platform applies scope validation, target validation, policy checks, rate limiting, test sequencing controls, execution monitoring, error handling, stop controls and kill-switch mechanisms.
- ✓Human AccountabilityHuman operators, customer stakeholders and FireCompass teams retain accountability for test authorization, scope definition, review, escalation and reporting. Findings can be reviewed before they are finalized.
- ✓Auditability by DesignTest activity, evidence, execution records, decision traces and reports are captured to support internal review and customer audit requirements. Where applicable, execution logs can be exported or reviewed.
- ✓Model Usage GovernanceModel usage is governed by use case, data sensitivity, customer scope, operational risk, required level of human review, and audit and reporting requirements. AI is not used to perform testing outside customer-approved scope.
- ✓Sensitive Data HandlingIf sensitive data is encountered during testing, controlled handling practices apply. The objective is to provide sufficient evidence of risk without unnecessarily exposing, extracting or retaining sensitive information.
We disclose governance controls, safety boundaries, audit evidence and customer assurance information, not proprietary implementation internals.
Trusted by the people who test the testers.
XBEN 104/104, Acuart 12/12 PoC-validated, and DVWA, fully autonomous with no human hints.
Featured in 30+ industry analyst reports. GigaOm Leader. On the technology maturity index five cycles running.
Security technologist and author, advisor to FireCompass. Trusted by Fortune 1000 enterprises.
Run a pentest against your own attack surface.
Start free, or connect with a FireCompass expert. In one session you will:
- ✓See shadow apps, subdomains, and exposed APIs discovered from your name alone.
- ✓Watch an agent validate a real finding with a working proof-of-concept exploit.
- ✓See the scope, exclusion and kill-switch controls that keep testing safe in production.
Governance is what makes autonomous testing safe to run in production.
Get the documents your review needs.
Certificates, audit reports, policies and completed security questionnaires are shared with named recipients under a mutual NDA. Tell us what your review needs.
- You send the request using this form.
- Our security team confirms the request and issues a mutual NDA for signature.
- Once signed by both parties, the documents are shared with the named recipients.
Changes to our certifications, policies and this Trust Center.
Certifications, controls and AI Agents Safety and Governance positions published for the first time.
Personal data is handled as described in our Privacy Notice. Commercial terms are set out in the Master Subscription Agreement.
Request our certificates and reports under NDA, or run your first trigger-driven web and API pentest. No install, results in about a day.
Free AI Pen Test →