Skip to content
Circles Technologies

Trust

How we protect your data.

You are about to let a firm hold a list of every way into your institution. That list deserves better protection than the systems it describes. Below is specifically how we hold it — each point a control we run today, stated as a principle rather than a blueprint, because publishing our own topology would be its own finding.

In place today

Your findings do not sit next to our front door

The system holding your vulnerabilities is not reachable from the public internet. The portal you log into has no live connection to it; findings cross a deliberate, controlled step rather than an open link. If our public-facing systems were attacked, your findings are not where the attacker lands.

In place today

Isolation enforced by the database, not by hope

Each client’s data is separated at the database engine level, not merely by application logic. We do not trust our own code to remember the rule on every query — the database enforces it by default and denies access when in doubt. We verify it with tests that deliberately attempt to cross the boundary and confirm the database refuses.

In place today

Everything we do is on the record

Every change our team makes to your data is written to an audit trail you can read and we cannot alter or delete after the fact. The ability to modify or remove those entries is revoked at the database, not merely disallowed in the application. Nothing happens to your information off the books.

In place today

Backups encrypted, off-site, and actually rehearsed

Backups are encrypted before they leave the machine that made them, and the key to read them is held somewhere no server can reach. We have restored from an encrypted backup end to end and confirmed the data came back — rather than assuming a backup works because a file was produced.

In place today

We only touch what you authorize

We test only the systems you authorize in writing, and only within the window you agree. Every engagement begins with a signed authorization defining exactly what is in scope, and that authorization stays visible to you for the life of the relationship.

In place today

We run our own shop the way we tell you to run yours

Least-privilege access, network segmentation, encrypted secrets management and immutable audit logs — the controls we recommend to you, applied to ourselves. We would not sell what we do not practise.

In place today

Your data stays under our control, and access is revocable

Your findings sit on infrastructure we operate rather than scattered across a global platform, reached through a portal where access is auditable and revocable — unlike a report emailed around, which lives forever in a dozen inboxes. Infrastructure is currently EU-based; if your regulator requires residency elsewhere, raise it and we will discuss it per engagement rather than claim something we have not built.

What we are not claiming

We are not certified to ISO 27001. We do not claim continuous testing between engagements. We do not claim that our systems are technically incapable of acting outside a signed scope — that is a design we are building toward, not one we run today. A security firm caught overstating its own security does not recover, so we would rather this page be shorter and true.