Trust Center

How we handle your side of it

Data handling, access, evidence retention and disclosure, stated plainly so your security and legal reviewers can finish in one sitting.

In short

Rynexor works under written authorisation, limits access to named individuals for the duration of an engagement, encrypts evidence at rest, shares it only through channels the client controls, and destroys it on a schedule the client sets. We hold no security certifications at this time and do not claim any.

Practices

Authorisation
Nothing is tested without a signed scope naming the systems in and out of scope, the testing window and the escalation path. Systems that look adjacent are not touched. If we believe something outside scope is at material risk, we tell you. We do not expand scope on our own.
Access
Least privilege, named individuals, time-boxed to the engagement. Credentials issued to us are rotated at handover as a matter of course, not on request. We do not use shared accounts.
Evidence
Findings, screenshots and any captured data are encrypted at rest and transferred only through a channel you nominate. We do not email reports as unencrypted attachments, and we do not upload client evidence to third-party services.
Retention
You set the retention period in the engagement agreement. The default is 90 days after final report delivery, after which evidence is destroyed and a confirmation is issued. Reports themselves are kept only if you ask us to.
Data location
Engagement data is held on infrastructure in the EU or Türkiye. The specific region is confirmed per engagement and stated in the agreement, so it can be checked against your own obligations rather than assumed.
Subprocessors
We keep the list short deliberately. Where a third party is involved in processing client data, it is named in the engagement agreement before work begins, and you can object.
Incidents on our side
If we suffer an incident that could affect your data, you are told within 24 hours of us confirming it, before we know the full scope, not after. Waiting until the picture is complete is how notification becomes useless.
Disclosure
We publish a vulnerability disclosure policy for our own systems and expect to be held to it. Read the policy, or fetch security.txt.

Running a supplier review

04 steps

  1. Step 01

    Send us your questionnaire

    Whatever format your security team uses. We complete it in place. You do not get a marketing pack to translate yourself.

  2. Step 02

    Five working days

    That is our turnaround commitment on a completed questionnaire. If a question needs a document we do not yet hold, you get told which one on day one, not in week three.

  3. Step 03

    Data processing agreement

    Signed before any engagement begins, naming the data categories, the retention period you have chosen, the processing location and any subprocessor involved.

  4. Step 04

    A call with whoever needs one

    Your security lead, your DPO, your procurement team. We would rather answer directly than exchange six rounds of email through an account manager.

If your process requires a specific certification, raise it in the first conversation. We will tell you immediately whether we can meet it rather than discovering it three weeks in.

Questions reviewers ask

Does Rynexor hold security certifications?

No. Rynexor does not currently hold ISO 27001, SOC 2, or similar certifications and does not claim them. Practices are stated on the Trust Center so procurement can evaluate them on their own terms.

How do you disclose a vulnerability in Rynexor systems?

Follow the vulnerability disclosure policy at /security/. Reports are acknowledged within three working days and assessed within ten.

Who you deal with

Halil Ahmad

Founder · Istanbul

LinkedIn profile

Send it to your reviewers.

If something on this page does not answer what your security or legal team needs, tell us what is missing and we will write it down properly.

Start a brief