How Penva Security Protects Your Data Our Own Security Posture
This page documents how Penva Security protects the data we handle on your behalf during penetration testing engagements. Australian jurisdiction throughout, end-to-end encryption, segregated tester environments, documented deletion at engagement closure.
Vendor security posture buyers can verify
- ✓ Australian Jurisdiction
- ✓ Encrypted End-to-End
- ✓ Deletion Attestations
Key trust signals
- Data jurisdiction: Australia only
- Encryption at rest: AES-256
- Encryption in transit: TLS 1.3
- Access auth: Hardware MFA (FIDO2)
- Engagement segregation: Per-key isolation
- Retention period: 90 days post-closure
- Incident notification: Within 24 hours
- Audit log retention: 7 years
How Penva Security handles your data
All Penva Security engagement data stays in Australian jurisdiction throughout the engagement and 90-day retention period. AES-256 encryption at rest, TLS 1.3 in transit, per-engagement encryption keys, hardware-backed multi-factor authentication for all access, and full audit logging of every data access.
How Penva Security handles your data
Trust Signals We Support
Recognised security practices, frameworks and methodologies used across Penva Security engagements.
The Four Pillars of Penva Security's Security Posture
The trust signals procurement teams most often want to confirm. Each is detailed in the control domains below.
Australian Jurisdiction
Encrypted End-to-End
Least-Privilege Access
Deletion Attestations
How Penva Security's Controls Are Structured
Six control domains covering jurisdiction, encryption, access controls, confidentiality framework, retention and deletion, and incident response.
Jurisdiction & Data Residency
- All testers Australian-based.
- All client data stored in Australian-based infrastructure.
- No third-country processing.
- FIRB-sensitive arrangements accommodated.
Encryption & Key Management
- AES-256 encryption at rest.
- TLS 1.3 for data in transit.
- Per-engagement encryption keys.
- Hardware-backed key storage.
Access Controls & Segregation
- Least-privilege access by default.
- Multi-factor authentication everywhere.
- Engagement-team segregation.
- Audit-logged access.
Confidentiality & Legal Framework
- Mutual NDA before any technical exchange.
- Individual tester confidentiality obligations.
- Standard MSA available, or work to your contract.
- No client identification without written permission.
Data Retention & Deletion
- Engagement data retained for 90 days post-closure.
- Deletion attestation at retention end.
- Long-term retention only for audit-evidence requirements.
- Client right of deletion at any time.
Incident Response & Continuity
- Documented incident response process.
- Client notification within 24 hours.
- Business continuity planning.
- Vulnerability disclosure for Penva Security systems.
Security Posture — Common Questions
Direct answers to the questions procurement and security teams ask about Penva Security’s own security controls. Updated May 2026.
Need a Vendor Security Questionnaire Response?
Email [email protected] with your security questionnaire or supplier review request. Standard turnaround is 2-3 business days. We accommodate APRA, IRAP, and large-enterprise procurement security reviews.