⬢ Security Posture · Updated May 2026

How Penva Security Protects Your Data Our Own Security Posture

This page documents how Penva Security protects the data we handle on your behalf during penetration testing engagements. Australian jurisdiction throughout, end-to-end encryption, segregated tester environments, documented deletion at engagement closure.

Vendor security posture buyers can verify

A clear view of how Penva Security protects engagement data, evidence, credentials and reports inside Australian jurisdiction.
At-a-glance

Key trust signals

A compact summary of the most important details visitors need before taking action.
Quick Answer

How Penva Security handles your data

All Penva Security engagement data stays in Australian jurisdiction throughout the engagement and 90-day retention period. AES-256 encryption at rest, TLS 1.3 in transit, per-engagement encryption keys, hardware-backed multi-factor authentication for all access, and full audit logging of every data access.

Quick answer

How Penva Security handles your data

All Penva Security engagement data stays in Australian jurisdiction throughout the engagement and 90-day retention period. AES-256 encryption at rest, TLS 1.3 in transit, per-engagement encryption keys, hardware-backed multi-factor authentication for all access, and full audit logging of every data access.
Engagement teams are segregated at the data-access level – testers cannot access engagements they’re not assigned to. Every tester signs individual confidentiality undertakings that survive engagement and employment termination. Penva Security does not use third-country processors and does not offshore any phase of any engagement.
At engagement closure, data is retained for 90 days to support retest queries, then deleted with a documented attestation letter provided to the client. Clients can request immediate deletion at any time. Incident response is tested annually with 24-hour client notification commitment for any incident affecting client data.
Certified & aligned with

Trust Signals We Support

Recognised security practices, frameworks and methodologies used across Penva Security engagements.

CR CREST
CR
OS OSCP
OS
OW OWASP
OW
Four Pillars

The Four Pillars of Penva Security's Security Posture

The trust signals procurement teams most often want to confirm. Each is detailed in the control domains below.

AU

Australian Jurisdiction

All data, all infrastructure, all testers. No offshoring, ever.
ENC

Encrypted End-to-End

AES-256 at rest, TLS 1.3 in transit. Per-engagement key separation.
ACL

Least-Privilege Access

Need-to-know access controls. Engagement teams cannot access other engagements.
DEL

Deletion Attestations

Documented deletion at engagement closure. Attestation letter provided.
Six Control Domains

How Penva Security's Controls Are Structured

Six control domains covering jurisdiction, encryption, access controls, confidentiality framework, retention and deletion, and incident response.

01

Jurisdiction & Data Residency

AU Jurisdiction & Data Residency All testers Australian-based. No offshoring of any engagement phase – reconnaissance, testing, reporting, or analysis. All client data stored in Australian-based infrastructure. Findings, screenshots, exploitation evidence, credentials, and analysis remain in Australia. No third-country processing. Penva Security does not use any third-country processors for client engagement data. FIRB-sensitive arrangements accommodated. For Australian Government, Defence, or APRA-regulated clients requiring specific data-residency commitments.
02

Encryption & Key Management

ENC Encryption & Key Management AES-256 encryption at rest. All client data encrypted on storage with AES-256 minimum. TLS 1.3 for data in transit. All communications between Penva Security systems, between testers and clients, and between testers and target systems use TLS 1.3 minimum. Per-engagement encryption keys. Each client engagement has dedicated encryption keys; key compromise in one engagement does not affect another. Hardware-backed key storage. Master keys stored in hardware security modules (HSMs) with multi-party access requirements for sensitive operations.
03

Access Controls & Segregation

ACL Access Controls & Segregation Least-privilege access by default. Engagement teams have access only to the specific engagement data required for their work. Multi-factor authentication everywhere. All Penva Security systems require hardware-backed MFA (FIDO2 / hardware security keys) for tester and admin access. Engagement-team segregation. Tester teams working on Engagement A cannot access data from Engagement B, even within the same client organisation. Audit-logged access. Every access to client data is logged with tester identity, timestamp, and operation type. Logs retained for 7 years.
04

Confidentiality & Legal Framework

NDA Confidentiality & Legal Framework Mutual NDA before any technical exchange. Every engagement starts with a mutual NDA covering both Penva Security and the client. Individual tester confidentiality obligations. Every Penva Security tester has signed individual confidentiality undertakings; these survive engagement and employment termination. Standard MSA available, or work to your contract. We have a standard Master Service Agreement and can work to client-supplied MSAs or supplier agreements. No client identification without written permission. Penva Security does not name clients, publish case studies, or share testimonials without explicit written client permission.
05

Data Retention & Deletion

DEL Data Retention & Deletion Engagement data retained for 90 days post-closure. Findings reports, evidence, and engagement working files retained for 90 days after engagement closure to support retest and audit queries. Deletion attestation at retention end. Documented deletion of client engagement data with attestation letter provided to the client. Long-term retention only for audit-evidence requirements. Where regulatory frameworks (APRA, IRAP) require longer retention, Penva Security can extend retention with documented justification. Client right of deletion at any time. Clients can request immediate deletion at any point during or after the engagement, with attestation provided.
06

Incident Response & Continuity

INC Incident Response & Continuity Documented incident response process. Tested annually. Includes client-notification timelines aligned to Australian Privacy Act NDB requirements. Client notification within 24 hours. Any security incident potentially affecting client data is notified within 24 hours of detection. Business continuity planning. Disaster recovery and tester unavailability scenarios documented; backup tester teams available for critical engagements. Vulnerability disclosure for Penva Security systems. See our responsible disclosure policy for reporting vulnerabilities in Penva Security’s own systems.
FAQ

Security Posture — Common Questions

Direct answers to the questions procurement and security teams ask about Penva Security’s own security controls. Updated May 2026.

Where is client engagement data stored?
All client engagement data – findings, screenshots, exploitation evidence, credentials, analysis notes – is stored in Australian-based infrastructure throughout the engagement and retention period. We do not use any third-country processors for client engagement data. For clients with specific data-residency requirements (FIRB-sensitive arrangements, APRA-regulated entities, Government supply-chain vendors), we can provide supplementary documentation of our infrastructure topology under NDA.
How long is engagement data retained?
Engagement data is retained for 90 days after engagement closure to support retest queries and audit verification. After 90 days, data is deleted and a deletion attestation letter is provided to the client. Where regulatory frameworks (APRA tripartite review evidence, IRAP assessments) require longer retention, we can extend retention with documented justification. Clients can request immediate deletion at any time.
Do all Penva Security testers sign individual confidentiality undertakings?
Yes. Every Penva Security tester signs individual confidentiality undertakings covering all client data they may access during their engagement work. These obligations survive engagement closure and employment termination. The corporate NDA (between Penva Security and the client) is supplemented by these individual obligations, providing defence-in-depth confidentiality protection.
How does Penva Security handle access between engagement teams?
Engagement teams are segregated at the data-access level. The tester team working on Engagement A cannot access Engagement B data, even within the same client organisation, without explicit elevation by the engagement lead. All access is logged with tester identity, timestamp, and operation. This is enforced by per-engagement encryption keys plus role-based access control.
What's the incident response process if Penva Security is breached?
Penva Security has a documented incident response process, tested annually, aligned to Australian Privacy Act NDB (Notifiable Data Breach) requirements. Any security incident potentially affecting client data triggers client notification within 24 hours of detection. The notification includes incident scope, affected data categories, containment status, and recommended client actions. We maintain incident-response readiness as an operational priority – it’s a baseline expectation of being a pentest provider.
Can we audit Penva Security's security controls before engagement?
Yes – we provide a vendor security questionnaire response covering our control environment, and for larger engagements we accommodate supplier-led security reviews including evidence-of-control review under NDA. APRA-regulated clients and Government supply-chain procurement typically include this as a procurement step. We treat Penva Security’s security posture as something to be evidenced, not just claimed.
Does Penva Security have ISO 27001 certification?
Penva Security operates to ISO 27001-aligned information security practices but is not currently ISO 27001 certified at the corporate level. We can evidence specific control implementation against Annex A under NDA. For clients where corporate-level ISO certification is a procurement hard requirement, we’ll be honest about this during scoping and discuss alternative evidence paths (SOC 2-aligned controls, ASD Essential Eight maturity).
How does Penva Security handle credentials provided during engagements?
Credentials provided by clients for testing (test user accounts, service-account credentials, API keys) are treated as the highest-sensitivity data category. Stored encrypted, accessed only by the testers assigned to that engagement, used only for the documented test scope, and deleted with attestation at engagement closure. We never use client credentials outside the documented engagement scope or retain credential material beyond the 90-day retention window.
Next step

Need a Vendor Security Questionnaire Response?

Email [email protected] with your security questionnaire or supplier review request. Standard turnaround is 2-3 business days. We accommodate APRA, IRAP, and large-enterprise procurement security reviews.

Need a Vendor Security Questionnaire Response?

Email [email protected] with your security questionnaire or supplier review request. Standard turnaround is 2-3 business days. We accommodate APRA, IRAP, and large-enterprise procurement security reviews.