Our own security posture, published
A security company's website is the first audit a buyer performs. Every control listed here is live on saktec.com right now, and every one of them can be checked from outside in under a minute with the public tool named beside it. We list what is in place — nothing aspirational.
What is in place
Every line below can be checked independently from outside, in a minute, with public tools. Last reviewed 15 September 2026.
| Control | What it means | How to check | Status |
|---|---|---|---|
| security.txt (RFC 9116) | A machine-readable security contact for researchers. | /.well-known/security.txt | In place |
| Vulnerability disclosure policy | How to report a vulnerability to us, and what we commit to in return. | Below | In place |
| No trackers | No analytics, advertising pixels or cookies on this website. | Browser developer tools | In place |
Independent scores (Qualys SSL Labs, Mozilla Observatory) will be published here, with the date measured, once this deployment has been scored.
Found a vulnerability in a SAK system? Tell us.
We welcome reports from security researchers. If you believe you have found a vulnerability in a system SAK operates, email security@saktec.com. Our contact details are also published in machine-readable form at /.well-known/security.txt.
In scope
- saktec.com and its subdomains
- Other domains and services that SAK itself operates
Out of scope
- Any client environment, even where you believe SAK is working with that client — never test a system you have not been authorised by its owner to test
- Denial-of-service testing, volumetric scanning, or anything that degrades service for others
- Social engineering of our staff, partners or clients, and physical testing
- Findings in third-party services we use (report those to the provider)
What we ask
- Give us a reasonable time to fix the issue before disclosing it publicly
- Access only the minimum data needed to demonstrate the issue, and do not keep, share or modify it
- Include enough detail for us to reproduce the issue
What we commit to
- An acknowledgement from a person within one business day
- Keeping you informed as we investigate and fix
- Not pursuing action against research carried out in good faith and within this policy
- Credit when the issue is fixed, if you would like it
We do not currently run a paid bug bounty.
Who this website relies on
The third parties involved in running this website and answering your enquiry. Client engagements have their own subprocessor schedule, provided in the proposal.
| Provider | What they do for this site | What they can see |
|---|---|---|
| Amazon Web Services | Hosting (S3) and content delivery (CloudFront) | Standard request data: IP address, browser, pages requested |
| Microsoft 365 | Our email, where enquiries are answered | What you send us |
| Google Fonts | Delivers the typefaces this site uses | Your IP address and browser, when the font files load |
No analytics, no advertising trackers and no cookies are used on this website.