SAK Get your exposure reportFree report
Trust

Our own security posture, published

A security company's website is the first audit a buyer performs. Every control listed here is live on saktec.com right now, and every one of them can be checked from outside in under a minute with the public tool named beside it. We list what is in place — nothing aspirational.

Posture

What is in place

Every line below can be checked independently from outside, in a minute, with public tools. Last reviewed 15 September 2026.

ControlWhat it meansHow to checkStatus
security.txt (RFC 9116)A machine-readable security contact for researchers./.well-known/security.txtIn place
Vulnerability disclosure policyHow to report a vulnerability to us, and what we commit to in return.BelowIn place
No trackersNo analytics, advertising pixels or cookies on this website.Browser developer toolsIn place

Independent scores (Qualys SSL Labs, Mozilla Observatory) will be published here, with the date measured, once this deployment has been scored.

Vulnerability disclosure

Found a vulnerability in a SAK system? Tell us.

We welcome reports from security researchers. If you believe you have found a vulnerability in a system SAK operates, email security@saktec.com. Our contact details are also published in machine-readable form at /.well-known/security.txt.

In scope

  • saktec.com and its subdomains
  • Other domains and services that SAK itself operates

Out of scope

  • Any client environment, even where you believe SAK is working with that client — never test a system you have not been authorised by its owner to test
  • Denial-of-service testing, volumetric scanning, or anything that degrades service for others
  • Social engineering of our staff, partners or clients, and physical testing
  • Findings in third-party services we use (report those to the provider)

What we ask

  • Give us a reasonable time to fix the issue before disclosing it publicly
  • Access only the minimum data needed to demonstrate the issue, and do not keep, share or modify it
  • Include enough detail for us to reproduce the issue

What we commit to

  • An acknowledgement from a person within one business day
  • Keeping you informed as we investigate and fix
  • Not pursuing action against research carried out in good faith and within this policy
  • Credit when the issue is fixed, if you would like it

We do not currently run a paid bug bounty.

Third parties

Who this website relies on

The third parties involved in running this website and answering your enquiry. Client engagements have their own subprocessor schedule, provided in the proposal.

ProviderWhat they do for this siteWhat they can see
Amazon Web ServicesHosting (S3) and content delivery (CloudFront)Standard request data: IP address, browser, pages requested
Microsoft 365Our email, where enquiries are answeredWhat you send us
Google FontsDelivers the typefaces this site usesYour IP address and browser, when the font files load

No analytics, no advertising trackers and no cookies are used on this website.