Skip to main content
Trust

Autonomy is the claim. This is what bounds it

A platform that tests without being asked twice is only worth buying if you can say exactly what it may do, what it keeps, and where it runs. Four pages, each answering one of the four questions a security team actually sends over.

Four questions

Which page answers which

In the order a diligence questionnaire usually asks them, which is not the order a sales conversation would put them in.

What you came to find outPageWhat it covers
What does an engagement hold, and for how long? How we handle your data What is kept, why each item is kept, and the approval gate that keeps your customers’ records out of it by default.
Where does it run, and where does the data sit? Deployment and residency Nothing deployed for external and application testing; on-premise or your own cloud tenancy for internal. Four regions to choose between.
How far can it go without asking us? Approvals and audit trail The three actions that stop and wait for written approval, identical on every coverage class and in all three delivery models.
Can we file the output with our regulator? Compliance frameworks The nine frameworks findings are mapped to, and which delivery model produces a report that carries a signature.

What does an engagement hold, and for how long?

What it covers
What is kept, why each item is kept, and the approval gate that keeps your customers’ records out of it by default.

Where does it run, and where does the data sit?

What it covers
Nothing deployed for external and application testing; on-premise or your own cloud tenancy for internal. Four regions to choose between.

How far can it go without asking us?

What it covers
The three actions that stop and wait for written approval, identical on every coverage class and in all three delivery models.

Can we file the output with our regulator?

What it covers
The nine frameworks findings are mapped to, and which delivery model produces a report that carries a signature.

The instruments

Two, and both are the firm’s

B-52 is a product of Security Brigade rather than a separate company, and these are Security Brigade’s instruments covering how it delivers. The platform itself holds no certification of its own, and this site does not claim one.

InstrumentWhat it is, and whose it is
CERT-In empanelment Security Brigade’s, held since 2008. It is what makes a report signable in the two delivery models that put an empanelled auditor inside the engagement.
ISO 27001 certification Security Brigade’s, issued by a certification body. It describes how the firm runs, which is a different question from what a platform does.

CERT-In empanelment

What it is, and whose it is
Security Brigade’s, held since 2008. It is what makes a report signable in the two delivery models that put an empanelled auditor inside the engagement.

ISO 27001 certification

What it is, and whose it is
Security Brigade’s, issued by a certification body. It describes how the firm runs, which is a different question from what a platform does.

Frameworks

Nine frameworks, and one rule that governs all of them

Findings are mapped to the controls a framework names. Certification and attestation are issued by certification bodies and by auditors appointed for that purpose — separate work from testing, and not work we do. Every framework page cites the instrument it rests on and the date that instrument was read, because a compliance page cited at a stale version is worse than no page: its reader is the one person who checks.

9 of the nine have pages today. The framework index lists the full set and links the ones that are written.

Ask the awkward questions before the commercial ones

Where something your security team needs to know is not on these pages, say so. A gap named is worth more than a gap papered over, and it is the faster route to an answer.