Trust

Security.

Last updated 9 September 2026

Applies to zorqly.com and the services described on it

Questions info@zorqly.com

01Reporting a vulnerability

If you have found a security issue in this site or in anything we operate, please tell us at info@zorqly.com with “Security” in the subject line.

Please include what you found, the steps to reproduce it, and its likely impact. If you need to send something sensitive, say so and we will arrange an encrypted channel.

StageWhat to expect
AcknowledgementWithin 2 business days
Initial assessmentWithin 5 business days
Progress updatesUntil the issue is closed

02Safe harbour for researchers

If you make a good-faith effort to follow this policy, we will not pursue legal action against you and will treat your research as authorised.

Good faith means: test only against assets we operate; do not access, modify or exfiltrate data that is not yours; do not degrade service or run denial-of-service or automated high-volume scans; do not use social engineering or physical intrusion; and give us a reasonable window to fix the issue before disclosing it publicly.

We do not currently run a paid bug bounty. We will credit you when an issue is fixed if you would like that.

03How this site is built

The site is a static page with one serverless endpoint for the contact form.

  • Served over HTTPS only, with HSTS.
  • Security headers set at the edge: X-Content-Type-Options, Referrer-Policy, X-Frame-Options and Permissions-Policy.
  • No database, no user accounts, no session cookies — so there is no stored credential or session to steal.
  • The contact endpoint validates and length-limits every field, strips control characters, and rejects anything that trips its spam trap.
  • Secrets live in environment variables at the host and are never present in the page source.

04Client data in engagements

  • Access is least-privilege and granted per engagement, not per person permanently.
  • Multi-factor authentication is required on every account that can reach client systems.
  • Data is encrypted in transit; at rest it is encrypted using the controls of the platform the client has chosen.
  • Production access is logged, and access is reviewed and revoked when an engagement or a role ends.
  • We work in the client’s environment wherever possible, so that data stays under their control and their retention rules.

05How AI agents are governed

Agentic systems fail differently from ordinary software, so they get their own controls. Every deployment we run includes:

  • Scoped tool access. An agent reaches only the systems and operations named in its scope, with credentials issued to it alone.
  • Approval gates. Irreversible actions, spend above an agreed threshold, and anything touching regulated data route to a named person with the context attached.
  • Spend and rate limits. Configured before go-live so a misbehaving agent is bounded rather than expensive.
  • Full audit trail. Every action, input and decision is logged for the client’s compliance team and for tuning.
  • Evaluation before production. Agents run against a test set and in shadow mode before they are given the ability to act.
  • A kill switch. Every agent can be stopped immediately without taking down the surrounding systems.

06Incident response

We maintain an incident process covering detection, containment, eradication, recovery and a written post-incident review.

Where we process data on a client’s behalf and become aware of a personal data breach, we notify that client without undue delay so they can meet their own regulatory deadlines. Notification timeframes for a specific engagement are set in its contract.

07Certifications and assurance

Current certifications and audit reports: [confirm: list any real certifications — ISO 27001, SOC 2, Cyber Essentials — or state plainly that none are currently held].

We would rather say nothing than imply an assurance we do not hold. If you need evidence for a vendor security review, ask us and we will send what we actually have.

08Contact

Security questions, vendor assessments and vulnerability reports: info@zorqly.com.