PUBLIC · securepeak.comAS216096 · L-717869-S
SecurePeak
Trust centre

Everything a vendor review asks for, before it asks.

Certification scope and audit dates, the complete subprocessor list with data classification per party, the disclosure timetable we hold vendors to, and the channel for reporting weaknesses in our own estate. Dated, scoped, and specific enough to check.

security.txt · securepeak.com
$curl -s https://securepeak.com/.well-known/security.txt
 
Contact: mailto:security@securepeak.com
Encryption: openpgp4fpr:7E4C91A82FD06B35C1EE40B79D22F81A5C630EA4
Policy: https://securepeak.com/trust#disclosure
Preferred-Languages: en, ca, es
Expires: 2027-09-01T00:00:00Z
99.999%
Edge availability, trailing 12mo
0
Confirmed breaches to date
4h
Critical finding escalation
90d
Disclosure deadline, no exceptions
Audits

Certifications and audit reports

Reports are available under NDA through your engagement lead. We do not publish audit reports to the open web.

Subprocessors

Who else can touch your data

This list is complete. Clients under contract are notified 30 days before any addition, and may object.

We do not use analytics, advertising, session-replay or AI subprocessors. Evidence never leaves the estate listed above, and is never used to train a model.

Reporting to us

Found something in our systems?

Security contact
security@securepeak.com

Monitored continuously. We acknowledge within one business day and will not pursue anyone acting in good faith under this policy.

PGP fingerprint
7E4C 91A8 2FD0 6B35 C1EE 40B7 9D22 F81A 5C63 0EA4

Tell us and we will treat it exactly as we ask vendors to treat ours: acknowledged, scoped, fixed, and credited.

We do not run a paid bounty. We do publish the fix, name the reporter if they want it, and say what we changed.