During an engagement
NDA before scoping
We sign a non-disclosure agreement before you share anything about your environment.
Need-to-know access
Only the named consultants on your engagement can access its data, with MFA on every system they use.
Encrypted evidence
Findings, screenshots and credentials found during testing are stored encrypted and never in personal mailboxes or chat apps.
Secure report delivery
Reports are shared through encrypted channels with passwords sent separately.
Deletion on schedule
Engagement data is deleted on the schedule agreed in your contract, and we confirm it in writing on request.
Safe testing
Rules of engagement, agreed windows, no destructive payloads on production and a live contact throughout.
On this website
No tracking
No advertising cookies, pixels, third-party fonts or scripts. Your browser only talks to our server.
DPDP-compliant forms
Every form shows what we collect, why and for how long, with an unticked consent box and a separate marketing opt-in.
Encrypted at rest
Form submissions are encrypted with AES-256-GCM and deleted automatically after the retention period.
Hardened & monitored
Strict Content-Security-Policy, HSTS, a web application firewall with automatic bans, and passkey-protected admin access.
Responsible disclosure
Found a vulnerability in our systems? We welcome reports and won't pursue good-faith research.
Your rights
Access, correct or erase your data and withdraw consent at any time — handled by our Grievance Officer.
Everything in one place
Privacy notice
DPDP Act notice, in English and Hindi.
Your data rights
Access, correct, erase, withdraw consent.
Report a vulnerability
Our disclosure policy and safe harbour.
security.txt
RFC 9116 security contact.
security@dravincon.com
For vulnerability reports and security questions about our services.
privacy@dravincon.com
For questions or complaints about how we handle personal data.
Team certifications: CC · eJPT · CAP · CNSP · CCNP · ITIL 4 · SAFe · AWS CCP · CCMP. Security questionnaires (vendor assessments) answered on request under NDA.
Find out how an attacker sees you — before they do.
Book a free 30-minute scoping call with our security team. No sales script, just an honest view of your risk and what to do first.