We build security software for regulated organisations, and a buyer's security team is right to ask how we hold ourselves to the same standard. This page answers with things you can verify: where your data goes with each product, how our own domain is configured, and who processes data on our behalf.
Checked on 26 September 2026. The domain lines are public and can be confirmed with
dig and a look at the response headers; anything else, ask us.
Where your data goes, product by product
Ibex
- Runs on a sealed appliance inside your perimeter. Nothing leaves it but the report, and it never opens a connection of its own: updates arrive as signed bundles imported by hand, verified against a key built into the appliance.
- The data drive is encrypted, and the appliance refuses to start from one that is not.
- Local accounts sign in with a mandatory second factor, and every action is written to an audit log whose entries are chained by hash, so a removed or altered entry shows.
Marmot
- The machine that holds your documents has no route to the internet. Only the second machine can reach a cloud model, and it holds no documents.
- Initial ingestion happens on your premises: your documents never come to us, and there is no inbound remote access.
- Every decision to let a request out is logged, and the log can be reconciled against your own firewall rather than taken on trust.
Goshawk
- Reads an immutable snapshot of your code. Nothing in your repository is changed, and no build is run.
- Git credentials, and any secrets an audit finds in the code, are encrypted at rest.
- Can run hybrid, with the scanning inside your perimeter and only the judgment in the cloud.
Buteo
- Scans only domains whose ownership has been proven, by a TXT record, a well-known file or an email challenge.
- Passive by design: it reads what your domain already publishes, tries no credentials, probes no paths and confirms no weakness by exploiting it.
- Hosted in the European Union, in Germany, with each customer's data isolated from the others' in the database itself.
Our own domain
The same checks Buteo runs, applied to deltacoders.com.
| Email authentication | SPF ends in -all, so mail from any server we have not listed fails, and DMARC is set to p=reject. |
|---|---|
| DNSSEC | The domain is signed, with its DS record published in .com. |
| Certificates | A CAA record allows only Let's Encrypt to issue certificates for the domain. |
| Transport and headers | HTTPS only, with HSTS preloaded, a content security policy, and framing, sniffing and referrer policies set on every response. |
| Disclosure | A security.txt that points to our vulnerability disclosure policy: reports acknowledged within five business days, and good-faith research welcome. |
Who processes data for us
The services this site relies on, what each one does and the basis for any transfer outside the European Economic Area. The detail is in the privacy policy.
| Service | What it does for us | Where, or on what basis |
|---|---|---|
| Hetzner | Hosting of this site | Germany |
| Workspace mailbox for contact and demo requests; Analytics on this site, loaded only after consent | EU-U.S. Data Privacy Framework and Standard Contractual Clauses | |
| SMTP2GO | Delivery of form submissions to our mailbox, through its EU endpoint | New Zealand, recognised as adequate |
| Cloudflare | Turnstile, the anti-spam check on our forms | EU-U.S. Data Privacy Framework and Standard Contractual Clauses |
| OpenStreetMap Foundation | The map on our About page | United Kingdom, recognised as adequate |

