Wiseep Information Security Policy

1. Purpose and Introduction

Wiseep provides online cybersecurity and vulnerability assessment services designed to help organizations identify, understand, assess, and remediate security weaknesses in their digital assets.

Wiseep supports multiple security assessment and scanning capabilities, which may include:

  • Red Team Scan

  • Wildcard Domain Scan

  • Single Domain Scan

  • Credentialed Scan

  • Mobile Application Scan

  • Desktop Application Scan

  • Static Code Scan / Code Review

  • Infrastructure Scan and

  • Other security assessment capabilities made available through the Wiseep platform.

Wiseep operates a hybrid security assessment model that may combine automated security testing, proprietary scanning technologies, third-party and open-source security tools, security intelligence, manual analysis, vulnerability research, and other technical assessment methodologies appropriate to the selected service and scope.

Wiseep may dynamically determine and apply the scanning engines, tools, techniques, payloads, discovery methods, and assessment procedures considered appropriate for the scope and service selected.

The purpose of this Information Security Policy is to describe the principles and controls Wiseep applies to protect the confidentiality, integrity, and availability of information processed in connection with its services.

This Policy is intended to describe Wiseep's security practices at a high level. It does not create or modify any contractual service level, warranty, guarantee, certification, or liability obligation unless expressly agreed in a separate written agreement.

2. Scope

This Policy applies to Wiseep's information systems, applications, infrastructure, personnel, processes, security operations, and third-party service providers involved in the delivery and operation of Wiseep services, to the extent applicable.

The Policy covers information processed through the Wiseep platform, including, where applicable:

  • Customer account information

  • Scan configurations and authorized scopes

  • Domain names, subdomains, IP addresses, URLs, applications, infrastructure information, and other customer-provided assets

  • Publicly available information and OSINT information

  • Vulnerability findings and security assessment results

  • Proof-of-concept information and technical evidence

  • Source code and related files submitted for code review

  • Mobile application packages and related materials

  • Desktop application binaries and related materials

  • Credentials or authentication material provided for authorized credential-based assessments

  • Network and service information

  • Logs, audit records, and operational information

  • Security intelligence and vulnerability information and

  • Other information required to provide the requested services.

The exact information processed may vary depending on the service selected by the customer.

3. Information Security Principles

Wiseep maintains security controls based on the following principles:

3.1. Confidentiality

Wiseep takes reasonable and appropriate technical and organizational measures to prevent unauthorized access, disclosure, or use of customer information.

Access to customer information is restricted based on legitimate business requirements, least privilege, and need-to-know principles.

Customer security assessment information is treated as confidential information and is not intentionally disclosed to unauthorized third parties except where permitted or required by applicable law, contractual obligations, or the security escalation provisions of this Policy and the applicable Terms of Service.

3.2. Integrity

Wiseep maintains controls designed to protect customer information, scan configurations, vulnerability findings, technical evidence, and other security assessment data against unauthorized modification, destruction, or manipulation.

Where appropriate, logging and audit mechanisms are used to support traceability, investigation, and integrity verification.

3.3. Availability

Wiseep maintains reasonable technical and organizational measures intended to support the availability and resilience of its services.

Wiseep does not guarantee uninterrupted or error-free availability unless expressly agreed otherwise in a separate written agreement.

Services may be temporarily unavailable or limited due to maintenance, upgrades, security measures, technical failures, third-party service interruptions, network conditions, or circumstances beyond Wiseep's reasonable control.

4. Customer Authorization and Scope Control

4.1. Authorized Assets

Customers are responsible for ensuring that they have the necessary ownership, authorization, consent, and legal rights to submit any asset or environment to Wiseep for security testing.

Customers must not submit or authorize Wiseep to scan:

  • Assets belonging to third parties without appropriate authorization

  • Systems for which the customer does not have testing permission

  • Infrastructure subject to contractual or legal restrictions that prohibit the requested testing

  • Any other asset that the customer is not legally authorized to test.

4.2. Scope Verification

Wiseep may require customers to demonstrate ownership or authorization over an asset before a scan is initiated.

Verification mechanisms may include, but are not limited to:

  • DNS-based verification

  • Domain verification

  • Configuration changes

  • Authentication

  • Technical verification

  • Administrative validation and

  • Other reasonable verification mechanisms.

Wiseep may refuse, suspend, restrict, modify, or terminate a scan where Wiseep reasonably believes that the customer does not have sufficient authorization to conduct the requested security assessment.

4.3. Customer Responsibility

The customer is solely responsible for the accuracy and legitimacy of the scope submitted to Wiseep.

The customer is also responsible for obtaining all necessary permissions from relevant owners, hosting providers, cloud providers, application owners, network operators, and other third parties where required.

4.4. Scope Expansion and Asset Discovery

Certain Wiseep services may involve identifying additional assets associated with an authorized organization or scope.

In particular, Red Team Scan may use information such as an organization's official name or other identifying information to discover publicly accessible assets associated with that organization.

Such discovery may include:

  • Domains

  • Subdomains

  • IP addresses

  • Websites

  • Publicly accessible systems

  • Network services

  • Exposed files

  • Publicly available technical information

  • Publicly exposed security information and

  • Other publicly available assets or information.

Where such discovery is part of the selected service, the customer acknowledges that the assessment may identify assets that were not explicitly supplied by the customer, subject to Wiseep's applicable authorization and assessment procedures.

5. Platform and Infrastructure Security

Wiseep applies reasonable technical and organizational safeguards to protect the infrastructure supporting its services.

Depending on the applicable environment and service, such controls may include:

  • Network security controls

  • Logical separation of customer data

  • Access control mechanisms

  • Authentication and authorization controls

  • Encryption

  • Security monitoring

  • Logging and audit mechanisms

  • Vulnerability management

  • Patch management

  • Backup and recovery mechanisms

  • Security hardening

  • Network segmentation

  • Isolation of security assessment environments where appropriate.

Wiseep periodically reviews its security controls based on changes in technology, identified risks, business requirements, security incidents, and applicable legal or contractual obligations.

6. Data Protection

6.1. Data Minimization

Wiseep seeks to process only information reasonably necessary to provide the requested service, operate the platform, maintain security, investigate vulnerabilities, and meet applicable legal or contractual obligations.

6.2. Encryption

Where appropriate to the nature and sensitivity of the information, Wiseep applies encryption or equivalent protective mechanisms to data transmitted between systems and to stored information.

Cryptographic mechanisms are selected based on industry-accepted security practices and the sensitivity of the information being protected.

6.3. Separation of Customer Data

Wiseep implements reasonable technical controls designed to prevent unauthorized access to information belonging to different customers.

6.4. Sensitive Information

Sensitive information, including credentials, source code, authentication tokens, vulnerability findings, proof-of-concept information, application binaries, security configurations, and other confidential technical information, is subject to appropriate access restrictions and security controls.

6.5. Security Assessment Evidence

Security assessment evidence may contain sensitive information discovered during testing, including:

  • Personal data

  • Authentication information

  • Session information

  • API keys

  • Credentials

  • Source code

  • Internal system information

  • Database information

  • Configuration information

  • Security weaknesses and

  • Other confidential technical information.

Such information is handled according to its sensitivity and the applicable security controls.

7. Service-Specific Security Controls

7.1. Red Team Scan

Red Team Scan may involve reconnaissance, publicly available information gathering, OSINT, asset discovery, validation of discovered systems, port and service identification, network-level security testing, web application testing, authentication and authorization testing, vulnerability identification, security misconfiguration checks, and other applicable security assessments.

Depending on the selected service and scope, Wiseep may perform a combination of automated, manual, and hybrid testing techniques.

Red Team Scan may identify publicly accessible assets without requiring the customer to provide a complete list of domains, IP addresses, or other technical scope information.

Wiseep may discover and assess assets associated with the customer's organization based on information provided by the customer and publicly available information.

Customers remain responsible for ensuring that they have the necessary authority to request and receive security assessment services relating to their organization and assets.

7.2. Wildcard Domain Scan

Wildcard scans may involve identifying subdomains and other assets falling within the customer's authorized wildcard scope.

Wiseep may perform automated discovery and security testing against discovered assets that fall within the authorized scope.

Depending on the selected service, Wiseep may perform:

  • Subdomain enumeration

  • Passive information gathering

  • OSINT checks

  • Data leakage checks

  • Port scanning

  • Service identification

  • URL discovery

  • Crawling

  • Fuzzing

  • Network-level testing

  • Web application security testing

  • Business logic testing

  • CVE detection and

  • Other applicable security checks.

Customers remain responsible for ensuring that the submitted wildcard scope is authorized and does not unintentionally include third-party assets.

7.3. Single Domain Scan

Single Domain Scans are performed against the specific domain or subdomain submitted and authorized by the customer.

Depending on the selected service, Wiseep may perform crawling, input analysis, web application security testing, authentication and authorization testing, business logic testing, network-level testing, vulnerability identification, and other applicable security checks.

Access to scan results is restricted through the Wiseep platform's applicable authentication and authorization mechanisms.

7.4. Credentialed Scan

Credentialed assessments may involve the use of customer-provided credentials to assess authenticated functionality and security controls.

Depending on the selected service, Wiseep may test:

  • Authentication

  • Authorization

  • Access control

  • Privilege separation

  • User-to-user authorization

  • Authenticated application functionality

  • Session management

  • Input validation

  • Business logic

  • Network-level controls and

  • Other applicable security controls.

Credentials and authentication materials provided for authorized assessments are treated as highly sensitive information.

Wiseep applies appropriate controls designed to:

  • Restrict access to authorized personnel and systems

  • Prevent unnecessary disclosure

  • Protect credentials during transmission and storage

  • Prevent credentials from being unnecessarily exposed in logs or reports

  • Remove or otherwise dispose of credentials in accordance with applicable retention requirements.

Customers are responsible for providing credentials with the minimum privileges reasonably necessary to perform the requested assessment.

Customers should revoke or rotate credentials after completion of testing where appropriate.

7.5. Mobile Application Scan

Mobile application assessments may involve customer-provided Android or iOS application packages, application metadata, configuration information, APIs, source code, libraries, and other materials required for the selected assessment.

Depending on the selected service, Wiseep may perform:

  • Static analysis

  • Dynamic analysis

  • Decompilation

  • Code review

  • Data storage testing

  • Device security testing

  • Third-party library and SDK analysis

  • Authentication testing

  • Authorization testing

  • Session management testing

  • Input validation testing

  • Business logic testing

  • Cryptographic analysis

  • Client-side security testing and

  • Other applicable security assessments.

Customer-provided application data is handled according to the security controls applicable to the sensitivity of the information.

7.6. Desktop Application Scan

Desktop Application Scan may involve customer-provided executable or application files, including applicable formats such as Windows executables or macOS application packages.

Depending on the selected service, Wiseep may perform:

  • Reverse engineering

  • Static analysis

  • Dynamic analysis

  • Runtime analysis

  • Memory analysis

  • Manual or automated code review

  • Fuzz testing

  • Dependency analysis

  • Third-party library analysis

  • Encryption testing

  • Obfuscation analysis

  • Malware or malicious-code analysis

  • Security configuration assessment and

  • Other applicable security assessments.

Desktop application files may contain proprietary source code, secrets, credentials, personal data, intellectual property, or other confidential information and will therefore be handled according to their sensitivity.

7.7. Static Code Scan / Code Review

Where Static Code Scan or Code Review services are provided, source code and related materials are treated as confidential customer information.

Depending on the selected service, Wiseep may assess:

  • User input handling

  • Authentication mechanisms

  • Authorization mechanisms

  • Input validation and sanitization

  • Sensitive information handling

  • Password and credential handling

  • API key and secret handling

  • Cryptographic implementation

  • Third-party libraries and dependencies

  • Known vulnerable dependencies

  • Business logic

  • Security configuration and

  • Other applicable security weaknesses.

Access to source code is restricted to authorized personnel or systems involved in providing the service.

Wiseep may use automated analysis, security tooling, manual review, AI-assisted analysis, or a combination of these approaches depending on the selected service.

7.8. Infrastructure Scan

Infrastructure assessments may involve:

  • IP addresses

  • Hosts

  • Networks

  • Subnets

  • Network services

  • Ports

  • Applications

  • Authentication services

  • Network protocols and

  • Other infrastructure components within the authorized scope.

Depending on the selected service, Wiseep may perform:

  • Port scanning

  • Service identification

  • Network-level vulnerability testing

  • Authentication testing

  • Default credential checks

  • Web application discovery

  • CVE checks

  • Configuration analysis

  • Outdated software checks and

  • Other applicable infrastructure security assessments.

Scanning tools and security intelligence sources may be updated periodically to address newly identified vulnerabilities, technologies, and threats.

8. Hybrid Security Assessment Methodology

Wiseep may combine multiple security assessment technologies and methodologies during a single assessment.

Depending on the service and scope, these may include:

  • Wiseep-developed scanning modules

  • Automated security scanners

  • Open-source security tools

  • Commercial security technologies

  • Security intelligence sources

  • Vulnerability databases

  • OSINT techniques

  • Automated crawling

  • Fuzzing

  • Manual analysis

  • Human security expertise

  • AI-assisted analysis and

  • Other security testing techniques.

Wiseep may determine which tools and methodologies are appropriate based on the characteristics of the target, the selected service, the available scope, the detected technologies, and other technical factors.

9. Scan Methodology and Limitations

Wiseep services are designed to identify security weaknesses using the techniques and scope applicable to the selected service.

However, no automated, manual, hybrid, AI-assisted, or penetration testing assessment can guarantee the identification of every security vulnerability, weakness, configuration issue, business logic flaw, or security risk in a target environment.

A scan result should not be interpreted as a guarantee that the assessed system is secure or free from vulnerabilities.

Unless expressly stated otherwise, Wiseep services do not constitute:

  • A guarantee that all vulnerabilities will be identified

  • A guarantee that a system is secure

  • A comprehensive compliance audit

  • A certification of compliance

  • A guarantee against future vulnerabilities or

  • A replacement for an organization's overall security program.

Free, trial, limited, or quick scan profiles may use a reduced testing scope, limited payloads, reduced testing depth, or other limitations and therefore may not provide the same level of coverage as a full assessment.

10. Scan Safety and Customer Responsibilities

Wiseep designs its scanning activities with reasonable measures intended to minimize unnecessary disruption.

Nevertheless, security testing inherently involves sending requests, payloads, probes, authentication attempts, file operations, fuzzing requests, or other technical traffic to target systems.

Certain assessments may also involve dynamic analysis, reverse engineering, runtime analysis, fuzzing, authentication testing, or other activities that may affect target systems or applications.

Customers are responsible for ensuring that their systems are appropriately prepared for the requested assessment.

Where appropriate, customers should maintain current backups, monitoring, recovery mechanisms, maintenance windows, and other safeguards before initiating security testing.

Wiseep shall not be responsible for disruptions, service degradation, data loss, business interruption, or other consequences arising from the customer's failure to properly prepare or authorize the target environment, except to the extent liability cannot lawfully be excluded or is expressly assumed under a separate written agreement.

11. Access Control

Wiseep applies access controls based on least privilege and need-to-know principles.

Depending on the relevant system and risk, access controls may include:

  • User authentication

  • Role-based access

  • Privileged access restrictions

  • Multi-factor authentication

  • Access logging

  • Periodic access review and

  • Removal or modification of access when personnel no longer require it.

Personnel are granted access to customer information only where such access is necessary for legitimate business, operational, security, support, investigation, or legal purposes.

12. Secure Development and Vulnerability Management

Wiseep maintains processes intended to identify and address vulnerabilities affecting its own applications, infrastructure, dependencies, scanning engines, and supporting systems.

Security considerations may be incorporated into:

  • Software development

  • Code review

  • Dependency management

  • Vulnerability scanning

  • Security testing

  • Patch management

  • Configuration management

  • Change management

  • Security monitoring.

Security vulnerabilities are prioritized for remediation based on factors such as severity, exploitability, exposure, business impact, available mitigations, and other relevant risk factors.

13. Logging and Monitoring

Wiseep maintains logging and monitoring capabilities appropriate to the security and operational requirements of its services.

Logs may be used for:

  • Security monitoring

  • Troubleshooting

  • Abuse detection

  • Incident investigation

  • Access auditing

  • Service reliability

  • Fraud prevention

  • Security analysis and

  • Compliance with applicable legal obligations.

Wiseep takes reasonable measures to prevent unauthorized access to logs and to avoid unnecessarily recording sensitive information such as plaintext credentials.

14. Security Incident Management

Wiseep maintains processes for identifying, assessing, containing, investigating, and remediating information security incidents affecting its systems or customer information.

Where an incident involving customer information is confirmed and notification is required under applicable law or contractual obligations, Wiseep will provide notification in accordance with those requirements.

Wiseep may also take immediate measures to protect its systems, customers, and other users, including suspending accounts, scans, credentials, integrations, or other functionality where reasonably necessary to contain a security incident or prevent further harm.

15. Security Vulnerability Escalation and Responsible Communication

15.1. Purpose

Wiseep's primary purpose is to help organizations identify and remediate security vulnerabilities.

Wiseep recognizes that certain vulnerabilities may present significant risks to the confidentiality, integrity, or availability of an organization's systems, information, customers, employees, or business operations.

15.2. Customer Notification

Vulnerability findings are normally made available through the Wiseep platform to the customer or authorized account users in accordance with the applicable service and commercial terms.

Depending on the selected service or pricing model, detailed vulnerability information, proof-of-concept information, technical evidence, or remediation information may be subject to applicable payment or service conditions.

15.3. Escalation of Significant Security Risks

Where Wiseep reasonably determines that a vulnerability presents a critical, material, or otherwise significant security risk, Wiseep may communicate or escalate the relevant security risk to appropriate representatives of the customer organization.

Depending on the circumstances, Wiseep may contact or communicate with:

  • Information Security personnel

  • Security Managers

  • CISO

  • CIO

  • CTO

  • Risk Management

  • Compliance personnel

  • Legal personnel

  • Executive Management

  • Senior Management or

  • Other individuals reasonably believed to have appropriate responsibility or authority for the relevant security risk.

15.4. Circumstances for Escalation

Such escalation may occur where Wiseep reasonably believes that:

  • A critical or material vulnerability is not being appropriately addressed

  • A significant security risk is being intentionally ignored

  • A material vulnerability is being suppressed or concealed

  • A significant security issue is being improperly dismissed

  • An individual without appropriate authority is preventing the issue from reaching responsible personnel

  • The customer representative has requested that a material vulnerability be deleted or suppressed

  • The customer representative has requested that Wiseep refrain from communicating a significant security risk to appropriate responsible personnel

  • The customer representative refuses or fails to sign a formal document requested by Wiseep regarding the deletion, suppression, or non-remediation of a significant security vulnerability, including confirmation of the customer's awareness and responsibility for the associated security risk

  • The continued existence of the vulnerability creates a material risk to the customer or other affected parties

  • Escalation is reasonably necessary to ensure that a significant security risk reaches personnel with appropriate responsibility or authority.

15.5. Independent Security Judgment

Wiseep's security assessments and vulnerability classifications are based on its technical assessment methodologies, security expertise, available evidence, and applicable vulnerability intelligence.

A customer representative's disagreement with a finding, refusal to purchase a vulnerability report, request to suppress a finding, or decision not to remediate a vulnerability does not necessarily require Wiseep to disregard its assessment of the security risk.

15.6. Scope of Escalation

Where Wiseep exercises its escalation rights, Wiseep will seek to communicate only information reasonably necessary to explain and assess the relevant security risk.

Wiseep will seek to avoid unnecessary disclosure of unrelated customer information, personal data, credentials, source code, or other confidential information.

However, where disclosure of additional information is reasonably necessary to demonstrate, validate, or communicate the security risk, Wiseep may disclose the relevant technical evidence to the extent reasonably necessary and legally permitted.

15.7. No Public Disclosure by Default

Security escalation under this Section does not constitute public disclosure.

Wiseep does not intend to publicly disclose customer vulnerabilities merely because it exercises its right to communicate a security risk internally within the relevant customer organization.

Any public disclosure will be subject to applicable law, contractual obligations, security considerations, and Wiseep's applicable policies.

15.8. Legal and Security Obligations

Nothing in this Policy prevents Wiseep from taking actions required to comply with applicable law, legal process, regulatory requirements, court orders, or legitimate security obligations.

16. Third-Party Service Providers

Wiseep may use third-party infrastructure, software, cloud services, hosting providers, payment processors, communication services, security services, analytics services, AI or machine-learning services, or other service providers necessary to operate and deliver its services.

Where third parties process customer information on Wiseep's behalf, Wiseep seeks to impose appropriate confidentiality, security, and data protection obligations consistent with the nature of the services provided and applicable requirements.

Wiseep may disclose information where required by law, court order, regulatory authority, or other legally binding process.

17. Data Retention and Deletion

Wiseep retains information only for as long as reasonably necessary for the purposes for which it was collected, to provide services, maintain security, comply with legal obligations, resolve disputes, enforce agreements, preserve security evidence, investigate incidents, or protect Wiseep's legitimate business interests.

Different categories of information may have different retention periods.

These may include:

  • Customer account information

  • Scan configurations

  • Scan results

  • Vulnerability evidence

  • Uploaded source code

  • Mobile application files

  • Desktop application files

  • Credentials and authentication material

  • Security logs

  • Billing records

  • Support communications and

  • Backup data.

Where appropriate and technically feasible, customer data may be deleted upon a valid customer request, subject to legal, security, fraud-prevention, dispute-resolution, accounting, contractual, evidentiary, backup, or other legitimate retention requirements.

Where Wiseep reasonably determines that security information must be retained for the purposes of security investigation, incident response, legal claims, contractual enforcement, or protection of Wiseep, its customers, or third parties, such information may be retained for the period reasonably necessary for those purposes.

Deletion from active systems does not necessarily mean immediate physical deletion from all backup or archival systems.

Backup copies may remain for a limited period until they are overwritten or securely deleted in accordance with Wiseep's applicable retention processes.

18. Privacy and Regulatory Requirements

Wiseep processes personal information in accordance with its Privacy Policy and applicable data protection laws.

Where applicable, Wiseep seeks to implement reasonable technical and organizational measures consistent with relevant data protection requirements.

References to particular laws, regulations, frameworks, or standards do not constitute a representation that Wiseep, its customers, or their environments are certified or compliant with those requirements unless Wiseep expressly states otherwise in a separate written statement or agreement.

Customers remain responsible for determining the regulatory and compliance requirements applicable to their own organizations, systems, data, and use of Wiseep services.

19. Security Awareness and Personnel

Personnel involved in operating or supporting Wiseep services may receive security and privacy awareness training appropriate to their responsibilities.

Personnel with access to confidential customer information are expected to follow applicable confidentiality, security, access control, and data handling requirements.

Violations of applicable security requirements may result in disciplinary or contractual action and, where appropriate, legal action.

20. Business Continuity and Resilience

Wiseep maintains reasonable measures intended to support the continuity and recovery of critical services.

Depending on the relevant system, such measures may include:

  • Backups

  • Redundancy

  • Recovery procedures

  • Monitoring

  • Failure detection

  • Incident response procedures and

  • Disaster recovery measures.

The availability of individual services may nevertheless be affected by planned maintenance, technical failures, security incidents, third-party service failures, telecommunications or network problems, or events outside Wiseep's reasonable control.

21. Acceptable Use and Security Protection

Wiseep may monitor and restrict activities that reasonably appear to constitute:

  • Abuse

  • Unauthorized access

  • Malicious activity

  • Attempts to circumvent security controls

  • Attacks against unauthorized third-party systems

  • Misuse of the Wiseep platform

  • Fraudulent activity or

  • Other activities that may create an unacceptable security or operational risk.

Wiseep reserves the right to suspend or terminate scans, accounts, credentials, integrations, or other service functionality where reasonably necessary to:

  • Protect Wiseep

  • Protect customers

  • Prevent unauthorized security testing

  • Prevent abuse

  • Comply with applicable law

  • Respond to security incidents

  • Protect third parties from potential harm.

Such action may be taken without prior notice where immediate action is reasonably necessary.

22. Intellectual Property and Security Data

Wiseep retains all rights in its platform, software, scanning engines, methodologies, algorithms, security technologies, vulnerability taxonomies, detection logic, security research, and other proprietary technology, except for rights expressly granted to customers under applicable agreements.

Customer ownership of customer-provided data is not transferred to Wiseep merely because such information is processed through the Wiseep platform.

However, Wiseep may process, analyze, store, reproduce, transform, and use customer-provided information to the extent reasonably necessary to:

  • Provide the requested services

  • Detect and validate vulnerabilities

  • Generate scan results

  • Perform security analysis

  • Maintain and secure the platform

  • Troubleshoot and improve service reliability

  • Prevent abuse and fraud

  • Investigate security incidents

  • Meet legal obligations and

  • Enforce applicable agreements.

Wiseep may also use appropriately aggregated, anonymized, or otherwise lawfully processed information for security research, statistical analysis, service improvement, vulnerability detection improvement, and development of its security technologies.

23. Vulnerability Findings and Security Results

Vulnerability findings, technical evidence, proof-of-concept material, remediation information, scan data, and related security information are considered confidential information.

Access to vulnerability details may depend on the service, scan type, selected pricing plan, payment status, customer account permissions, or other applicable commercial conditions.

Detection of a vulnerability does not constitute a warranty regarding the existence, exploitability, severity, business impact, or completeness of the finding.

Wiseep may use its own vulnerability classification, severity methodology, taxonomy, validation processes, and pricing rules in determining how findings are classified and presented.

Wiseep may re-evaluate, modify, merge, suppress, or otherwise update findings based on:

  • Additional technical evidence

  • Validation results

  • Duplicate detection

  • Changes in vulnerability intelligence

  • Changes in affected technologies

  • False-positive analysis

  • Security research or

  • Other relevant information.

Wiseep may determine that a vulnerability remains a security concern regardless of whether a customer elects to purchase the detailed vulnerability information.

24. Security Testing of Wiseep

Wiseep may conduct internal or external security assessments of its own systems and services.

Such assessments may include:

  • Vulnerability scanning

  • Penetration testing

  • Code review

  • Configuration review

  • Dependency analysis

  • Infrastructure testing

  • Application security testing and

  • Other security testing techniques.

Security testing may be performed by Wiseep personnel or qualified third parties where appropriate.

25. Continuous Improvement

Wiseep periodically evaluates its security controls and processes based on:

  • Emerging threats

  • Vulnerability intelligence

  • Security incidents

  • Changes in technology

  • Changes to services

  • Regulatory developments

  • Customer requirements

  • Security research and

  • Identified security risks.

Wiseep may modify its security controls, technologies, processes, scanning engines, detection methods, and procedures as necessary to maintain an appropriate security posture.

26. Policy Review and Governance

This Information Security Policy is reviewed periodically and may be updated when necessary to reflect changes in Wiseep's services, technology, security risks, legal requirements, or business operations.

The latest version of this Policy may be published through Wiseep's website or other appropriate communication channels.

Wiseep reserves the right to modify this Policy where reasonably necessary.

Unless expressly stated otherwise, updates to this Policy do not amend or override the terms of any separate written agreement between Wiseep and a customer.

27. Disclaimer and Limitation

This Information Security Policy describes Wiseep's general information security practices and controls.

It is not intended to constitute:

  • A guarantee of security

  • A guarantee that vulnerabilities will not exist

  • A guarantee that all vulnerabilities will be identified

  • A service-level agreement

  • A penetration testing certification

  • A regulatory compliance certification or

  • A representation that a customer's environment is secure or compliant.

Wiseep's services are provided subject to the applicable Terms of Service, service-specific terms, pricing terms, Privacy Policy, and any separately executed written agreement.

In the event of a conflict between this Policy and a separately executed written agreement, the applicable written agreement will control to the extent permitted by law.

28. Contact

Questions regarding this Information Security Policy or Wiseep's security practices may be directed to: support@wiseep.com