Wiseep Information Security Policy
1. Purpose and Introduction
Wiseep provides online cybersecurity and vulnerability assessment services designed to help organizations identify, understand, assess, and remediate security weaknesses in their digital assets.
Wiseep supports multiple security assessment and scanning capabilities, which may include:
Red Team Scan
Wildcard Domain Scan
Single Domain Scan
Credentialed Scan
Mobile Application Scan
Desktop Application Scan
Static Code Scan / Code Review
Infrastructure Scan and
Other security assessment capabilities made available through the Wiseep platform.
Wiseep operates a hybrid security assessment model that may combine automated security testing, proprietary scanning technologies, third-party and open-source security tools, security intelligence, manual analysis, vulnerability research, and other technical assessment methodologies appropriate to the selected service and scope.
Wiseep may dynamically determine and apply the scanning engines, tools, techniques, payloads, discovery methods, and assessment procedures considered appropriate for the scope and service selected.
The purpose of this Information Security Policy is to describe the principles and controls Wiseep applies to protect the confidentiality, integrity, and availability of information processed in connection with its services.
This Policy is intended to describe Wiseep's security practices at a high level. It does not create or modify any contractual service level, warranty, guarantee, certification, or liability obligation unless expressly agreed in a separate written agreement.
2. Scope
This Policy applies to Wiseep's information systems, applications, infrastructure, personnel, processes, security operations, and third-party service providers involved in the delivery and operation of Wiseep services, to the extent applicable.
The Policy covers information processed through the Wiseep platform, including, where applicable:
Customer account information
Scan configurations and authorized scopes
Domain names, subdomains, IP addresses, URLs, applications, infrastructure information, and other customer-provided assets
Publicly available information and OSINT information
Vulnerability findings and security assessment results
Proof-of-concept information and technical evidence
Source code and related files submitted for code review
Mobile application packages and related materials
Desktop application binaries and related materials
Credentials or authentication material provided for authorized credential-based assessments
Network and service information
Logs, audit records, and operational information
Security intelligence and vulnerability information and
Other information required to provide the requested services.
The exact information processed may vary depending on the service selected by the customer.
3. Information Security Principles
Wiseep maintains security controls based on the following principles:
3.1. Confidentiality
Wiseep takes reasonable and appropriate technical and organizational measures to prevent unauthorized access, disclosure, or use of customer information.
Access to customer information is restricted based on legitimate business requirements, least privilege, and need-to-know principles.
Customer security assessment information is treated as confidential information and is not intentionally disclosed to unauthorized third parties except where permitted or required by applicable law, contractual obligations, or the security escalation provisions of this Policy and the applicable Terms of Service.
3.2. Integrity
Wiseep maintains controls designed to protect customer information, scan configurations, vulnerability findings, technical evidence, and other security assessment data against unauthorized modification, destruction, or manipulation.
Where appropriate, logging and audit mechanisms are used to support traceability, investigation, and integrity verification.
3.3. Availability
Wiseep maintains reasonable technical and organizational measures intended to support the availability and resilience of its services.
Wiseep does not guarantee uninterrupted or error-free availability unless expressly agreed otherwise in a separate written agreement.
Services may be temporarily unavailable or limited due to maintenance, upgrades, security measures, technical failures, third-party service interruptions, network conditions, or circumstances beyond Wiseep's reasonable control.
4. Customer Authorization and Scope Control
4.1. Authorized Assets
Customers are responsible for ensuring that they have the necessary ownership, authorization, consent, and legal rights to submit any asset or environment to Wiseep for security testing.
Customers must not submit or authorize Wiseep to scan:
Assets belonging to third parties without appropriate authorization
Systems for which the customer does not have testing permission
Infrastructure subject to contractual or legal restrictions that prohibit the requested testing
Any other asset that the customer is not legally authorized to test.
4.2. Scope Verification
Wiseep may require customers to demonstrate ownership or authorization over an asset before a scan is initiated.
Verification mechanisms may include, but are not limited to:
DNS-based verification
Domain verification
Configuration changes
Authentication
Technical verification
Administrative validation and
Other reasonable verification mechanisms.
Wiseep may refuse, suspend, restrict, modify, or terminate a scan where Wiseep reasonably believes that the customer does not have sufficient authorization to conduct the requested security assessment.
4.3. Customer Responsibility
The customer is solely responsible for the accuracy and legitimacy of the scope submitted to Wiseep.
The customer is also responsible for obtaining all necessary permissions from relevant owners, hosting providers, cloud providers, application owners, network operators, and other third parties where required.
4.4. Scope Expansion and Asset Discovery
Certain Wiseep services may involve identifying additional assets associated with an authorized organization or scope.
In particular, Red Team Scan may use information such as an organization's official name or other identifying information to discover publicly accessible assets associated with that organization.
Such discovery may include:
Domains
Subdomains
IP addresses
Websites
Publicly accessible systems
Network services
Exposed files
Publicly available technical information
Publicly exposed security information and
Other publicly available assets or information.
Where such discovery is part of the selected service, the customer acknowledges that the assessment may identify assets that were not explicitly supplied by the customer, subject to Wiseep's applicable authorization and assessment procedures.
5. Platform and Infrastructure Security
Wiseep applies reasonable technical and organizational safeguards to protect the infrastructure supporting its services.
Depending on the applicable environment and service, such controls may include:
Network security controls
Logical separation of customer data
Access control mechanisms
Authentication and authorization controls
Encryption
Security monitoring
Logging and audit mechanisms
Vulnerability management
Patch management
Backup and recovery mechanisms
Security hardening
Network segmentation
Isolation of security assessment environments where appropriate.
Wiseep periodically reviews its security controls based on changes in technology, identified risks, business requirements, security incidents, and applicable legal or contractual obligations.
6. Data Protection
6.1. Data Minimization
Wiseep seeks to process only information reasonably necessary to provide the requested service, operate the platform, maintain security, investigate vulnerabilities, and meet applicable legal or contractual obligations.
6.2. Encryption
Where appropriate to the nature and sensitivity of the information, Wiseep applies encryption or equivalent protective mechanisms to data transmitted between systems and to stored information.
Cryptographic mechanisms are selected based on industry-accepted security practices and the sensitivity of the information being protected.
6.3. Separation of Customer Data
Wiseep implements reasonable technical controls designed to prevent unauthorized access to information belonging to different customers.
6.4. Sensitive Information
Sensitive information, including credentials, source code, authentication tokens, vulnerability findings, proof-of-concept information, application binaries, security configurations, and other confidential technical information, is subject to appropriate access restrictions and security controls.
6.5. Security Assessment Evidence
Security assessment evidence may contain sensitive information discovered during testing, including:
Personal data
Authentication information
Session information
API keys
Credentials
Source code
Internal system information
Database information
Configuration information
Security weaknesses and
Other confidential technical information.
Such information is handled according to its sensitivity and the applicable security controls.
7. Service-Specific Security Controls
7.1. Red Team Scan
Red Team Scan may involve reconnaissance, publicly available information gathering, OSINT, asset discovery, validation of discovered systems, port and service identification, network-level security testing, web application testing, authentication and authorization testing, vulnerability identification, security misconfiguration checks, and other applicable security assessments.
Depending on the selected service and scope, Wiseep may perform a combination of automated, manual, and hybrid testing techniques.
Red Team Scan may identify publicly accessible assets without requiring the customer to provide a complete list of domains, IP addresses, or other technical scope information.
Wiseep may discover and assess assets associated with the customer's organization based on information provided by the customer and publicly available information.
Customers remain responsible for ensuring that they have the necessary authority to request and receive security assessment services relating to their organization and assets.
7.2. Wildcard Domain Scan
Wildcard scans may involve identifying subdomains and other assets falling within the customer's authorized wildcard scope.
Wiseep may perform automated discovery and security testing against discovered assets that fall within the authorized scope.
Depending on the selected service, Wiseep may perform:
Subdomain enumeration
Passive information gathering
OSINT checks
Data leakage checks
Port scanning
Service identification
URL discovery
Crawling
Fuzzing
Network-level testing
Web application security testing
Business logic testing
CVE detection and
Other applicable security checks.
Customers remain responsible for ensuring that the submitted wildcard scope is authorized and does not unintentionally include third-party assets.
7.3. Single Domain Scan
Single Domain Scans are performed against the specific domain or subdomain submitted and authorized by the customer.
Depending on the selected service, Wiseep may perform crawling, input analysis, web application security testing, authentication and authorization testing, business logic testing, network-level testing, vulnerability identification, and other applicable security checks.
Access to scan results is restricted through the Wiseep platform's applicable authentication and authorization mechanisms.
7.4. Credentialed Scan
Credentialed assessments may involve the use of customer-provided credentials to assess authenticated functionality and security controls.
Depending on the selected service, Wiseep may test:
Authentication
Authorization
Access control
Privilege separation
User-to-user authorization
Authenticated application functionality
Session management
Input validation
Business logic
Network-level controls and
Other applicable security controls.
Credentials and authentication materials provided for authorized assessments are treated as highly sensitive information.
Wiseep applies appropriate controls designed to:
Restrict access to authorized personnel and systems
Prevent unnecessary disclosure
Protect credentials during transmission and storage
Prevent credentials from being unnecessarily exposed in logs or reports
Remove or otherwise dispose of credentials in accordance with applicable retention requirements.
Customers are responsible for providing credentials with the minimum privileges reasonably necessary to perform the requested assessment.
Customers should revoke or rotate credentials after completion of testing where appropriate.
7.5. Mobile Application Scan
Mobile application assessments may involve customer-provided Android or iOS application packages, application metadata, configuration information, APIs, source code, libraries, and other materials required for the selected assessment.
Depending on the selected service, Wiseep may perform:
Static analysis
Dynamic analysis
Decompilation
Code review
Data storage testing
Device security testing
Third-party library and SDK analysis
Authentication testing
Authorization testing
Session management testing
Input validation testing
Business logic testing
Cryptographic analysis
Client-side security testing and
Other applicable security assessments.
Customer-provided application data is handled according to the security controls applicable to the sensitivity of the information.
7.6. Desktop Application Scan
Desktop Application Scan may involve customer-provided executable or application files, including applicable formats such as Windows executables or macOS application packages.
Depending on the selected service, Wiseep may perform:
Reverse engineering
Static analysis
Dynamic analysis
Runtime analysis
Memory analysis
Manual or automated code review
Fuzz testing
Dependency analysis
Third-party library analysis
Encryption testing
Obfuscation analysis
Malware or malicious-code analysis
Security configuration assessment and
Other applicable security assessments.
Desktop application files may contain proprietary source code, secrets, credentials, personal data, intellectual property, or other confidential information and will therefore be handled according to their sensitivity.
7.7. Static Code Scan / Code Review
Where Static Code Scan or Code Review services are provided, source code and related materials are treated as confidential customer information.
Depending on the selected service, Wiseep may assess:
User input handling
Authentication mechanisms
Authorization mechanisms
Input validation and sanitization
Sensitive information handling
Password and credential handling
API key and secret handling
Cryptographic implementation
Third-party libraries and dependencies
Known vulnerable dependencies
Business logic
Security configuration and
Other applicable security weaknesses.
Access to source code is restricted to authorized personnel or systems involved in providing the service.
Wiseep may use automated analysis, security tooling, manual review, AI-assisted analysis, or a combination of these approaches depending on the selected service.
7.8. Infrastructure Scan
Infrastructure assessments may involve:
IP addresses
Hosts
Networks
Subnets
Network services
Ports
Applications
Authentication services
Network protocols and
Other infrastructure components within the authorized scope.
Depending on the selected service, Wiseep may perform:
Port scanning
Service identification
Network-level vulnerability testing
Authentication testing
Default credential checks
Web application discovery
CVE checks
Configuration analysis
Outdated software checks and
Other applicable infrastructure security assessments.
Scanning tools and security intelligence sources may be updated periodically to address newly identified vulnerabilities, technologies, and threats.
8. Hybrid Security Assessment Methodology
Wiseep may combine multiple security assessment technologies and methodologies during a single assessment.
Depending on the service and scope, these may include:
Wiseep-developed scanning modules
Automated security scanners
Open-source security tools
Commercial security technologies
Security intelligence sources
Vulnerability databases
OSINT techniques
Automated crawling
Fuzzing
Manual analysis
Human security expertise
AI-assisted analysis and
Other security testing techniques.
Wiseep may determine which tools and methodologies are appropriate based on the characteristics of the target, the selected service, the available scope, the detected technologies, and other technical factors.
9. Scan Methodology and Limitations
Wiseep services are designed to identify security weaknesses using the techniques and scope applicable to the selected service.
However, no automated, manual, hybrid, AI-assisted, or penetration testing assessment can guarantee the identification of every security vulnerability, weakness, configuration issue, business logic flaw, or security risk in a target environment.
A scan result should not be interpreted as a guarantee that the assessed system is secure or free from vulnerabilities.
Unless expressly stated otherwise, Wiseep services do not constitute:
A guarantee that all vulnerabilities will be identified
A guarantee that a system is secure
A comprehensive compliance audit
A certification of compliance
A guarantee against future vulnerabilities or
A replacement for an organization's overall security program.
Free, trial, limited, or quick scan profiles may use a reduced testing scope, limited payloads, reduced testing depth, or other limitations and therefore may not provide the same level of coverage as a full assessment.
10. Scan Safety and Customer Responsibilities
Wiseep designs its scanning activities with reasonable measures intended to minimize unnecessary disruption.
Nevertheless, security testing inherently involves sending requests, payloads, probes, authentication attempts, file operations, fuzzing requests, or other technical traffic to target systems.
Certain assessments may also involve dynamic analysis, reverse engineering, runtime analysis, fuzzing, authentication testing, or other activities that may affect target systems or applications.
Customers are responsible for ensuring that their systems are appropriately prepared for the requested assessment.
Where appropriate, customers should maintain current backups, monitoring, recovery mechanisms, maintenance windows, and other safeguards before initiating security testing.
Wiseep shall not be responsible for disruptions, service degradation, data loss, business interruption, or other consequences arising from the customer's failure to properly prepare or authorize the target environment, except to the extent liability cannot lawfully be excluded or is expressly assumed under a separate written agreement.
11. Access Control
Wiseep applies access controls based on least privilege and need-to-know principles.
Depending on the relevant system and risk, access controls may include:
User authentication
Role-based access
Privileged access restrictions
Multi-factor authentication
Access logging
Periodic access review and
Removal or modification of access when personnel no longer require it.
Personnel are granted access to customer information only where such access is necessary for legitimate business, operational, security, support, investigation, or legal purposes.
12. Secure Development and Vulnerability Management
Wiseep maintains processes intended to identify and address vulnerabilities affecting its own applications, infrastructure, dependencies, scanning engines, and supporting systems.
Security considerations may be incorporated into:
Software development
Code review
Dependency management
Vulnerability scanning
Security testing
Patch management
Configuration management
Change management
Security monitoring.
Security vulnerabilities are prioritized for remediation based on factors such as severity, exploitability, exposure, business impact, available mitigations, and other relevant risk factors.
13. Logging and Monitoring
Wiseep maintains logging and monitoring capabilities appropriate to the security and operational requirements of its services.
Logs may be used for:
Security monitoring
Troubleshooting
Abuse detection
Incident investigation
Access auditing
Service reliability
Fraud prevention
Security analysis and
Compliance with applicable legal obligations.
Wiseep takes reasonable measures to prevent unauthorized access to logs and to avoid unnecessarily recording sensitive information such as plaintext credentials.
14. Security Incident Management
Wiseep maintains processes for identifying, assessing, containing, investigating, and remediating information security incidents affecting its systems or customer information.
Where an incident involving customer information is confirmed and notification is required under applicable law or contractual obligations, Wiseep will provide notification in accordance with those requirements.
Wiseep may also take immediate measures to protect its systems, customers, and other users, including suspending accounts, scans, credentials, integrations, or other functionality where reasonably necessary to contain a security incident or prevent further harm.
15. Security Vulnerability Escalation and Responsible Communication
15.1. Purpose
Wiseep's primary purpose is to help organizations identify and remediate security vulnerabilities.
Wiseep recognizes that certain vulnerabilities may present significant risks to the confidentiality, integrity, or availability of an organization's systems, information, customers, employees, or business operations.
15.2. Customer Notification
Vulnerability findings are normally made available through the Wiseep platform to the customer or authorized account users in accordance with the applicable service and commercial terms.
Depending on the selected service or pricing model, detailed vulnerability information, proof-of-concept information, technical evidence, or remediation information may be subject to applicable payment or service conditions.
15.3. Escalation of Significant Security Risks
Where Wiseep reasonably determines that a vulnerability presents a critical, material, or otherwise significant security risk, Wiseep may communicate or escalate the relevant security risk to appropriate representatives of the customer organization.
Depending on the circumstances, Wiseep may contact or communicate with:
Information Security personnel
Security Managers
CISO
CIO
CTO
Risk Management
Compliance personnel
Legal personnel
Executive Management
Senior Management or
Other individuals reasonably believed to have appropriate responsibility or authority for the relevant security risk.
15.4. Circumstances for Escalation
Such escalation may occur where Wiseep reasonably believes that:
A critical or material vulnerability is not being appropriately addressed
A significant security risk is being intentionally ignored
A material vulnerability is being suppressed or concealed
A significant security issue is being improperly dismissed
An individual without appropriate authority is preventing the issue from reaching responsible personnel
The customer representative has requested that a material vulnerability be deleted or suppressed
The customer representative has requested that Wiseep refrain from communicating a significant security risk to appropriate responsible personnel
The customer representative refuses or fails to sign a formal document requested by Wiseep regarding the deletion, suppression, or non-remediation of a significant security vulnerability, including confirmation of the customer's awareness and responsibility for the associated security risk
The continued existence of the vulnerability creates a material risk to the customer or other affected parties
Escalation is reasonably necessary to ensure that a significant security risk reaches personnel with appropriate responsibility or authority.
15.5. Independent Security Judgment
Wiseep's security assessments and vulnerability classifications are based on its technical assessment methodologies, security expertise, available evidence, and applicable vulnerability intelligence.
A customer representative's disagreement with a finding, refusal to purchase a vulnerability report, request to suppress a finding, or decision not to remediate a vulnerability does not necessarily require Wiseep to disregard its assessment of the security risk.
15.6. Scope of Escalation
Where Wiseep exercises its escalation rights, Wiseep will seek to communicate only information reasonably necessary to explain and assess the relevant security risk.
Wiseep will seek to avoid unnecessary disclosure of unrelated customer information, personal data, credentials, source code, or other confidential information.
However, where disclosure of additional information is reasonably necessary to demonstrate, validate, or communicate the security risk, Wiseep may disclose the relevant technical evidence to the extent reasonably necessary and legally permitted.
15.7. No Public Disclosure by Default
Security escalation under this Section does not constitute public disclosure.
Wiseep does not intend to publicly disclose customer vulnerabilities merely because it exercises its right to communicate a security risk internally within the relevant customer organization.
Any public disclosure will be subject to applicable law, contractual obligations, security considerations, and Wiseep's applicable policies.
15.8. Legal and Security Obligations
Nothing in this Policy prevents Wiseep from taking actions required to comply with applicable law, legal process, regulatory requirements, court orders, or legitimate security obligations.
16. Third-Party Service Providers
Wiseep may use third-party infrastructure, software, cloud services, hosting providers, payment processors, communication services, security services, analytics services, AI or machine-learning services, or other service providers necessary to operate and deliver its services.
Where third parties process customer information on Wiseep's behalf, Wiseep seeks to impose appropriate confidentiality, security, and data protection obligations consistent with the nature of the services provided and applicable requirements.
Wiseep may disclose information where required by law, court order, regulatory authority, or other legally binding process.
17. Data Retention and Deletion
Wiseep retains information only for as long as reasonably necessary for the purposes for which it was collected, to provide services, maintain security, comply with legal obligations, resolve disputes, enforce agreements, preserve security evidence, investigate incidents, or protect Wiseep's legitimate business interests.
Different categories of information may have different retention periods.
These may include:
Customer account information
Scan configurations
Scan results
Vulnerability evidence
Uploaded source code
Mobile application files
Desktop application files
Credentials and authentication material
Security logs
Billing records
Support communications and
Backup data.
Where appropriate and technically feasible, customer data may be deleted upon a valid customer request, subject to legal, security, fraud-prevention, dispute-resolution, accounting, contractual, evidentiary, backup, or other legitimate retention requirements.
Where Wiseep reasonably determines that security information must be retained for the purposes of security investigation, incident response, legal claims, contractual enforcement, or protection of Wiseep, its customers, or third parties, such information may be retained for the period reasonably necessary for those purposes.
Deletion from active systems does not necessarily mean immediate physical deletion from all backup or archival systems.
Backup copies may remain for a limited period until they are overwritten or securely deleted in accordance with Wiseep's applicable retention processes.
18. Privacy and Regulatory Requirements
Wiseep processes personal information in accordance with its Privacy Policy and applicable data protection laws.
Where applicable, Wiseep seeks to implement reasonable technical and organizational measures consistent with relevant data protection requirements.
References to particular laws, regulations, frameworks, or standards do not constitute a representation that Wiseep, its customers, or their environments are certified or compliant with those requirements unless Wiseep expressly states otherwise in a separate written statement or agreement.
Customers remain responsible for determining the regulatory and compliance requirements applicable to their own organizations, systems, data, and use of Wiseep services.
19. Security Awareness and Personnel
Personnel involved in operating or supporting Wiseep services may receive security and privacy awareness training appropriate to their responsibilities.
Personnel with access to confidential customer information are expected to follow applicable confidentiality, security, access control, and data handling requirements.
Violations of applicable security requirements may result in disciplinary or contractual action and, where appropriate, legal action.
20. Business Continuity and Resilience
Wiseep maintains reasonable measures intended to support the continuity and recovery of critical services.
Depending on the relevant system, such measures may include:
Backups
Redundancy
Recovery procedures
Monitoring
Failure detection
Incident response procedures and
Disaster recovery measures.
The availability of individual services may nevertheless be affected by planned maintenance, technical failures, security incidents, third-party service failures, telecommunications or network problems, or events outside Wiseep's reasonable control.
21. Acceptable Use and Security Protection
Wiseep may monitor and restrict activities that reasonably appear to constitute:
Abuse
Unauthorized access
Malicious activity
Attempts to circumvent security controls
Attacks against unauthorized third-party systems
Misuse of the Wiseep platform
Fraudulent activity or
Other activities that may create an unacceptable security or operational risk.
Wiseep reserves the right to suspend or terminate scans, accounts, credentials, integrations, or other service functionality where reasonably necessary to:
Protect Wiseep
Protect customers
Prevent unauthorized security testing
Prevent abuse
Comply with applicable law
Respond to security incidents
Protect third parties from potential harm.
Such action may be taken without prior notice where immediate action is reasonably necessary.
22. Intellectual Property and Security Data
Wiseep retains all rights in its platform, software, scanning engines, methodologies, algorithms, security technologies, vulnerability taxonomies, detection logic, security research, and other proprietary technology, except for rights expressly granted to customers under applicable agreements.
Customer ownership of customer-provided data is not transferred to Wiseep merely because such information is processed through the Wiseep platform.
However, Wiseep may process, analyze, store, reproduce, transform, and use customer-provided information to the extent reasonably necessary to:
Provide the requested services
Detect and validate vulnerabilities
Generate scan results
Perform security analysis
Maintain and secure the platform
Troubleshoot and improve service reliability
Prevent abuse and fraud
Investigate security incidents
Meet legal obligations and
Enforce applicable agreements.
Wiseep may also use appropriately aggregated, anonymized, or otherwise lawfully processed information for security research, statistical analysis, service improvement, vulnerability detection improvement, and development of its security technologies.
23. Vulnerability Findings and Security Results
Vulnerability findings, technical evidence, proof-of-concept material, remediation information, scan data, and related security information are considered confidential information.
Access to vulnerability details may depend on the service, scan type, selected pricing plan, payment status, customer account permissions, or other applicable commercial conditions.
Detection of a vulnerability does not constitute a warranty regarding the existence, exploitability, severity, business impact, or completeness of the finding.
Wiseep may use its own vulnerability classification, severity methodology, taxonomy, validation processes, and pricing rules in determining how findings are classified and presented.
Wiseep may re-evaluate, modify, merge, suppress, or otherwise update findings based on:
Additional technical evidence
Validation results
Duplicate detection
Changes in vulnerability intelligence
Changes in affected technologies
False-positive analysis
Security research or
Other relevant information.
Wiseep may determine that a vulnerability remains a security concern regardless of whether a customer elects to purchase the detailed vulnerability information.
24. Security Testing of Wiseep
Wiseep may conduct internal or external security assessments of its own systems and services.
Such assessments may include:
Vulnerability scanning
Penetration testing
Code review
Configuration review
Dependency analysis
Infrastructure testing
Application security testing and
Other security testing techniques.
Security testing may be performed by Wiseep personnel or qualified third parties where appropriate.
25. Continuous Improvement
Wiseep periodically evaluates its security controls and processes based on:
Emerging threats
Vulnerability intelligence
Security incidents
Changes in technology
Changes to services
Regulatory developments
Customer requirements
Security research and
Identified security risks.
Wiseep may modify its security controls, technologies, processes, scanning engines, detection methods, and procedures as necessary to maintain an appropriate security posture.
26. Policy Review and Governance
This Information Security Policy is reviewed periodically and may be updated when necessary to reflect changes in Wiseep's services, technology, security risks, legal requirements, or business operations.
The latest version of this Policy may be published through Wiseep's website or other appropriate communication channels.
Wiseep reserves the right to modify this Policy where reasonably necessary.
Unless expressly stated otherwise, updates to this Policy do not amend or override the terms of any separate written agreement between Wiseep and a customer.
27. Disclaimer and Limitation
This Information Security Policy describes Wiseep's general information security practices and controls.
It is not intended to constitute:
A guarantee of security
A guarantee that vulnerabilities will not exist
A guarantee that all vulnerabilities will be identified
A service-level agreement
A penetration testing certification
A regulatory compliance certification or
A representation that a customer's environment is secure or compliant.
Wiseep's services are provided subject to the applicable Terms of Service, service-specific terms, pricing terms, Privacy Policy, and any separately executed written agreement.
In the event of a conflict between this Policy and a separately executed written agreement, the applicable written agreement will control to the extent permitted by law.
28. Contact
Questions regarding this Information Security Policy or Wiseep's security practices may be directed to: support@wiseep.com

