Permission first, in writing.
This page states how we conduct the Exposure Review, and how to reach us if you believe you have found a weakness in something we operate.
Nothing begins without authorization
The Exposure Review is performed only on systems a client owns or lawfully controls, and only under a signed Rules of Engagement and an authorization letter. Those documents fix what is in scope, what is expressly excluded, the window in which the work happens, and the person on each side who is accountable for it.
An acknowledgement on the application form is a condition of being considered. It is not permission to begin, and we do not treat it as such.
We do not take data
The review establishes who holds the domain, the mail, and the accounts, and what the organization publishes about itself. It does not require us to read client files, download records, or retain anything belonging to the organization or to the people it serves.
Where evidence must be recorded to support a finding, it is limited to what proves the finding and is returned or destroyed on request.
The scope is a ceiling, not a starting point
We do not test systems outside the written scope, and we do not expand scope mid-engagement because something adjacent looks interesting. If the review indicates that something outside scope deserves attention, we say so in the register and leave the decision with the organization.
This is a documentary review. It is not a penetration test, not a certification, and not a legal or insurance determination.
Findings are written to be acted on without us
Every finding names the party who can close it. Where the operator, a registrar, a mail provider, or an existing vendor can close it, the register says so and gives the steps. Most of what a review finds is closed this way, at little or no cost.
The report does not quote remediation. Read the standing on independence for why.
Reporting something to us
If you believe you have found a weakness in a system this practice operates, write to enquiries@theprivatestandard.com with enough detail to reproduce it. We will confirm receipt, tell you what we find, and tell you when it is closed.
We will not pursue anyone who reports in good faith, does not access or alter data belonging to others, and gives us a reasonable opportunity to close the issue before making it public. We ask for that opportunity. We do not make it a condition of being treated well.
Nothing on this page creates an obligation on a client beyond what the signed Rules of Engagement states, and nothing on it is legal advice.