// security & trust

Evidence you can review. Controls you can verify.

Kotav Labs delivers authorised security assessments through a controlled engagement model. This page states what we protect, how delivery is governed and where our boundaries are.

Authorised testing

Testing starts only after scope, hosts, dates, rate limits, write permissions and Rules of Engagement are documented.

EU-hosted evidence

Assessment infrastructure and evidence are hosted in Germany. Subprocessors and any additional processing locations are disclosed per engagement.

Reviewed delivery

Material findings receive specialist review. Deliverables use verified evidence and an audit-suitable report, with PDF and SARIF where applicable.

Tenant separation

Tenant-scoped access, explicit roles and server-side authorisation protect customer records and operational actions.

Account security

HttpOnly sessions, rotating refresh tokens, TOTP MFA, one-time backup codes and encrypted secrets protect browser accounts.

Traceability

Assessment jobs, finding changes, retest requests, role changes and sensitive administrative actions produce attributable records.

// scope of service

Clear operational boundaries

Kotav does not present Argus Sentinel as 24/7 monitoring or incident response, and does not guarantee certification. Retention, subprocessors, testing permissions and deliverables are agreed for each engagement.

// due diligence

Security review material

A DPA, security FAQ, subprocessor disclosure, sample deliverables and technical answers are available during qualification under appropriate confidentiality terms.

Plano de Recuperação e Resiliência, República Portuguesa e Financiado pela União Europeia — NextGenerationEU