Cassorian Systems
Start a Project →
Home

Last updated 1 January 2026

Security Policy

Security is a constraint we design around, not a feature we add at the end. This policy describes our posture and how to report an issue.

Our approach

We build systems that run on our clients' own infrastructure, under their own access controls. That architecture is itself a security decision: it keeps sensitive data inside the client's perimeter rather than spread across third-party services.

Within each engagement, we build with audit trails, role-based access controls, data residency requirements, and compliance documentation as standard, not as add-ons.

Data handling

We minimise the data we hold. Client production data stays in the client's environment. Where we need access during an engagement, it is scoped, time-limited, and governed by the engagement agreement.

Reporting a vulnerability

If you believe you have found a security issue in our website or in a system we maintain, please tell us. Email info@cassorian.com with enough detail to reproduce the issue. We will acknowledge your report and keep you informed as we investigate.

We ask that you give us a reasonable opportunity to address an issue before disclosing it publicly, and that you do not access or modify data that is not yours while researching it.

Responsible disclosure

We treat good-faith security research as a contribution, not a threat. We will not pursue action against researchers who follow this policy and act in good faith.