Rules of engagement
Authorized targets, locations, systems, time windows, prohibited actions and escalation paths are recorded before operational work begins.
The Trust Center explains how VEXTRACE scopes authorized work, handles information, uses analytical automation and separates professional credentials from institutional certifications.
Controls are adapted to the engagement, data classification and applicable legal requirements.
Authorized targets, locations, systems, time windows, prohibited actions and escalation paths are recorded before operational work begins.
Collection is limited to the mission objective. Retention and deletion periods are defined by contract, legal obligation and evidentiary need.
Automation may accelerate classification, extraction and correlation, but material judgments and client-facing conclusions remain subject to human review.
Relevant sources, collection times, transformations and analytical notes are preserved to support verification and audit.
Case access should be limited by role, mission and need-to-know. Production client access requires authenticated and audited controls.
Security findings are handled through coordinated disclosure, client authorization and contractual communication channels.
The scope of every credential should be stated clearly.
Only certifications formally issued to the legal entity should be represented as company certifications. Scope and validity should be confirmed in the commercial proposal.
Professional certifications validate the knowledge or examination status of named practitioners and must not be presented as institutional certification.
References to MITRE ATT&CK, PTES, OWASP, NIST or ISO describe methodological alignment unless an active certification explicitly states otherwise.
Vextrace is a member of NVIDIA's Inception Program for Startups — a startup support program, not a technical certification. It is represented here as a partnership, distinct from the certifications above.
General privacy principles and data-subject communication channel.
Classification, transfer, retention, deletion and evidence controls.
Authorized, proportionate and legally grounded intelligence operations.
How to report a vulnerability in VEXTRACE-owned assets.
Published components and configuration dependencies.
General site and engagement principles pending contract-specific terms.