Trust & security

Security at ThreatReady

Last updated: 22 April 2026

We build a platform that measures how well security engineers think. The least we can do is take our own security seriously. This page is a factual, ongoing account of how we protect your data — not a marketing statement.

TLS 1.3 encryption Stored in India (Mumbai) Account isolation Audited regularly

On this page

  1. Infrastructure
  2. Encryption
  3. Access controls
  4. Application security
  5. Data handling
  6. Assessment integrity controls
  7. Incident response
  8. Compliance & attestations
  9. Landing page protections
  10. Responsible disclosure
  11. Security contact

1. Infrastructure

2. Encryption

3. Access controls

4. Application security

5. Data handling

6. Assessment integrity controls

These are specific to our product — they protect the scoring signal, which is the thing customers pay us for:

7. Incident response

8. Compliance & attestations

Transparency note We will not claim certifications we do not hold. If this page says something is "on roadmap," it is not yet completed. Customers with specific compliance requirements should confirm current status with [email protected] before subscribing.

11. Landing page protections

Even before signup, this marketing site (threatready.io) applies abuse protections so signup forms, the demo, and the auth modal cannot be used to attack our infrastructure or yours.

Real enforcement of rate limits, abuse detection, and account security happens server-side in the product backend. The protections on this page slow down casual abuse and reduce the load that reaches our APIs.

9. Responsible disclosure

We welcome good-faith security research. If you believe you have found a vulnerability in ThreatReady, please report it to us privately:

Safe harbor

We will not pursue legal action against researchers who:

Out of scope

We currently do not run a paid bug bounty program, but we credit reporters publicly in our security acknowledgements unless they prefer anonymity.

10. Security contact

For security disclosures: [email protected]
For business inquiries about security posture, SIG / CAIQ / security questionnaires: [email protected]