NetInsightPro is a security product. We hold ourselves to the same bar we expect you to hold us to.
Cybersecurity framework alignment
NIST CSF 2.0
Identify, Protect, Detect, Respond, Recover — mapped across our infrastructure. See mapping table below.
OWASP ASVS Level 2
Web and API controls across authentication, session integrity, and input handling, verified against the ASVS Level 2 checklist.
UK GDPR / EU GDPR
Data minimization: client never ships traffic data to us. Accountability: DPA available on request.
ISO 27001 (audit in progress)
Controls implemented; certification audit in progress — target 2027.
SOC 2 Type II (audit in progress)
Audit in progress — target 2026. Security posture document available under NDA on request.
PCI DSS
Out of scope — all payment data handled by Stripe (PCI DSS Level 1 certified).
Built to be audited, not just trusted: we publish our security posture, run a responsible-disclosure programme, and don’t claim certifications we don’t yet hold. Where an audit is in progress, we say so.
NIST CSF 2.0 mapping
| Function | Our implementation |
|---|---|
| Identify | Asset inventory via cloud-native tooling; privileged access reviews quarterly; data-flow diagram maintained. |
| Protect | Encryption at rest across all data stores and secrets; multi-factor authentication; managed WAF with bot and abuse protection; signed request integrity; least-privilege access control. |
| Detect | Continuous threat detection with on-call escalation; audit trail; API access logging; breached-credential detection; alerting on anomalous activity. |
| Respond | Documented runbook (rollback, license revocation, data erasure); on-call escalation; admin audit trail on every write. |
| Recover | Point-in-time recovery across all data stores; versioned object storage with lifecycle retention; quarterly DR drill. |
Encryption
- In transit: TLS 1.2+ enforced (TLS 1.3 preferred), with HSTS
- At rest: Encrypted across all data stores, secrets, and object storage, with managed key rotation
- Request integrity: Layered request signing and replay protection on private endpoints
Infrastructure
- Regionally hosted in audited, compliance-aligned cloud infrastructure
- Global CDN with managed WAF, rate limiting, and bot/abuse protection
- Managed identity platform with multi-factor authentication support
- Serverless compute behind a managed API edge, with request throttling and detailed metrics
- Zero-trust: private resources require authenticated, signed requests
Client security
- Release signing: Android builds are cryptographically signed. Code-signing rollout is in progress for Windows, and macOS notarisation is in progress; the Download page carries current installer guidance.
- Update manifests are served over HTTPS and cryptographically signed; SHA-256 is verified before any installer runs
- On-device data never leaves your machine — our servers have no visibility into your network traffic
Responsible disclosure
If you find a vulnerability, email security@netinsightpro.com (PGP key on request). We aim to:
- Acknowledge within 2 business days
- Provide triage + severity within 5 business days
- Patch critical issues within 14 days
- Credit researchers (opt-in) on a public Hall of Fame
Out-of-scope: DoS/DDoS, social engineering, physical attacks.
Documents on request
- Data Processing Agreement (DPA)
- Sub-processor list
- Penetration-test summary
- Insurance certificate (cyber liability)
Email legal@netinsightpro.com.