You are about to give us access.
Here is what happens to it.
A security firm holding your findings is itself a risk. This page answers the questions your vendor review will ask, without you having to send the form first.
The least we need, for the shortest time.
- Read-only access wherever the work can be done read-only.
- Named accounts for each person. Never a shared login.
- Access requested per engagement, scoped to the systems in the agreed scope.
- Time-bound, and revoked at handover rather than at some later tidy-up.
- Credentials you issue us are yours to rotate the day we finish.
Testing access is different from advisory access, and we ask for each separately. The penetration testing scope records exactly which access was granted and when it was withdrawn.
Where the evidence lives, and for how long.
- Held in Australia, under Sorami control, on encrypted storage.
- Reachable only by the people on your engagement.
- Retained for 90 days after the final report, then deleted.
- A shorter window, or immediate destruction, if your scope says so.
- Deletion confirmed in writing when it happens.
Evidence of a vulnerability in your systems is the most sensitive thing we will ever hold. It is treated as your data throughout, and the retention window is written into the scope rather than left to a default nobody read.
How the deliverable reaches you.
- Delivered through the channel named in your scope.
- Sent to named recipients you nominate, not to a generic inbox.
- Never posted to a public link or an unauthenticated download.
- Draft findings raised with you before the report is finalised.
- Urgent findings raised the day we confirm them, not at the end.
What we keep, and what goes.
- Working copies, tooling output and evidence are destroyed.
- Credentials are handed back for rotation and confirmed revoked.
- One copy of the final report is retained for our professional records.
- That copy goes too, on request, subject to any legal retention obligation.
- You get the deletion confirmation in writing either way.
What we are building, stated plainly.
Sorami is a new company. Some of what a mature supplier would show you does not exist yet, and listing it is more useful than implying otherwise.
- A documented information security management system. In progress.
- A published register of the tools that touch client data. Not yet published.
- An independent assessment of our own environment. Planned, not done.
- A formal, exercised incident response plan for Sorami itself. In draft.
Ask about any of these on the scoping call and you will get the current status rather than a roadmap slide. If one of them is a hard requirement for your procurement today, we are probably not the right firm yet.
The short list, in public.
- Not a CREST member company.
- Not ISO 27001 certified.
- Not SOC 2 audited.
- Not an ASD-endorsed or IRAP assessment provider.
- Not an AWS, Microsoft or Google partner.
The certifications listed on our about page are held by individuals. They are not company accreditations, and we do not present them as any. Where a requirement genuinely calls for an accredited company, we will tell you in writing that we do not meet it.
We prepare other organisations for these regimes through ISO 27001 readiness and SOC 2 readiness, which is a different thing from holding the certificate ourselves.
The clause your auditor will quote.
APRA-regulated entities carry an obligation about suppliers like us. Paragraph 28 of Prudential Standard CPS 234 requires an entity relying on a third party control testing to assess whether the nature and frequency of that testing is commensurate with paragraphs 27(a) to 27(e).
So expect to ask us about it, and expect us to answer. We would rather that happened during scoping than during your next review.
Tell us, and we will not come after you.
If you find a security problem in a Sorami system, email [email protected] with enough detail to reproduce it.
- We acknowledge within two business days.
- We will tell you what we found and when it is fixed.
- Good-faith research is welcome and we will not pursue you for it.
- Do not access other people data, and do not run denial of service.
There is no bounty. There is a straight answer and credit if you want it. Read our full responsible disclosure policy for testing boundaries and safe harbour terms.
Practical answers.
Where is our data held?
In Australia, under Sorami control, for the engagement and the retention window agreed in your scope. If your contract requires a specific jurisdiction or a shorter window, we write that into the scope instead.
Who can see our findings?
Only the people working on your engagement. Access is named rather than shared, and it is removed at handover along with every credential you issued us.
What happens to our data when the work ends?
We delete working copies and return or destroy evidence on the schedule in your scope. We confirm it in writing. The default is 90 days after final report unless you ask for sooner.
Will you complete our vendor security questionnaire?
Yes, at no charge, before you engage us. Send it with your scoping request. If a question has an answer we cannot give honestly today, we write that rather than leaving it blank.
Are you certified?
No. Sorami is not ISO 27001 certified, not SOC 2 audited, not a CREST member company and not an ASD or IRAP provider. The certifications on our about page are held by individuals, not by the company.
How do we report a vulnerability in your systems?
Email [email protected] with the detail and how to reproduce it. We acknowledge within two business days. We will not pursue anyone who reports in good faith and does not access other people data.
Send the questionnaire before you send the brief.
We complete vendor security questionnaires at no charge and before any engagement. It is the fastest way to find out whether we clear your bar.
Last reviewed: