Skip to content
Disqnect

Security controls

Review the safeguards in use and the scope of each control.

Last reviewed 25 September 2026

19 of 19 controls

Access and infrastructure

Database connections are limited to authorised network sources through an allowlist. Credentials are still required.

The application uses a dedicated database account with restricted permissions and no database-administration privileges.

Multi-factor authentication is enabled for Exoscale, Proton, GitHub, Neon, Netlify, Resend, PRO ISP and Cloudflare. This control covers administrative access to these services.

The transactional-email credential is restricted to sending for the configured authentication-email domain.

Administration of Exoscale, Neon and the business email organisation uses named accounts. Multi-factor authentication protects those accounts; application database access uses a separate service credential.

Product and communication

A code review of report and evidence access found checks for user and engagement permissions. Reports must be published before customers can read them. Portal membership and connector access are checked on the server for each request.

TLS is enforced for authentication-email delivery, and open/click tracking is disabled.

Customer onboarding records who approved the engagement scope and when. Later scope changes are archived so the authorisation history can be reviewed.

Customers can raise security concerns at security@disqnect.com and privacy requests at privacy@disqnect.com. The application also provides a way to request that testing stop; execution limits are described in the security overview.

Recovery and incident response

Seven-day history and daily snapshots with 14-day expiry are configured for the production database.

A database restoration test was completed on 20 September 2026, including checks of selected records and relationships. Full-service disaster recovery was outside the scope of this test.

Responsibilities, containment, customer communication and follow-up are documented. A guided incident scenario has been completed.

Data and privacy

Support correspondence has defined deletion deadlines, with completion recorded. Sensitive attachments are scheduled for deletion within 30 days of case closure and routine correspondence within 90 days, subject to earlier applicable obligations.

Incident-response templates have restricted access. Access to incident evidence and its retention are determined for each case.

Disqnect has a tested manual process for returning customer data and carrying out deletion across related records and supplier-held copies. At the end of service, the DPA provides a 30-day export window followed by seven days for active deletion. Backup expiry is handled separately under the agreed retention terms.

Assessment records and supporting evidence are retained for the agreed service period to support review, reproduction and remediation. The DPA sets out return, deletion and backup handling when the service ends.

Agreements and suppliers

The service agreement and DPA define the responsibilities for customer information. A mutual NDA is available for confidential material shared during scoping, testing and remediation.

The supplier schedule identifies the services involved in delivering Disqnect, the information they handle and their processing locations. Application hosting is distinguished from supporting email, website and development services.

The security overview explains how Disqnect Intelligence carries out authorised testing, how assessment information moves through the service, and the scope and stopping limits customers should understand.