Trust & data protection

How we protect your data

A security assessment means handing us the most sensitive material your company holds — unremediated vulnerabilities in products that are already in the field, along with firmware and internal evidence. Protecting it is not a side concern of this work; it is the work. Here is how we keep it safe, and how you can verify that for yourself.

Your data stays in the EU JURISDICTION

Client material is never placed on US-hosted code platforms or consumer cloud storage. Anything that leaves the workstation is encrypted first and stored only with EU-based infrastructure — so jurisdiction is never a question you have to raise in a procurement review.

Encrypted at every stage AT REST · IN TRANSIT

Working data lives on full-disk-encrypted volumes (LUKS2 / AES-256) that are mounted only during active work. Everything in transit uses modern TLS. Backups are encrypted before they leave the machine, so any storage provider only ever sees ciphertext.

Isolated per engagement NO SHARED KEYS

Every engagement gets its own dedicated encryption key, used for no other client and no other purpose. One client's material can never be exposed through another's, and access can be granted or removed one engagement at a time.

Provably destroyed CRYPTO-ERASURE

Because each engagement's data is encrypted under a single dedicated key, destroying that key renders the data permanently unrecoverable — including from any backup that can't be selectively edited.

At close, or on your instruction, you receive a signed Certificate of Data Destruction stating exactly what was destroyed, when, and how.

Authentic deliverables eIDAS SIGNED

Every report is issued as a digitally signed PDF (PAdES / eIDAS) with a qualified timestamp. You can confirm it genuinely came from us and hasn't been altered — and prove, later, exactly what was assessed and when.

Verifiable identity PUBLISHED KEYS

Our signing keys are published at a stable, signed URL with a plain verification script that needs nothing installed. The full history is public, so you can confirm our identity independently — not just take our word for it.

Don't take our word for it — check

Everything above is designed to be verified by you, with standard tools and no software to install. The three checks that matter:

Our identity

Our public keys are published at bit-shepherd.com/.well-known/keys.txt, signed by an offline root key. A one-command verification script (verify.sh / verify.ps1) is published alongside it.

A deliverable

Drag any report we send you into the European Commission's signature validator at ec.europa.eu · DSS validation. It checks our certificate against the EU Trusted List and confirms the document is intact.

Deletion

Your Certificate of Data Destruction lists the SHA-256 hashes of what was destroyed and is itself a signed document you can validate the same way.


The full policy

Written down, and aligned to the frameworks you use

The summary above is drawn from our Cryptographic Key Management Policy (KMP-001), which sets out key generation, protection, rotation, revocation, and destruction in full. It maps to the controls you're likely already audited against — ISO/IEC 27001:2022 (cryptography, deletion, backup), GDPR (Art. 32 protection, Art. 17 erasure, Art. 33–34 breach notification), and eIDAS — and holds itself to the standard of care the CRA sets for handling vulnerability information.

The complete policy is available to clients and prospective clients on request, under NDA. If your security team has a supplier questionnaire, send it over — most of the answers are already in this document. Ask for the policy →

Client material protected by design · deliverables independently verifiable · data provably destroyed on request

Discuss an engagement