Do you work with an NDA and how is my data protected?

Yes, DongIT works with a Non-Disclosure Agreement (NDA) by default before starting every pentest. Our own information security is ISO 27001 certified since 2025, so we can demonstrably prove how we protect your data.

NDA and legal aspects

Before we begin a pentest, an NDA is signed. This covers confidentiality of your application, test data, discovered vulnerabilities and the final report. We accept both our standard NDA and versions you provide, as long as they offer essential legal protection.

For certain sectors (healthcare, financial, government), we additionally sign a data processing agreement per GDPR, specifying the processing purpose, retention periods and incident notification obligation.

Data protection during the pentest

  • Encrypted storage. Test data and reports are stored encrypted on systems that pass ISO 27001 audits.
  • Minimal access. Only the involved pentesters and peer reviewers have access to your data. Access is logged and monitored.
  • Secure communication. Findings are shared through our Security Reporter platform. Sensitive data is not sent via regular email.
  • Physical security. Our work environment meets ISO 27001 requirements for physical access control and workplace security.

Retention and availability of your report

Pentest reports remain available in the Security Reporter platform so you and your team can always reference them for audits, compliance accountability and internal processes. You have ongoing access through your own account, long after the pentest is completed.

On request, we remove your reports from the system. This typically applies at the end of a customer relationship or due to specific retention requirements in your GDPR policy. Contact us and we will arrange secure deletion in accordance with NIST SP 800-88.

Incidents and notification obligation

In the event of a security incident on our side that could affect your data, we notify you within 24 hours per GDPR Article 33. Our incident response plan is tested annually as part of our ISO 27001 audit.

Contact us for our standard NDA, deletion requests or questions about data protection. Or view our pentest packages.