Data Handling
For a penetration testing firm, the most important security question is simple: what happens to my data during an engagement? This page answers it in full.
Last updated: August 2026
Each client's engagement data is segregated. One engagement can never touch another's data.
We secure our own environment and the KLUE platform with the same rigor we apply when testing our clients' systems.
A mutual NDA is signed before any sensitive data is exchanged. Engagement-specific scoping is always documented.
During a security engagement, Shellvoide may receive or generate:
We work with public-sector and regulated clients and can accommodate additional handling requirements, including data residency constraints, on-premise or self-managed model deployments for sensitive workloads, and custom contractual terms.
For KLUE specifically, the platform is model-agnostic: for sensitive workloads, locally hosted or self-managed model deployments can be arranged so that data does not leave a controlled environment.
Contact us at disclosure@shellvoide.com or review our detailed policies.