Trust center

How we protect what you share with us.

You are trusting us with access to your systems. Here is exactly what we do with it, and how to reach us if something looks wrong.

What we access, and why

Only what the service needs.

Every permission we hold is listed in your dashboard with the reason we hold it. You can revoke any of it at any time, and we'll tell you what stops working if you do.

SystemWhat we accessWhy
Microsoft 365 or Google WorkspaceMail flow rules, sign-in and audit logs, security settings. Message content only when a message is quarantined or you ask us to investigate.Email security, identity protection and evidence for reports
Company devicesA security agent with local administrator rights. Process, network and file activity. No screenshots, keystrokes or personal files.Endpoint protection, isolation and patching
BackupsRead access to mailboxes, files, Teams and SharePoint; image access to servers you nominate.Nightly backups and restore tests
Business applicationsSign-in and admin audit logs only, through each application's official integration.Identity protection across the apps you rely on
NetworkFirewall and DNS logs where available. We do not inspect the content of your traffic.Detection of command-and-control and lateral movement

Your data

Encrypted, contained and deleted on schedule.

Security telemetry and backups are stored in dedicated environments in the United States. Access is limited to the team members assigned to your account, logged, and reviewed.

  • Encrypted in transit and at rest, with keys managed separately from the data
  • Access limited to the team members assigned to your account, with every access logged and reviewed
  • Multi-factor authentication and hardware security keys for every WindBreak employee
  • Background checks for everyone with access to customer environments
  • Security telemetry retained for 12 months; backups retained per your plan
  • Your data is returned to you and deleted within 30 days of cancellation
  • We never sell, share or use your data for anything other than protecting you

Monitored like a customer

Our own environment runs on the same detection and response we sell, with the same alerts and the same reports.

Tested by outsiders

Independent penetration tests of our platform and processes every year, with findings tracked to closure.

Least privilege

Access to customer environments is granted per engagement, expires automatically and requires a hardware key.

Documented controls

Our control set maps to CIS Controls v8 and SOC 2 criteria. Audit documentation is available to customers under NDA.

Our own security

We hold ourselves to the controls we run for you.

A security provider is a target. We design for that: separate environments for each customer, no standing admin access, and the assumption that any single control can fail.

Incident notification

If something happens to us, you hear it from us first.

If an incident at WindBreak affects your data or your service, we notify you within 24 hours of confirmation. The notice covers what happened, what we did, what we know about the impact on you, and what, if anything, you need to do. We update you until it's closed.

Subprocessors

A short list, shared at onboarding.

We use a small number of vendors to deliver the service, such as endpoint and email security platforms and cloud hosting. Each is contractually bound to protect your data to the same standard we are. The current list is provided to every customer at onboarding and whenever it changes, with 30 days' notice.

Request the current list

Email us and we'll send the subprocessor list, our data processing terms and our security overview.

Email security@windbreaksecurity.com

Responsible disclosure

Found a security issue? Tell us.

If you've found a vulnerability in our website, platform or systems, we want to hear about it. We'll acknowledge within two business days, keep you informed while we fix it, and credit you if you'd like. We won't take legal action against research done in good faith.

How to report

  • Email security@windbreaksecurity.com with steps to reproduce
  • Don't access, modify or keep customer data beyond what's needed to demonstrate the issue
  • Give us reasonable time to fix it before sharing publicly
  • Out of scope: denial of service, social engineering of our staff, and physical attacks

Questions about any of this?

Ask a security lead directly. We'd rather over-explain than leave you guessing.