Monitored like a customer
Our own environment runs on the same detection and response we sell, with the same alerts and the same reports.
Trust center
You are trusting us with access to your systems. Here is exactly what we do with it, and how to reach us if something looks wrong.
What we access, and why
Every permission we hold is listed in your dashboard with the reason we hold it. You can revoke any of it at any time, and we'll tell you what stops working if you do.
| System | What we access | Why |
|---|---|---|
| Microsoft 365 or Google Workspace | Mail flow rules, sign-in and audit logs, security settings. Message content only when a message is quarantined or you ask us to investigate. | Email security, identity protection and evidence for reports |
| Company devices | A security agent with local administrator rights. Process, network and file activity. No screenshots, keystrokes or personal files. | Endpoint protection, isolation and patching |
| Backups | Read access to mailboxes, files, Teams and SharePoint; image access to servers you nominate. | Nightly backups and restore tests |
| Business applications | Sign-in and admin audit logs only, through each application's official integration. | Identity protection across the apps you rely on |
| Network | Firewall and DNS logs where available. We do not inspect the content of your traffic. | Detection of command-and-control and lateral movement |
Your data
Security telemetry and backups are stored in dedicated environments in the United States. Access is limited to the team members assigned to your account, logged, and reviewed.
Our own environment runs on the same detection and response we sell, with the same alerts and the same reports.
Independent penetration tests of our platform and processes every year, with findings tracked to closure.
Access to customer environments is granted per engagement, expires automatically and requires a hardware key.
Our control set maps to CIS Controls v8 and SOC 2 criteria. Audit documentation is available to customers under NDA.
Our own security
A security provider is a target. We design for that: separate environments for each customer, no standing admin access, and the assumption that any single control can fail.
Incident notification
If an incident at WindBreak affects your data or your service, we notify you within 24 hours of confirmation. The notice covers what happened, what we did, what we know about the impact on you, and what, if anything, you need to do. We update you until it's closed.
A reporting vendor disclosed unauthorized access to their systems on Tuesday.
Confirmed with the vendor that no WindBreak data was stored in the affected systems, rotated our credentials with them, and reviewed our own logs.
Nothing.
Subprocessors
We use a small number of vendors to deliver the service, such as endpoint and email security platforms and cloud hosting. Each is contractually bound to protect your data to the same standard we are. The current list is provided to every customer at onboarding and whenever it changes, with 30 days' notice.
Email us and we'll send the subprocessor list, our data processing terms and our security overview.
Email security@windbreaksecurity.comResponsible disclosure
If you've found a vulnerability in our website, platform or systems, we want to hear about it. We'll acknowledge within two business days, keep you informed while we fix it, and credit you if you'd like. We won't take legal action against research done in good faith.
Ask a security lead directly. We'd rather over-explain than leave you guessing.