Reporting a vulnerability
If you believe you have found a security issue in this website or in the yourKEYtoIT platform, email security@yourkeytoit.com. Please include:
- What you found and where — a URL, endpoint or screen
- The steps needed to reproduce it
- What an attacker could do with it
- How you would like to be credited, if at all
We will acknowledge your report and keep you informed while we investigate. We ask that you give us a reasonable opportunity to fix an issue before disclosing it publicly, and that you avoid accessing, modifying or deleting data belonging to anyone else while testing. We will not pursue legal action against researchers who act in good faith within those bounds.
We do not currently run a paid bug bounty program.
What we do not claim
Security pages are often written to imply more than is true, so to be explicit:
- yourKEYtoIT does not hold a SOC 2, ISO 27001 or equivalent third-party certification, and we will not describe ourselves as certified, aligned or compliant with one.
- We do not claim any government or sector-specific accreditation.
- We have not commissioned an independent penetration test of the platform to date.
If your procurement process requires any of the above, tell us at the start of the conversation. We would rather say so plainly than waste your time.
How we build
These are the principles the platform is built to. Where you need specifics for a security review, ask us and we will answer the actual question rather than send a brochure.
- Least access by default. Role-based permissions decide what each user can see, and access to production is limited to the people who need it.
- Encryption in transit. Traffic to this site and to the platform is served over HTTPS.
- Separation between customers. One customer's project data is not visible to another.
- Recorded change. Approvals and status changes are written to an activity history rather than being editable in place without trace.
- Data you can take with you. Export is available on every plan, and deletion requests are honoured. See the privacy policy.
- Few third parties. We keep the number of vendors that touch customer data small, and we will tell you who they are if you ask.
Questions for a security review
Send security questionnaires and architecture questions to security@yourkeytoit.com. Data protection and privacy questions go to privacy@yourkeytoit.com.
Last updated 22 July 2026.