Skip to content
DefendGen

Trust and security

We sell security. You should hold us to it.

If you are running a vendor review before signing, this page is the short version. Anything not covered here we will answer in writing. Email contact@defendgen.com and ask.

Where we operate

Our SOC is in Pakistan. We say so up front.

Our security operations centre runs from Pakistan, nine to ten hours ahead of US time zones. That gap is the reason the service works: US overnight hours, when a large share of attacks land, fall in the middle of our staffed working day. A 2 a.m. alert on your side is handled by an analyst who is awake and on shift.

This is the same follow-the-sun model used by global security firms serving much larger clients. We put it on the website rather than in the small print, because you will find out either way and it is better that you hear it from us.

Client calls and reviews are scheduled during US business hours. Incident response runs around the clock. All work is documented in writing.

Running a vendor security review?

Send us your questionnaire. Questions about data handling, access control, subcontractors, insurance, and incident notification are answered in writing before you sign anything, not after. If we cannot meet a requirement we will tell you that instead of working around it.

Send us your questionnaire

The client portal

The portal is held to the standard we sell.

The portal is in build and not yet open to clients. These are the constraints it is being built under, published before launch rather than after.

  • An authenticator code is required for every account. There is no way to opt out, including for our own staff.
  • Client data is separated at the database level, and automated tests prove the separation before any release ships.
  • The portal can read your security data. It cannot take action inside your environment, so a portal compromise cannot reach your endpoints.
  • Client data is stored in the United States. Every sign in and administrative action is written to an audit log.

Reporting a problem

Found a security issue in something of ours?

Tell us. Email contact@defendgen.com with enough detail to reproduce it. We will acknowledge your report, keep you updated while we fix it, and credit you if you want the credit. We will not pursue anyone acting in good faith who reports a genuine issue to us privately.

Our machine-readable disclosure policy is published at /.well-known/security.txt.

Have a question this page did not answer?

Ask it directly. We would rather answer a hard question before you sign than have it surface during an audit.

Get Your Free Risk Assessment