Security & Trust

A forensics firm must protect what it examines

We audit security for a living, so we hold our own to the same bar. Two things matter: how your case materials are handled, and how this website itself is built. Here is exactly how we protect both.

Your case materials

Handled through encrypted channels only

Encrypted intake

Sensitive documents never go through the website form. We move you to an encrypted channel for anything confidential.

Data minimisation

We ask only for what a case truly needs — nothing more — and the website collects no personal data by default.

Storage & deletion

Case materials are kept encrypted, only as long as needed, and deleted on your request.

Confidentiality

Only the analyst on your case sees your materials. We work independently and can sign an NDA.

This website

Built with almost no attack surface

  • Static pages — no database, no admin panel, no server-side code to breach.
  • Hardened HTTP headers — strict Content-Security-Policy, HSTS, anti-clickjacking, and more.
  • No third-party trackers or ad scripts — nothing loads without your consent.
  • DDoS mitigation and a Web Application Firewall at the edge.
  • Domain locked with DNSSEC, registrar lock and 2FA on every account.
  • Encrypted email on our own domain, with SPF, DKIM and DMARC against spoofing.

Your data lifecycle

From intake to deletion

01

Intake

You reach us encrypted; sensitive files come through a secure channel, not the site.

02

Work

Materials stay encrypted and are seen only by your analyst.

03

Delivery

The report is handed over through the same secure channel.

04

Deletion

On request, we delete your materials and confirm it.

Privacy by default

Built to GDPR as a baseline

The site collects no personal data by default, loads no analytics before consent, and uses cookieless, anonymous statistics only if you opt in. You can access, correct or delete your data and withdraw consent at any time.

Read our Privacy Policy
Found a security issue?

We welcome reports from security researchers. Email security@fesoti.io — a security.txt is published on the domain.

Talk to us, securely

Start over an encrypted channel — no sensitive data through the website.

Request a confidential consultation