Sensitive data transmission
Here is how we reduce information leakage when sending data to our clients.
Secure information-sharing system
We use an information-sharing system with DLP (data loss prevention) when sending sensitive information to our clients. This includes contracts, portfolios, and other confidential documents. Further, Fluid Attacks’ platform offers a feature that allows clients to securely upload files that may be helpful or necessary to perform security testing.
Onion routing
The Fluid Attacks domain supports onion routing , which enhances user privacy and enables more fine-grained protection.
Verification code required
Fluid Attacks manages all report downloads within the platform, requiring verification codes for report generation requests.
Watermarked reports
Every report that is downloaded via our platform comes with a watermark on all pages, specifying that only the individual who generated it is allowed to read it. This is used as a measure to identify who generated the report in the first place and discourage its distribution through channels other than our platform .
Requirements
- 032. Avoid session ID leakagesÂ
- 045. Remove metadata when sharing filesÂ
- 132. Passphrases with at least 4 wordsÂ
- 261. Avoid exposing sensitive informationÂ
- 300. Mask sensitive dataÂ