Trust
How we protect your code and your data
Security vendors should be held to the standard they sell. This page states what we do, what we do not do, and how to report a problem. Documents referenced here are available under NDA from [email protected].
Security controls
ISO/IEC 27001 certified
O360 B.V. operates an information security management system certified against ISO/IEC 27001. The certificate is available to customers and prospects under NDA on request.
Your code stays where you choose
The platform runs as an on-premise appliance, as an Azure image inside your own subscription, or fully air-gapped with offline licensing and offline AI-assisted triage. In those modes no source code, binary or finding leaves your network.
EU hosting for the cloud service
The hosted service and the demo environment run in the European Union (Lithuania and the Netherlands). Data is not transferred outside the EU for processing.
Encryption and access control
TLS 1.2 or higher in transit, encryption at rest for stored artefacts, role-based access per organization and project, single sign-on and API tokens scoped to projects. Customer access is logged.
Least retention
Uploaded code and binaries are retained only as long as needed to produce findings and are deleted on request or on project deletion. Findings belong to the customer.
Tested by the people who build it
The platform is scanned with its own SAST and DAST engines on every release, and reviewed by our red team. Third-party penetration test summaries are shared with customers under NDA.
Vulnerability disclosure policy
Published in our security.txt as well. Last reviewed 9 September 2026.
- Report vulnerabilities in Offensive360 products or offensive360.com to [email protected]. You may encrypt sensitive details on request; we will provide a key.
- We acknowledge reports within two business days and aim to triage within five. We keep you informed of progress and agree a disclosure timeline with you, normally 90 days.
- Good-faith research is welcome: do not access, modify or exfiltrate data that is not yours, do not degrade service availability, and stop and report as soon as you confirm an issue.
- We do not pursue legal action against researchers who follow this policy. We credit researchers publicly on request.
- This policy covers offensive360.com, the hosted service at sast.offensive360.com and the shipped appliance images. It does not cover customer-operated deployments; report those to the customer.
Compliance mapping for our customers
Reports from the platform map findings to OWASP Top 10, CWE, SANS Top 25, PCI DSS, ISO/IEC 27001, NIS2, DORA, SOC 2, SAMA CSF and NCA ECC. See compliance for the detail, and Offensive360 GRC for managing the programs themselves.