We ask clients to trust us with staff details and training records. This page describes how we handle that, and how to report a problem.
Reporting a vulnerability
If you have found a security issue in this website or in a training portal we operate, email security@maksisu.com. Include enough detail to reproduce it.
We will acknowledge within two business days and tell you what we intend to do. We will not pursue legal action against anyone who reports a genuine issue in good faith, avoids privacy violations and service disruption, and gives us reasonable time to fix it before disclosing. We do not currently operate a paid bug bounty.
Please do not test against client portals, run automated scanners at volume, or access data that is not yours.
Data minimisation
We ask for the least we need: for a booking, a work email address; for a training program, staff names and work email addresses. We do not collect government identifiers, financial details of staff, or the content of anyone's mailbox. We never see or store the credentials your staff use for their real accounts — including during phishing simulations, where credentials submitted to a simulated page are not captured or stored, only the fact that a submission occurred.
Hosting and infrastructure
- This website is served as static files from Cloudflare's edge network, with TLS enforced and HSTS enabled.
- Security headers, including a content security policy, are applied to every response.
- Form submissions are rate-limited and validated server-side.
Access control
Access to client data is limited to personnel who need it to deliver the service. Administrative access requires multi-factor authentication. We review access when anyone's role changes.
Phishing simulations
Simulations are run only under written client authorisation, against that client's own staff. Landing pages are clearly identified as training once the exercise concludes. Results are reported in aggregate by default; individual results are shared only where the client requests them and has a lawful basis. We design simulations to teach, not to humiliate — we avoid themes such as bonuses, redundancies or bereavement that cause disproportionate distress.
Subprocessors
The current list is maintained in our privacy notice. Active clients are notified before a new subprocessor handling personal data is added.
Incident response
If we suffer a breach affecting client personal data, we notify affected clients without undue delay and within 72 hours of becoming aware, with what we know, what we are doing, and what we recommend. As a processor we support clients in meeting their own regulatory notification duties.
Business continuity
Training records are backed up so that a quarterly evidence package can be reproduced. If we cease operating, active clients receive their complete training records and evidence packages before service ends.
Credentials
MakSisu's practice is led by a practitioner holding professional certifications in ISO/IEC 27001 (information security management), ISO 22301 (business continuity), CISA, CISM and ITIL.
These are individual professional credentials, not an organisational certification of MakSisu Technologies. We are not ourselves certified to ISO 27001, and we do not hold a SOC 2 attestation. We say so plainly because the distinction matters: it means your curriculum and your evidence packages are prepared by someone who works inside these frameworks, and it means you should not cite us as a certified supplier in your own vendor assessments.
Contact
Security matters: security@maksisu.com. Everything else: hello@maksisu.com.