Legal & Compliance
Our commitments to operational integrity, bilateral non-disclosure, responsible disclosure ethics, and compliance with African data protection frameworks.
All offensive testing, penetration assessments, and red teaming exercises are performed strictly under authorized written consent. Pique Squid requires designated executive sign-off and explicit definition of target IP ranges, domains, and operational boundaries prior to testing.
Any vulnerability findings, network architectural schematics, credential samples, or client telemetry gathered during an engagement are classified as Confidential Trade Secrets. Data is stored on sovereign encrypted infrastructure and purged in accordance with our data destruction protocol post-remediation.
If our research team identifies an external critical vulnerability affecting a regional entity or open source technology, we practice coordinated, responsible disclosure. Affected vendors are given adequate remediation windows prior to public advisory publication.
Our practices are governed by the Zimbabwe Cyber and Data Protection Act (CDPA), the Zambia Data Protection Act, and international frameworks including ISO/IEC 27001 and the NIST Cybersecurity Framework (CSF).
Retained Managed Detection and Response (MDR) clients receive guaranteed 24/7/365 active monitoring with guaranteed sub-15 minute triage response times for Severity 1 (Critical) breach alerts.