How we handle your data

What happens to your information before, during and after an engagement, and where our managed services keep data. Written for the security, legal and vendor-risk teams who review their suppliers.

In short

  • An NDA is signed before any system detail is shared, ours or yours.
  • Testing starts only after written authorisation and a signed scope. The authorisation names the people who will carry out the testing.
  • We keep a timestamped activity log and share it on request.
  • Evidence is encrypted at rest and destroyed on a date agreed with you.
  • We never name a client publicly without written permission.
  • Where IMIZI Monitor and IMIZI Aware data is hosted is agreed in your contract, against your regulator's rules.

Before testing starts

  1. NDA. Signed before either side shares any system detail, including on the scoping call if it needs that detail.
  2. Signed scope. What we test, when, and what is out of bounds, agreed in writing.
  3. Written authorisation. Your authorisation to test, signed before any testing starts. It names the people who will carry out the testing.
  4. Source addresses. We give you the IP addresses we will test from, so your team can tell our traffic apart from anyone else's.

During testing

  • We test only what the signed scope covers, inside the agreed testing window.
  • We keep a real-time activity log recording the timestamp, source IP, target and action for what we do. It is available to you on request, during or after the engagement.
  • On production systems we agree timing with you and use non-destructive techniques. If anything behaves unexpectedly, we pause and coordinate with your team.

Evidence and reports

  • Test evidence, such as screenshots, requests, responses and notes, is encrypted at rest.
  • The report reaches you through a delivery channel we agree with you. Reports can be exchanged with PGP: our security@ key and its fingerprint are published on the responsible disclosure page.
  • Findings are presented to your technical team and to management, in person where possible.

After the engagement

  • Test evidence is destroyed on a date agreed with you.
  • On request, we return or destroy all confidential information you gave us and confirm it in writing. Copies held in routine backups, or kept under a legal hold, remain confidential.

Confidentiality

We never name a client publicly without written permission. What we learn about your environment stays under the NDA.

IMIZI Monitor and IMIZI Aware

Where our managed services store your data is set out in your contract and agreed during onboarding. Monitor works from the domains and internet-facing assets you give us; Aware needs the work email addresses of the people in the programme.

Any transfer of personal data out of Rwanda follows Law N° 058/2021 (Articles 48 to 50), and we agree the basis with you in the contract before processing starts.

If you are supervised by the National Bank of Rwanda, your own outsourcing rules may also apply: Regulation N° 49/2022 treats cloud services as outsourcing (Article 20) and requires BNR's prior approval to outsource a material activity (Article 21).

Who we are

IMIZI Cyber Consulting Ltd, Norrsken House, 1 KN 78 St, Kigali, Rwanda, is registered with the National Cyber Security Authority (NCSA) as a data controller under Law N° 058/2021. Data-protection questions: dpo@imizicyber.com.

This page covers data from engagements. For data collected through this website, see our privacy policy.

Questions vendor-risk teams ask

Do you sign an NDA before scoping?

Yes. An NDA is signed before any system detail is shared, in either direction. If the scoping call needs detail about your environment, the NDA comes first.

Who will test our systems?

The testers are named in the written authorisation you sign before testing starts. Testing does not begin until that authorisation and a signed scope are in place.

How long do you keep our test evidence?

Until a destruction date we agree with you after the engagement; until then it is encrypted at rest. On request we return or destroy all confidential information and confirm it in writing. Copies in routine backups or under a legal hold remain confidential.

Will you name us as a client?

Not without your written permission.

Where are IMIZI Monitor and IMIZI Aware hosted?

Hosting is set out in your contract and agreed during onboarding, against your regulator's rules and Law N° 058/2021. Any transfer of personal data out of Rwanda follows Articles 48 to 50 of that law, and we agree the basis with you before processing starts.

Who to contact

Engagement and data questions
info@imizicyber.com
Security reports and encrypted exchange
security@imizicyber.com (PGP key and fingerprint)
Phone
+250 793 146 617

Walk through your vendor-risk questions with us

Book a free call and we will walk through how data is handled on your engagement, or email the questions and we reply within 24 hours.