// Security & Trust

We Run Our Shop the Way
We Tell You to Run Yours.

Corvus is a security practice, so we hold ourselves to the same controls we'd expect of any vendor we assess. This is how we protect the information you share with us, and how our own house is kept in order.

How We Protect Your Data Report a Security Concern
Access Multi-factor authentication enforced across every business system.
Client Data Encrypted in transit and at rest, exchanged only through access-controlled channels.
Program Governed by written policy and aligned to the NIST Cybersecurity Framework.

Practitioner-Led.
Held to Our Own Standard.

A consultancy that advises on security has no business running a loose one. Every engagement puts sensitive client information in our hands, assessment findings, architecture details, incident history, and that trust is only as good as the controls behind it. The practices below are the baseline we operate to, described in the same terms we use when we evaluate a third party for our clients.

The Controls Behind the Trust

Eight areas, described by capability. We keep specifics of vendors and architecture private, the same posture we recommend to clients.

Data Protection & Client Confidentiality

  • Client data encrypted in transit and at rest
  • Files exchanged through a dedicated, access-controlled portal, never as open email attachments
  • Data minimization: we collect only what an engagement requires
  • Defined retention with secure destruction at engagement close
  • Client material isolated from general-purpose and marketing systems

Access & Identity

  • Multi-factor authentication enforced on every business system
  • Unique, strong credentials managed in a self-hosted password vault
  • Least-privilege access; administrative accounts separated from daily use
  • Single sign-on applied wherever a platform supports it
  • Access reviewed and revoked promptly when it is no longer needed

Infrastructure & Application Security

  • Public services sit behind an enterprise web application firewall and CDN with DDoS protection
  • Administrative surfaces are identity-gated, not exposed to the open internet
  • Hardened server configuration with a routine patching cadence
  • Modern TLS everywhere, with security response headers enforced
  • Segmented network architecture separating trust zones

Vulnerability Management

  • Routine vulnerability scanning across systems and applications
  • Findings prioritized by risk and remediated on defined timelines
  • Operating systems and software kept current against known issues
  • Vendor and CVE advisories monitored for components we run

Threat Detection & Monitoring

  • Centralized logging with SIEM-based monitoring across systems
  • Endpoint detection and response on managed devices
  • Continuous ingestion of external threat intelligence
  • Alerting on anomalous access and administrative activity

Third-Party Risk Management

  • Vendors and subprocessors assessed for security posture before adoption
  • Diligence scaled to the data sensitivity and access each provider holds
  • Preference for providers holding recognized attestations (SOC 2, ISO 27001)
  • Data-processing terms reviewed; retention and training controls confirmed
  • Critical providers reassessed on an ongoing basis

Resilience & Continuity

  • Automated, encrypted backups with verified restoration
  • Backup copies kept separate from primary systems
  • Documented recovery procedures for critical services
  • Reputable, security-reviewed providers underpin core infrastructure

Governance & Policy

  • Written security policies govern how the practice operates
  • Program aligned to the NIST Cybersecurity Framework
  • Defined ownership and accountability for security decisions
  • Regular self-assessment against the standards we hold clients to

Your Data Isn't Used to Train AI Models

Corvus rook: AI confidentiality

AI, Vetted Like Any Other Third Party

AI is part of how we work, and we treat the tools like any vendor that touches sensitive data. We review providers against the same security posture we'd expect of any third party, opt our accounts out of model training, and route the most sensitive client material to private AI running on infrastructure we control. That private footprint keeps growing. Where we use commercial AI, we match the tool and its configuration to the sensitivity of the data rather than defaulting to it. It's the same third-party diligence we'd tell you to apply to your own AI use.

Aligned to the Frameworks We Assess

Corvus maps its own practice to recognized frameworks and is led by a certified, long-tenured practitioner.

Frameworks We Work In

NIST CSF NIST 800-53 SOC 2 PCI DSS HIPAA GLBA SOX ITGC GovRAMP TX-RAMP CMMC

Leadership Credentials

CISSP Certified Information Systems Security Professional, active
GIAC GLEG Law of Data Security & Investigations, SANS Institute, active
CCP → CCA Certified CMMC Professional and Assessor, in progress
Former → PCIP & ISA PCI Professional and Internal Security Assessor, PCIP renewal in progress.

Corvus aligns its practice to the frameworks above and delivers formal assessments, SOC 2, PCI DSS, HIPAA, and others, on behalf of clients. Those attestations are the engagements we perform; our own program is governed by written policy and continuous self-assessment against the same standards.

Found Something? Tell Us.

If you believe you've found a security vulnerability affecting Corvus, we want to hear from you. We review every good-faith report and will work with you on responsible disclosure. Full guidelines are on our disclosure page.

Read the Disclosure Policy
Report to [email protected]
Good-faith reports acknowledged
Coordinated, responsible disclosure

Questions About How We Handle Your Data?

Ask us anything about our security posture before you engage. It's exactly the diligence we'd tell you to run on any vendor.

Start a Conversation