Corvus is a security practice, so we hold ourselves to the same controls we'd expect of any vendor we assess.
This is how we protect the information you share with us, and how our own house is kept in order.
AccessMulti-factor authentication enforced across every business system.
Client DataEncrypted in transit and at rest, exchanged only through access-controlled channels.
ProgramGoverned by written policy and aligned to the NIST Cybersecurity Framework.
// Our Commitment
Practitioner-Led. Held to Our Own Standard.
A consultancy that advises on security has no business running a loose one. Every engagement puts sensitive client
information in our hands, assessment findings, architecture details, incident history, and that trust is only as
good as the controls behind it. The practices below are the baseline we operate to, described in the same terms we
use when we evaluate a third party for our clients.
// How We Operate
The Controls Behind the Trust
Eight areas, described by capability. We keep specifics of vendors and architecture private, the same posture we recommend to clients.
Data Protection & Client Confidentiality
Client data encrypted in transit and at rest
Files exchanged through a dedicated, access-controlled portal, never as open email attachments
Data minimization: we collect only what an engagement requires
Defined retention with secure destruction at engagement close
Client material isolated from general-purpose and marketing systems
Access & Identity
Multi-factor authentication enforced on every business system
Unique, strong credentials managed in a self-hosted password vault
Least-privilege access; administrative accounts separated from daily use
Single sign-on applied wherever a platform supports it
Access reviewed and revoked promptly when it is no longer needed
Infrastructure & Application Security
Public services sit behind an enterprise web application firewall and CDN with DDoS protection
Administrative surfaces are identity-gated, not exposed to the open internet
Hardened server configuration with a routine patching cadence
Modern TLS everywhere, with security response headers enforced
Segmented network architecture separating trust zones
Vulnerability Management
Routine vulnerability scanning across systems and applications
Findings prioritized by risk and remediated on defined timelines
Operating systems and software kept current against known issues
Vendor and CVE advisories monitored for components we run
Threat Detection & Monitoring
Centralized logging with SIEM-based monitoring across systems
Endpoint detection and response on managed devices
Continuous ingestion of external threat intelligence
Alerting on anomalous access and administrative activity
Third-Party Risk Management
Vendors and subprocessors assessed for security posture before adoption
Diligence scaled to the data sensitivity and access each provider holds
Preference for providers holding recognized attestations (SOC 2, ISO 27001)
Data-processing terms reviewed; retention and training controls confirmed
Critical providers reassessed on an ongoing basis
Resilience & Continuity
Automated, encrypted backups with verified restoration
Backup copies kept separate from primary systems
Documented recovery procedures for critical services
Written security policies govern how the practice operates
Program aligned to the NIST Cybersecurity Framework
Defined ownership and accountability for security decisions
Regular self-assessment against the standards we hold clients to
// AI & Confidentiality
Your Data Isn't Used to Train AI Models
AI, Vetted Like Any Other Third Party
AI is part of how we work, and we treat the tools like any vendor that touches sensitive data. We review providers against the same security posture we'd expect of any third party, opt our accounts out of model training, and route the most sensitive client material to private AI running on infrastructure we control. That private footprint keeps growing. Where we use commercial AI, we match the tool and its configuration to the sensitivity of the data rather than defaulting to it. It's the same third-party diligence we'd tell you to apply to your own AI use.
// Governance & Credentials
Aligned to the Frameworks We Assess
Corvus maps its own practice to recognized frameworks and is led by a certified, long-tenured practitioner.
CISSPCertified Information Systems Security Professional, active
GIAC GLEGLaw of Data Security & Investigations, SANS Institute, active
CCP → CCACertified CMMC Professional and Assessor, in progress
Former → PCIP & ISAPCI Professional and Internal Security Assessor, PCIP renewal in progress.
Corvus aligns its practice to the frameworks above and delivers formal assessments, SOC 2, PCI DSS, HIPAA, and
others, on behalf of clients. Those attestations are the engagements we perform; our own program is governed by
written policy and continuous self-assessment against the same standards.
// Responsible Disclosure
Found Something? Tell Us.
If you believe you've found a security vulnerability affecting Corvus, we want to hear from you. We review every
good-faith report and will work with you on responsible disclosure. Full guidelines are on our disclosure page.