What happens to your data when you work with us, and what we're accountable for.
Last updated: 2026-08-11
Crusader Security is a boutique practice based in Madison, Wisconsin. Engagements are delivered personally by the practitioner you meet on your first call — your account is not handed to a junior after the sale, and the person who runs your assessment is the person who wrote the report and will answer questions about it.
A current list of the tools used to process client data during an engagement is available on request, as are references from comparable engagements.
What we collect
Only what the engagement requires: configuration exports, scan output, and the findings derived from them. We don't ask for data we have no use for.
Retention
Engagement evidence is retained for 12 months after delivery, then deleted. The window exists so we can support re-tests, insurer and audit questions, and follow-up work without asking you to reassemble everything.
Early deletion
You can request deletion sooner at any time, for any reason. Email info@crusadersec.com and we'll confirm once it's done.
Your report is yours
Deliverables belong to you. Share them with your insurer, your board, or your auditor without asking us — that's what they're for.
Confidentiality
Findings identify real weaknesses in your environment, so we treat them as sensitive by default. We don't publish client names, use your findings as marketing material, or discuss one client's environment with another.
Insurance
We carry cyber liability and professional (errors & omissions) coverage. Certificates are available on request — just ask during scoping and we'll send one over, including directly to your procurement office if that's easier.
Engagement terms
Every project is governed by its own Statement of Work covering scope, schedule, and price. Our Terms of Service apply where the SOW is silent.
Managed protection term
Managed plans run on a 12-month term that renews automatically, with 60 days' notice to cancel before a renewal. Assessments and projects carry no such commitment — they're one-time engagements.
Pricing
Assessment and managed pricing is published on our site rather than quoted per buyer. You can price an engagement yourself before you ever speak to us.
A trust page is only useful if it's honest about the gaps, so:
We are not SOC 2 certified
SOC 2 attests to a service organization's own control environment. We are a small consulting practice, not a SaaS platform holding your data at scale. If your procurement process requires a SOC 2 report from vendors, tell us early and we'll work through what evidence we can provide instead.
We do not offer a HIPAA BAA
Our engagements are scoped to avoid processing protected health information. If your environment makes that unavoidable, raise it during scoping so we can adjust scope rather than discover it mid-engagement.
We are not a 24/7 in-house SOC
Round-the-clock monitoring in our managed plans is delivered with an established SOC partner. We are the ones you call, and we own the relationship and the outcome — but we are not pretending to staff a night shift ourselves.
An assessment is a point-in-time review
It reflects your environment as configured during the engagement window. It is not a guarantee against compromise, and no honest security vendor will offer you one.
If you've found a security issue in this website, we want to hear about it. We publish a machine-readable security contact at /.well-known/security.txt (RFC 9116). Direct contact:
Security, privacy & legal: info@crusadersec.com
We acknowledge reports within 2 business days. Good-faith research is welcome; please avoid denial-of-service testing and anything that would affect other visitors.
If you spot a claim on this page that doesn't match your experience working with us, email info@crusadersec.com — we want to know.