What happens to your data when you work with us, and what we're accountable for.

Last updated: 2026-08-11

Who does the work

Crusader Security is a boutique practice based in Madison, Wisconsin. Engagements are delivered personally by the practitioner you meet on your first call — your account is not handed to a junior after the sale, and the person who runs your assessment is the person who wrote the report and will answer questions about it.

A current list of the tools used to process client data during an engagement is available on request, as are references from comparable engagements.

How we handle your data

What we collect

Only what the engagement requires: configuration exports, scan output, and the findings derived from them. We don't ask for data we have no use for.

Retention

Engagement evidence is retained for 12 months after delivery, then deleted. The window exists so we can support re-tests, insurer and audit questions, and follow-up work without asking you to reassemble everything.

Early deletion

You can request deletion sooner at any time, for any reason. Email info@crusadersec.com and we'll confirm once it's done.

Your report is yours

Deliverables belong to you. Share them with your insurer, your board, or your auditor without asking us — that's what they're for.

Confidentiality

Findings identify real weaknesses in your environment, so we treat them as sensitive by default. We don't publish client names, use your findings as marketing material, or discuss one client's environment with another.

Insurance & contracting

Insurance

We carry cyber liability and professional (errors & omissions) coverage. Certificates are available on request — just ask during scoping and we'll send one over, including directly to your procurement office if that's easier.

Engagement terms

Every project is governed by its own Statement of Work covering scope, schedule, and price. Our Terms of Service apply where the SOW is silent.

Managed protection term

Managed plans run on a 12-month term that renews automatically, with 60 days' notice to cancel before a renewal. Assessments and projects carry no such commitment — they're one-time engagements.

Pricing

Assessment and managed pricing is published on our site rather than quoted per buyer. You can price an engagement yourself before you ever speak to us.

What we don't claim

A trust page is only useful if it's honest about the gaps, so:

We are not SOC 2 certified

SOC 2 attests to a service organization's own control environment. We are a small consulting practice, not a SaaS platform holding your data at scale. If your procurement process requires a SOC 2 report from vendors, tell us early and we'll work through what evidence we can provide instead.

We do not offer a HIPAA BAA

Our engagements are scoped to avoid processing protected health information. If your environment makes that unavoidable, raise it during scoping so we can adjust scope rather than discover it mid-engagement.

We are not a 24/7 in-house SOC

Round-the-clock monitoring in our managed plans is delivered with an established SOC partner. We are the ones you call, and we own the relationship and the outcome — but we are not pretending to staff a night shift ourselves.

An assessment is a point-in-time review

It reflects your environment as configured during the engagement window. It is not a guarantee against compromise, and no honest security vendor will offer you one.

Reporting a vulnerability

If you've found a security issue in this website, we want to hear about it. We publish a machine-readable security contact at /.well-known/security.txt (RFC 9116). Direct contact:

Security, privacy & legal: info@crusadersec.com

We acknowledge reports within 2 business days. Good-faith research is welcome; please avoid denial-of-service testing and anything that would affect other visitors.

If you spot a claim on this page that doesn't match your experience working with us, email info@crusadersec.com — we want to know.