Security is part of the product
Vulnerabilities are disclosed, incidents are reported with a timeline, and neither waits for a news cycle.
Every system will eventually fail somewhere. What separates a trustworthy institution from an untrustworthy one is entirely in what it does in the hours afterwards.
THIS RULES OUT
- No quiet patching of an issue that affected people's data.
- No legal pressure applied to good-faith researchers.
- No incident description written to minimise what happened.
HOW TO CHECK US
- A published disclosure route with a stated response window.
- Incident reports include what failed, who was affected and what changed.