Security
Piscium's platform and infrastructure are built with the same rigor Radius applies to yours, and this page is honest about where that stands: OWASP APTS alignment, encryption in transit and at rest, and no certifications yet.
Security Status
Active
All systems operational. Continuous monitoring enabled.
Standards & Posture
OWASP APTS
We align our autonomous testing to the OWASP Autonomous Penetration Testing Standard: a governance standard for operating autonomous pentest platforms safely, transparently, and within defined boundaries.
Certifications: none yet
Piscium holds no third-party security certifications. SOC 2 and ISO 27001 are on the roadmap, and this page will be updated when that changes. We will not claim what we have not earned.
Data protection
Customer data is encrypted in transit and at rest, with least-privilege access controls and documented handling practices.
Our Security Posture
Encryption, least-privilege access, and continuous validation, applied to our own systems with the same rigor we deliver to customers.
Encryption
Data encrypted in transit (TLS 1.3) and at rest (AES-256).
Access Control
Role-based access control with mandatory multi-factor authentication and least-privilege defaults.
Secure Development
SAST, DAST, and SCA integrated into our CI/CD pipeline. All code reviewed before merge. Dependency updates automated.
Incident Response
Documented incident response plan with defined escalation paths.
Radius on Piscium
Piscium runs Radius against its own environment, inside the same rules of engagement and safety model it applies to customers, aligned with the OWASP APTS.
Related Resources
Have Security Questions?
Ask about our practices, request the security documentation, or send a vendor security questionnaire. One person answers, and it is the person who built the platform.