Start with the minimum information necessary.
Compliance testing can involve sensitive information. Rulint's approach begins by separating non-confidential scoping from the governed client workflows used during an engagement.
Compliance testing can involve sensitive information. Rulint's approach begins by separating non-confidential scoping from the governed client workflows used during an engagement.
The public testing-request form is intended only for initial, non-confidential scoping information.
Data requirements should be driven by the approved testing methodology, not by collecting information simply because it is available.
Rulint maintains separate authenticated client and administrative workflows for operational testing activities rather than conducting client testing through the public website.
Security, access, data-transfer, retention, and other vendor-diligence requirements can be addressed during scoping before production client data is accepted for an engagement.
Public security statements are intended to reflect controls and practices that Rulint can substantiate. Formal certifications or examination results will be identified specifically if and when they are completed.
The exact information required depends on the testing scope, systems, population, evidence, and client environment. Those requirements are established during engagement scoping rather than through the public form.