Skip to main content
Infrastructure security

Security at BreachLine Labs

Nebula is built for offensive security — and we apply the same rigour to protecting your data. Complete isolation, encrypted at every layer, and GDPR-compliant by design.

Compliance

Compliance and standards

GDPR & UK DPA 2018

Full compliance with UK GDPR and the Data Protection Act 2018, as a UK-registered company.

EU AI Act

A limited-risk AI system under the EU AI Act — not a high-risk (Annex III) use, and we neither train nor release a general-purpose AI model. We meet the Article 50 transparency duties (in force Aug 2026), human oversight, and AI-literacy obligations: the platform is disclosed as AI and stays operator-directed. This is a self-assessed position, not a certificate — the Act issues none for limited-risk systems.

Data rights built in

Article 17 erasure, data export, and a tamper-evident audit log you can verify yourself.

Tested to standard

Engagements follow OWASP, PTES, and MITRE ATT&CK, aligned to NCSC guidance.

Cyber Essentials certified

Certified under the NCSC-backed Cyber Essentials scheme by the IASME Consortium (issued Aug 2026, valid to Aug 2027) — verifiable on the public register. ISO 27001 and SOC 2 remain on our roadmap; we publish each certificate when it is issued, not before.

Encrypted by default

AES-256 at rest, TLS 1.2+ in transit, and per-organisation database isolation.

Framework mapping

Findings mapped to ISO 27001, SOC 2, PCI DSS, and NIST CSF for audit evidence.

Controls

Security measures

Customer data isolation

Each organisation is isolated at the database level: an organisation's data lives in its own dedicated database, with row-level security enforced as a second, independent layer. Scan results, credentials, and findings are not shared between customers. Enterprise customers can deploy Nebula on-premise or in their own cloud tenancy for complete data control.

Encrypted infrastructure

All data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher, with TLS 1.3 negotiated wherever the peer supports it. API keys and credentials are protected with additional key-derivation layers. Infrastructure is hosted with geographic redundancy and strict access controls.

Access control

Role-based access control (RBAC), multi-factor authentication available on every account, and full session management. Every API call and Nebula scan action is logged. Complete audit trails available to enterprise customers.

Continuous security testing

We deploy Nebula against our own infrastructure continuously — dogfooding our own product. We operate a published vulnerability disclosure policy with safe harbour for good-faith researchers.

Data protection

How we handle personal data

As a UK-registered company, BreachLine Labs Limited processes personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our approach to data protection includes:

  • Data Protection Officer (DPO) — A designated DPO monitors our compliance with data protection law, advises on our processing, and is the contact point for the ICO and for data subjects. The DPO can be reached at [email protected]; full details are in our Privacy Policy.
  • Data Protection Impact Assessments (DPIAs) — We conduct DPIAs for any processing activity that may present a high risk to individuals' rights and freedoms.
  • Data Minimisation — Nebula only collects and retains the minimum data necessary to perform scans and deliver results. Scan data is purged according to configurable retention policies.
  • Lawful Processing — All personal data is processed under a valid lawful basis, typically legitimate interest or contractual necessity, and never sold to third parties.
  • Data Subject Rights — We honour all data subject rights including access, rectification, erasure, portability, and the right to object. Requests are answered within one calendar month, extendable by up to two further months for complex or numerous requests, as permitted by Article 12(3).
  • International Transfers — Where data is transferred outside the UK, we rely on approved safeguards such as Standard Contractual Clauses (SCCs) or adequacy decisions.

Disclosure

Responsible disclosure

We appreciate the security research community's efforts in keeping Nebula and BreachLine secure. If you discover a vulnerability in our platform or infrastructure, report it to [email protected]. Our machine-readable contact details are published at /.well-known/security.txt (RFC 9116).

Safe harbour. If you follow this policy in good faith, we will treat your research as authorised access to our systems for the purposes of the Computer Misuse Act 1990 and of our Terms of Service, which carry a matching security research carve-out. We will not bring a civil claim against you in respect of that research, and will not refer you to law enforcement, save where we are required to do so by law or by a regulator. If a third party brings action against you for research that complied with this policy, we will make that compliance known. Should you unintentionally breach this policy, telling us promptly and in good faith preserves the safe harbour.

The limits of that promise — stated plainly, because relying on a promise we cannot keep is the real harm. Decisions to prosecute under the Computer Misuse Act 1990 rest with the Crown Prosecution Service, which is not bound by this policy; we can decline to complain and can vouch for your compliance, and that is the extent of what any company can offer. This authorisation covers only systems BreachLine owns or controls: our platform runs on third-party infrastructure, and we cannot waive those providers' acceptable-use policies on your behalf. Where we hold personal data belonging to our customers, statutory duties to notify a regulator or an affected customer override this policy.

In scope

  • • breachline.io and its subdomains, api.breachline.io, and the BreachLine CLI and desktop clients.

Out of scope — the safe harbour does not extend to these

  • • Denial-of-service, volumetric or load testing, or anything degrading service for others.
  • • Accessing, modifying or exfiltrating data belonging to any other customer. Stop at the point a vulnerability is demonstrated, and never collect more data than proves it.
  • • Social engineering, phishing, or physical attacks against our staff, customers or offices.
  • • Findings in our third-party providers' own infrastructure — report those to the provider.

What to expect

  • • Acknowledgement within 3 working days, and a triage decision within 10 working days.
  • • Progress updates at least every 14 days until the issue is resolved.
  • • Coordinated disclosure: please allow 90 days before publishing, and we will agree an earlier date with you where a fix ships sooner.
  • • Public credit where you want it, and none where you do not. We do not currently run a paid bounty programme; where a report is materially valuable we may offer a reward at our discretion.

Security questions?

Contact our security team for any concerns.

BreachLine Labs Limited — 60 Tottenham Court Road, Office 1377, Fitzrovia, London W1T 2EW, United Kingdom

Contact security team