
Security & Compliance
Access the latest security and compliance certifications and assessments

Security as a foundation
Outerlimit maintains a formal information security compliance program, independently assessed against recognised industry frameworks. Below is the current status of our certifications and attestations, along with the frameworks we are actively pursuing.
Security & compliance at Outerlimit is an ongoing program, not a fixed checklist. Beyond the certifications below, we continually evaluate additional frameworks and attestations to meet evolving customer, regulatory, and industry requirements, and we will update this page as our certification program expands.
For a copy of our current certificates, audit reports, or our security questionnaire responses, please contact our security team or request access to the compliance portal.

Security Testing
Certification and attestation are backed by ongoing, operational security practices, not just periodic audits.
Continuous Vulnerability Scanning
Outerlimit runs continuous automated vulnerability scanning across its endpoint and infrastructure estate, with identified vulnerabilities tracked and remediated against defined severity-based timelines.
Penetration Testing — Internal
In addition to automated scanning, Outerlimit carries out internal penetration testing to identify exploitable weaknesses within its internal network and systems.F
Penetration Testing — External
Outerlimit commissions independent external penetration testing on a quarterly basis, carried out by a third-party security firm against internet-facing infrastructure and applications. Findings are tracked through to remediation, and reports are available on request as part of our due-diligence pack.
Staff Security Awareness Training
All staff complete security awareness training covering topics such as phishing, social engineering, data handling, and acceptable use, reinforced through ongoing simulated phishing exercises and periodic refreshers.
Secure Development Practices
Software development follows secure lifecycle practices: code review and independent QA approval before merge, static code, infrastructure-as-code and dependency scanning, separated development, staging and production environments, and automated deployment from approved builds behind a production approval gate. Production data is never used outside production..




