Resources

Security & Compliance

Access the latest security and compliance certifications and assessments

Security as a foundation

Outerlimit maintains a formal information security compliance program, independently assessed against recognised industry frameworks. Below is the current status of our certifications and attestations, along with the frameworks we are actively pursuing.

Security & compliance at Outerlimit is an ongoing program, not a fixed checklist. Beyond the certifications below, we continually evaluate additional frameworks and attestations to meet evolving customer, regulatory, and industry requirements, and we will update this page as our certification program expands.

For a copy of our current certificates, audit reports, or our security questionnaire responses, please contact our security team or request access to the compliance portal.

Outerlimit Security Compliance

Security Testing

Certification and attestation are backed by ongoing, operational security practices, not just periodic audits.

Continuous Vulnerability Scanning

Outerlimit runs continuous automated vulnerability scanning across its endpoint and infrastructure estate, with identified vulnerabilities tracked and remediated against defined severity-based timelines.

Penetration Testing — Internal

In addition to automated scanning, Outerlimit carries out internal penetration testing to identify exploitable weaknesses within its internal network and systems.F

Penetration Testing — External

Outerlimit commissions independent external penetration testing on a quarterly basis, carried out by a third-party security firm against internet-facing infrastructure and applications. Findings are tracked through to remediation, and reports are available on request as part of our due-diligence pack.

Staff Security Awareness Training

All staff complete security awareness training covering topics such as phishing, social engineering, data handling, and acceptable use, reinforced through ongoing simulated phishing exercises and periodic refreshers.

Secure Development Practices

Software development follows secure lifecycle practices: code review and independent QA approval before merge, static code, infrastructure-as-code and dependency scanning, separated development, staging and production environments, and automated deployment from approved builds behind a production approval gate. Production data is never used outside production..

Outerlimit Security Testing