Cybersecurity for businesses

Contact

Trust Center

In cybersecurity, trust is documented rather than declared.

Credentials

Founded 2018 · 30 professionals · 100+ clients.

Third-party certifications

Certified to ISO/IEC 27001, ISO 9001 and ISO 14001. All three certificates are available on request, with public certificate numbers and validity so anyone can verify them:

  • ISO/IEC 27001:2022, no. CI 9765-ES, valid until 4 March 2029
  • ISO 9001:2015, no. 00409, valid until 19 March 2029
  • ISO 14001:2015, no. 00328, valid until 19 March 2029

Catalogues and memberships

Listed in the INCIBE catalogue · CIS SecureSuite Member · AMETIC member (Cybersecurity, AI, Cloud committees) · Women4Cyber Spain associate member.

Data protection

We have a Data Protection Officer appointed and registered with the Spanish Data Protection Agency (AEPD), reachable at dpo@mineryreport.com.

We don't list what we can't show.

How we work

How we protect client information

  • NDA on every engagement, signed before work begins
  • Least privilege and need-to-know access
  • Encrypted channels for all sensitive transfers
  • Environment segregation in our own operations
  • Secure destruction of evidence and temporary data at project close, unless legally required or otherwise agreed
  • Full traceability of actions performed

Methodologies

  • CIS Controls v8 as the basis of our maturity assessments
  • CCN-STIC guidance (Spanish National Cryptologic Centre) for ENS and hardening work
  • PTES, OSSTMM and OWASP in offensive security
  • Documented chain of custody in all forensic work
  • GDPR compliance in any personal data processed on a client's behalf

Incident response and availability

Incident response available year-round, with documented escalation and communication procedures, coordination with authorities and court-appointed experts where required, and a complete record of all actions taken. For commercial enquiries, a partner responds within one hour, during business hours.

Commitments

Vendor agnosticism

We are not tied to any manufacturer. We work with multiple technologies and recommend based on the client's risk, not on a catalogue. Our audits never end in a predetermined shopping list.

We are part of a business group that includes a separate company dedicated to systems and technology supply. Separate companies, separate teams — and one rule that is not negotiable: Minery Report's audits and recommendations favour no one's product, including within the group. We state this here because transparency about a corporate relationship is worth more than silence: anyone who audits should be able to explain how they make their money.

Transparency

If we identify a vulnerability or incident affecting you during an engagement, we tell you immediately and in writing — even when it falls outside the agreed scope, and even when the news is unwelcome.

Documentation

Additional documentation under NDA

We can provide further detail on our internal security measures, forensic procedures and applied controls under a confidentiality agreement.