Credentials
Founded 2018 · 30 professionals · 100+ clients.
Third-party certifications
Certified to ISO/IEC 27001, ISO 9001 and ISO 14001. All three certificates are available on request, with public certificate numbers and validity so anyone can verify them:
ISO/IEC 27001:2022, no. CI 9765-ES, valid until 4 March 2029
ISO 9001:2015, no. 00409, valid until 19 March 2029
ISO 14001:2015, no. 00328, valid until 19 March 2029
Catalogues and memberships
Listed in the INCIBE catalogue · CIS SecureSuite Member · AMETIC member (Cybersecurity, AI, Cloud committees) · Women4Cyber Spain associate member.
Data protection
We have a Data Protection Officer appointed and registered with the Spanish Data Protection Agency (AEPD), reachable at dpo@mineryreport.com.
We don't list what we can't show.
How we work
How we protect client information
- NDA on every engagement, signed before work begins
- Least privilege and need-to-know access
- Encrypted channels for all sensitive transfers
- Environment segregation in our own operations
- Secure destruction of evidence and temporary data at project close, unless legally required or otherwise agreed
- Full traceability of actions performed
Methodologies
- CIS Controls v8 as the basis of our maturity assessments
- CCN-STIC guidance (Spanish National Cryptologic Centre) for ENS and hardening work
- PTES, OSSTMM and OWASP in offensive security
- Documented chain of custody in all forensic work
- GDPR compliance in any personal data processed on a client's behalf
Incident response and availability
Incident response available year-round, with documented escalation and communication procedures, coordination with authorities and court-appointed experts where required, and a complete record of all actions taken. For commercial enquiries, a partner responds within one hour, during business hours.
Commitments
Vendor agnosticism
We are not tied to any manufacturer. We work with multiple technologies and recommend based on the client's risk, not on a catalogue. Our audits never end in a predetermined shopping list.
We are part of a business group that includes a separate company dedicated to systems and technology supply. Separate companies, separate teams — and one rule that is not negotiable: Minery Report's audits and recommendations favour no one's product, including within the group. We state this here because transparency about a corporate relationship is worth more than silence: anyone who audits should be able to explain how they make their money.
Transparency
If we identify a vulnerability or incident affecting you during an engagement, we tell you immediately and in writing — even when it falls outside the agreed scope, and even when the news is unwelcome.
Documentation
Additional documentation under NDA
We can provide further detail on our internal security measures, forensic procedures and applied controls under a confidentiality agreement.


