LEGAL & GOVERNANCE

Legal Framework & Governance

RawSecLabs operates under a comprehensive legal and governance framework aligned with international cybersecurity standards, regulatory requirements, and industry best practices.

Our Framework

Governance Structure

Corporate Governance

RawSecLabs Limited is registered in the United Kingdom at 124 City Road, London, EC1V 2NX. The company operates under UK company law and maintains appropriate corporate governance structures.

Security Governance

Our security governance framework aligns with NIST Cybersecurity Framework, ISO 27001, and industry best practices for offensive security service providers.

Data Governance

Data handling practices governed by GDPR, UK Data Protection Act 2018, and applicable international data protection regulations with robust data classification and access controls.

Compliance Alignment

Regulatory & Industry Standards

International Standards

  • ISO 27001:2022 - Information Security Management System certified by UKAS-accredited body
  • ISO 9001:2015 - Quality Management System for consistent service delivery
  • Industry Frameworks - All operations align with globally recognized penetration testing best practices (OSSTMM, OWASP, and NIST).
  • PCI DSS Standards - Technical testing maps directly to the PCI Security Standards Council controls to facilitate client compliance.

Regional Compliance

  • UK GDPR & Data Protection Act 2018 - Full compliance for UK data processing
  • EU GDPR - Compliance for EU data subjects with appropriate data transfer mechanisms
  • DORA - Digital Operational Resilience Act compliance for financial sector clients
  • NIST CSF & SP 800-115 - US federal standards alignment for American clients
Security Commitments

Data Protection & Security

Data Protection Principles

  • Lawful, fair, and transparent processing
  • Purpose limitation and data minimization
  • Accuracy and data quality maintenance
  • Storage limitation and retention policies
  • Integrity and confidentiality by design

Security Measures

  • End-to-end encryption for sensitive data
  • Strict access controls and authentication
  • Regular security audits and penetration testing
  • Comprehensive incident response procedures
  • Staff security training and awareness programs

RawSecLabs maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services, the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

Legal & Governance Inquiries

For questions about our legal framework, compliance, or governance practices, please contact our legal team.

Contact Legal Team