KrakenIO Data Handling Policy
KrakenIO is committed to handling data responsibly in our cybersecurity work. This policy governs how we collect threat intelligence and manage exposed data across all our activities, and it applies to every employee, contractor, and third party acting on KrakenIO's behalf. Its purpose is simple: all data handling serves legitimate cybersecurity purposes, in compliance with the SHIELD Act, federal law, and the ethical standards we hold ourselves to.
Principles of Data Handling
- Legitimate Use: Data handling, including intelligence gathering, is conducted solely for legitimate cybersecurity purposes, protecting our clients and the wider community, never with intent to commit any criminal violation.
- Compliance with Laws: KrakenIO adheres to the SHIELD Act in safeguarding data such as leaked credentials, the CFAA and ECPA in avoiding unauthorized access to systems and communications, and the FTC Act and New York GBL Section 349 in representing our work honestly, including the use of public data in OSRA demonstrations.
- Ethical Considerations: Data is secured while in use, applied only to the client protection purpose it was gathered for, and erased when that purpose ends, unless retention is required by law.
Handling Breach Data and Cyber Threat Intelligence
Exposed and breach data is part of how OSRA finds what attackers would find. Our handling of it is informed by guidance from the U.S. Department of Justice on gathering cyber threat intelligence. Information is collected passively and used solely for defensive purposes, helping clients understand and reduce their exposure. KrakenIO does not purchase stolen data, does not solicit or encourage criminal activity, and does not provide information or assistance to threat actors. What we collect exists because it is already exposed. Our role is to make sure our clients know before someone else uses it against them.
Frequently Asked Questions
Kraken IO provides cybersecurity solutions to businesses across diverse sectors, including medical practices, restaurants, real estate firms, and IT service providers. We focus on protecting businesses that are often the most vulnerable to cyber threats. Our services are Core, our approach to building and maintaining secure company websites, Operational Security Risk Audits (OSRA), Integrated Security Analytics Solutions (ISAS), and Ransomware Defense and Simulation. Each engagement is tailored to the client, so every business receives protection built around its actual risk.
We tailor our services to meet the needs of startups, mid-sized companies, and large enterprises, offering practical solutions at accessible prices. Our Match or Lower Pricing Policy ensures the best value for your investment. If you provide a verifiable quote from a competitor with a detailed scope and pricing breakdown, our team will review it and match the price for comparable services, or lower ours when feasible. Affordability never affects quality. We deliver industry standard solutions that balance cost with uncompromised results.
OSRA is a comprehensive assessment that identifies vulnerabilities and provides actionable insights, helping businesses strengthen their cybersecurity posture. It has two main components. Intelligence Analysis evaluates breaches, exposed credentials, and operational security. Technical Assessment conducts non-intrusive scans and delivers detailed solutions for the vulnerabilities found. Clients receive clear reports, including follow-up reports that highlight progress and improvements from implemented measures. The result is a holistic view of your risks, so decisions are informed, precise, and aligned with your organization's risk profile.
ISAS is a real-time cybersecurity solution that integrates threat analytics, automated policies, and endpoint protection to detect and mitigate threats. Its key features include endpoint protection with HIPS, tripwires, and canary tokens, network security with DNS control and firewall optimization, and threat intelligence with continuous updates to malicious path directories and IOC libraries. ISAS is designed for businesses of all sizes and provides robust protection without requiring a full Security Operations Center team, which makes it especially practical for small businesses.
We enforce strict Non-Disclosure Agreements to secure all shared information, findings, and methodologies. Client identities and service details remain strictly confidential. Before any engagement, we define a clear project scope, which ensures accurate pricing and solutions tailored to your infrastructure, risk profile, and operational needs. All data we handle is governed by our Data Handling Policy above. We also provide training programs to help clients understand threats and adopt effective prevention and mitigation strategies.