Skip to main content
STAGING - not for external sharing

Security

What a security or procurement review asks first, answered here. Fuller documentation follows under a non-disclosure agreement.

Who you contract with

Contracting entity
You contract with Obscurity Ltd, an Irish company trading as ConsentMark.
Company registration
Its Companies Registration Office number is 622475.
VAT number
Its VAT number is IE3526981EH, checkable on the European Commission VIES service.
Registered office
Its registered office is 71 Lower Baggot Street, Dublin 2, D02 P593, Ireland.
Jurisdiction
Contracts are governed by the law of the Republic of Ireland.

Our role in each processing activity, controller or processor, is in section 1 of the privacy policy.

Data location and protection

ConsentMark's application database is hosted in AWS in Dublin, Ireland. No copy of stored evidence leaves the EU. Both evidence buckets carry a policy statement that denies replication to every principal, including the account root, and the database is single-region in eu-west-1. Data is encrypted at rest under customer-managed AWS KMS keys, rotated annually, and in transit over TLS 1.3 only. A client that cannot negotiate TLS 1.3 cannot connect. Sign-in is by passkey or a one-time code sent to your email address; there are no passwords.

Each governance record is signed by AWS KMS over its canonical JSON form, and carries the signature, the hash, the key identifier and the signing time. Once written, an evidence record cannot be altered or deleted by the application. Stored evidence sits under AWS S3 Object Lock in compliance mode, so it cannot be deleted, and its retention cannot be shortened, before it expires. Compliance mode binds the account root and AWS itself. It applies to the governance evidence bucket, and to the scan evidence bucket for everything written from 7th September 2026. The Monitor loads pages only on a site your organisation has proved it owns. A site is a domain and its subdomains, up to 100 pages.

What we keep, and for how long

Every window we hold, by data category, is in the privacy policy under Retention.

Sub-processors

Every recipient of your data, what it does and where the data sits, is in section 6 of the privacy policy.

Assurance and insurance

ConsentMark is not SOC 2 certified. Our control documentation answers the standard vendor security questionnaires and goes out under that agreement. Professional indemnity insurance is held, and we send the certificate on request.

Incidents

If a security incident affects your data, we tell you within 24 hours of becoming aware of it.

Reporting a vulnerability

Security issues go to contact@consentmark.com, published at /.well-known/security.txt under RFC 9116. Send the affected address, the steps that reproduce the issue and what you observed. Dónal Troddyn is the named responder, in the Data Processing Agreement and the Master Services Agreement. We do not pursue researchers who report responsibly. The websites ConsentMark monitors or scans belong to their owners and are out of scope - we cannot authorise a test against them.

Documentation and contact

The posture document, the questionnaire answers and the scanner abuse controls go out the same way.

For anything not answered here, write to contact@consentmark.com.

Disputing a public scan result

A dispute about a public scan result, including its accuracy and its removal, goes to contact@consentmark.com. Dónal Troddyn reads every dispute, and we amend or retract findings where the evidence is contested.

Last reviewed 25th September 2026.