How we access your server
We connect over SSH using a key pair dedicated to your account. You add our public key; you can remove it at any time and our access ends immediately. We never ask for passwords by email or web form, and we never store your hosting or WordPress passwords in our ticketing or email systems.
- Least privilege: we request the minimum access needed for the job and explain why before we ask for more.
- Named engineers: only members of the PatientZero incident team connect to customer servers.
- Revocation: removing our key from
~/.ssh/authorized_keysrevokes access instantly. We confirm revocation in writing when an engagement ends, if you ask.
What the scan engine does
The PatientZero scan engine is deployed to /opt/patient-zero/scan-engine on your server and runs scans locally. Scans are read-only: nothing is changed until a finding has been verified by our team and a Fix or Harden action is run.
# deployed path
/opt/patient-zero/scan-engine
# profiles
dfir-fast # forensic scan: persistence, users, cron, sockets
malware-intelligence # malware sweep: every site, every fileWhat data leaves your server
Scans run on your server. What comes back to us is findings and metadata: file paths, hashes, timestamps, matched indicators and scan logs, so we can verify and report on them. Quarantined malware samples are kept in an evidence vault with their hashes so you have proof of what was removed.
We do not copy your databases, customer records or site content off the server as part of routine scanning. If a sample of a file is needed for analysis, we tell you what and why.
Encryption and retention
- All connections to your server use SSH. All connections to this website and our systems use TLS.
- Reports and evidence packages are stored encrypted and shared with you over secure links.
- Findings, reports and evidence are retained for the life of your plan so we can compare scans over time, then deleted on request or after the retention period agreed in your terms.
Audit logs
Every action on your server is recorded in the Activity log: who connected, when, which scan ran, what was quarantined, restored or hardened. The log is part of your report, and is the evidence trail you need for clients, insurers or the ICO.
How we secure this website
A security company’s own website should be exemplary. This site is hand-built with no WordPress and no third-party plugins. It uses HTTPS only with HSTS, a strict Content-Security-Policy with no inline scripts, and hardened security headers. Forms are protected by signed tokens, rate limiting, strict validation and bot checks.
And yes: this site is scanned by PatientZero.
Responsible disclosure
If you believe you have found a security vulnerability in this website or our services, please email repair@patientzerosolutions.co.uk with the subject “Security disclosure”. Please give us reasonable time to fix the issue before public disclosure, and don’t access or modify data that isn’t yours. Our security.txt has the details.