Who We Are

A Defender's Doctrine

We assume one thing by default — data is lost because security failed somewhere. Everything we do follows from that assumption.

STROJAN
5+ Years in the field
The Position

A Defender's Mindset in a Hostile Landscape

STROJAN is a cybersecurity-driven data recovery entity. We assume one thing by default — data is lost because security failed somewhere.

Every device we handle is treated as a potential breach, and every recovery is executed as a controlled cyber operation rather than a repair job.

We follow zero-trust principles, read-only methodologies and ethical software-based recovery practices. No hardware tampering. No shortcuts. No fear-based selling.

When recovery is not feasible, we say so — in writing, on day one. That honesty is the product.

  • Read-only forensic imaging before any analysis
  • Written feasibility report before any payment
  • NDA and chain-of-custody on every engagement
  • Zero data retention after verified handover
0 Devices Assessed
0 First Response
0 Original Media Modified
0 Confidential Handling
Boundaries

What We Will Not Do

An ethics statement is only meaningful if it costs you work. These are the engagements we turn down.

No unauthorised access

We do not access any system, account or device without documented authorisation from its verified owner. No exceptions, regardless of the story.

No surveillance work

We do not perform covert monitoring of individuals, partner tracking, or any activity designed to violate a person's privacy.

No fear-based selling

We will not inflate urgency, invent hardware failures, or quote a price before diagnosis to pressure a decision.

No hardware tampering

We are software-only. We will not open a drive, swap heads or experiment physically on media we cannot restore.

No guaranteed outcomes

We will not promise recovery before imaging the media. Anyone who does is selling certainty they do not have.

No data as leverage

We do not hold recovered data hostage against payment disputes, and we do not retain copies after handover.

Operating Principles

How We Work

Zero-Trust By Default

Every device that reaches us is treated as a potential breach until proven otherwise. Nothing is assumed clean.

Read-Only, Non-Invasive

We image first and work on the copy. Your original media is never written to, opened, or physically altered.

No False Guarantees

Nobody can promise 100% recovery. We give you a written feasibility verdict before you pay anything.

NDA & Chain of Custody

Signed confidentiality on every engagement, with documented handling from intake to verified handover.

Zero Data Retention

Once you confirm handover, working copies are securely wiped. We do not keep your data as leverage.

Ethical Practice Only

No unauthorised access, no surveillance work, no engagement without documented consent from the asset owner.

Engagement Protocol

The Five Checkpoints

01

Secure Intake

You describe the incident. We sign an NDA, log the device, and tell you immediately what NOT to do next.

02

Read-Only Diagnosis

A hash-verified forensic image is created. All analysis happens on the copy — the original is sealed and untouched.

03

Honest Feasibility Report

You receive a written verdict: what is recoverable, what is not, what it costs. If nothing is recoverable, you pay nothing.

04

Controlled Operation

On your approval, recovery runs as a documented operation with checkpoints — not a black box you wait outside of.

05

Verified Handover

You validate the recovered data before we close. Working copies are then securely destroyed and the log is signed off.

Work with people who tell you the truth

Even when the truth is that you should not pay us.