Editorial policy

How we produce our content

This page explains who signs what we publish on secra.es, how each topic is chosen and documented, what role artificial intelligence tools play and how we correct what is wrong. We wrote it so that any reader, client or search engine can check the standard we work to.

Who writes and reviews

All technical content on this site is written and reviewed by the three founders of Secra Solutions. All three work daily on penetration testing, red team and compliance engagements, and each published piece is signed by one of them.

How a topic is chosen

  • We only write about what the team works on in real engagements: penetration testing, red team operations, compliance with ENS, NIS2, DORA and ISO 27001, and the tools we use or build.
  • A topic enters the calendar when it answers a question clients ask us, a finding that keeps coming up in audits, or a regulatory change that affects Spanish and European companies.
  • We discard topics where we have no direct experience, even if they have search volume. We prefer to publish less and be able to defend every claim.

How it is documented

Every article starts from primary sources and, where possible, from our own data:

  • Regulation and official guidance: BOE, OJEU, CCN-CERT, INCIBE, ENISA and the consolidated texts of ENS, NIS2, DORA and ISO 27001.
  • Frameworks and technical references: MITRE ATT&CK, OWASP, CISA, NIST and the documentation of the vendors involved.
  • Our own data: lab results, proofs of concept reproduced by the team and findings from engagements, always anonymised and with the client's authorisation where required.
  • Sources are cited in the article itself. If a claim cannot be backed by a verifiable source or by our own testing, it is not published.

Use of artificial intelligence assistance

  • The team uses AI tools as support for drafting, structuring and translating between Spanish and English.
  • Every published piece is signed by, and is the responsibility of, a member of the team. AI is not the author of any content on this site.
  • No data, command, regulatory reference or technical claim is published without human review by a certified professional.
  • Content that does not meet this standard is removed from the index and either corrected or deleted.

Corrections and updates

  • Every article shows its publication date and, when it has been modified, its update date. Articles reviewed by a second member of the team also show the reviewer's name and the review date.
  • We periodically review content that depends on regulation or software versions and update or withdraw what has become outdated.
  • If you spot an error, an inaccuracy or an outdated source, write to devs@secra.es. We review every report and correct what is needed, stating the date of the change.

What we do not do

  • We do not publish mass-produced content or articles written solely to rank for keywords.
  • We do not accept sponsored content without clearly labelling it as such. We currently publish none.
  • We do not publish vulnerability details without following a responsible disclosure process with the vendor or the affected party.
  • We do not copy or rewrite third-party content and present it as our own.

For any question about this policy you can write to devs@secra.es.

Last updated: September 2026

👋Hi! Have any questions? Write to us, we reply in minutes.

Open WhatsApp →