Trust & Security
A cybersecurity company should be held to at least the same standard it holds its clients to. This page explains how we handle client information, how we approach security testing ethically, and what to do if you find a problem with our own systems.
Data Handling
Client data collected during an engagement, network details, credentials shared temporarily for testing, findings, and reports, is used only for the purpose of that engagement, stored with access limited to the team members working on it, and retained only as long as needed to deliver the service and meet any agreed reporting or compliance obligations.
Confidentiality
Engagement details, findings, and any data encountered during an assessment are confidential by default. We don't disclose client identities or specifics without permission, which is why our published case studies are anonymized and generalized rather than naming clients directly.
Security Testing Ethics
Every penetration test and security assessment runs within written rules of engagement agreed with the client in advance, defined scope, defined boundaries, and a clear stop condition. We stop short of anything genuinely destructive: we'll demonstrate that a vulnerability grants access without exfiltrating or altering data, and we won't take down a production system to prove a point that can be shown safely.
Responsible Disclosure
We hold ourselves to the same disclosure standard we ask of anyone reporting a vulnerability in our own systems: report privately, give reasonable time to fix it, and coordinate on public disclosure. Findings from client engagements affecting third-party software are disclosed to the vendor responsibly, not published for attention. Read our full responsible disclosure policy.
Access Controls
Internally, access to client systems, credentials, and engagement data is limited to the team members actually working on that engagement, protected with multi-factor authentication, and logged. Access granted for a specific engagement is removed once that engagement ends.
Incident Handling
If we ever identified a security issue affecting our own systems or a client's data as a result of something on our end, our commitment is straightforward: contain it, assess what was actually affected, notify anyone impacted without unnecessary delay, and be direct about what happened and what we're doing about it, the same standard we'd expect from any vendor we relied on.
Privacy
Information submitted through this website (contact forms, inquiries) is handled according to our Privacy Policy, which explains what we collect, why, and the choices you have.
Client Information
We don't sell, rent, or share client information with third parties for marketing purposes. Information is shared outside our team only where necessary to deliver a service (for example, a specialized subcontractor on a specific engagement, disclosed to the client in advance) or where required by law.
Security Practices
We apply the same fundamentals we recommend to clients to our own environment: MFA on administrative and remote access, patched and monitored systems, tested backups, and least-privilege access internally. We don't ask a client to do something we haven't already done ourselves.
Contact Security
To report a security issue with our own systems, email security@cyberisolve.com or see our security.txt file. For anything else, use our general contact page.
Questions about how we handle your data?
Ask before you sign, not after, we're glad to walk through any of this in more detail.