Security & Data Protection

Your data is your most valuable asset. We protect it like our own Encrypted end-to-end, stored where you choose, and never shared.

SOC 2 Compliant
256-bit Encryption
99.9% Uptime SLA
ISO 27001

What We Protect

Cyberity only collects the evidence necessary for compliance. Here is exactly where the line is drawn.

We Collect

Only what compliance requires. Nothing more.

  • Backup verification results
  • Server health metrics
  • Configuration snapshots
  • Security logs & alerts
  • Compliance check results
  • Audit trails & timestamps

We Never Collect

Your sensitive data stays out of reach.

  • Passwords or credentials
  • User personal data (PII)
  • Email content
  • File contents
  • Customer data
  • Anything not needed for proof

We Never Share

No third parties. No exceptions.

  • Data with third parties
  • Data with advertisers
  • Data with other customers
  • Data with government (unless required by law)
  • Data without your consent
  • Unencrypted data over the internet

How Your Data Flows

Local collection, encrypted transmission, secure storage — a three-layer architecture you can audit at every step.

Inside your network

Layer 1

Local Agent

Your Infrastructure

A lightweight, auditable agent runs on your servers and collects only what compliance requires.

1
Reads logs
2
Checks configs
3
Verifies backups
Nothing leaves your network unencrypted

Crossing the boundary

Layer 2

Encrypted Transport

Your Network to Cloud

Evidence is sealed before it moves. Keys never leave your control, and you can audit every transfer.

1
AES-256 encrypt at source
2
TLS 1.3 tunnel
3
IP whitelisting
Keys stay in your control

At rest, your choice

Layer 3

Secure Storage

Your Choice of Cloud

Encrypted evidence lands on SOC 2 Type II certified infrastructure — ours, or your own cloud account.

1
SOC 2 certified provider
2
Or your AWS / Azure / GCP
3
Zero-knowledge: we can't read it
Delete or export anytime

Auditable at every step — agent code, transport logs, and storage are all open to your review.

Encryption everywhere

Enterprise-grade security, not optional

Every byte is encrypted, signed, and timestamped. We hold ourselves to the same standards we help you prove.

Data at Rest

AES-256 encryption on all stored data.

Data in Transit

TLS 1.3 for all network communication.

Evidence Ledger

Hash-chained with Ed25519 signatures for tamper-proof proof.

Backups

Encrypted at source before any transmission.

Audit Logs

Immutable, encrypted, and timestamped for compliance.

Compliance & Certifications

Cyberity is built for compliance — the same standards required by ISO 27001, SOC 2, PDPA, and other frameworks we help you prove.

SOC 2 Type II

Annual audit of our security controls.

ISO 27001

Information security management system certified.

GDPR / PDPA Compliant

Data processing agreements available.

No Vendor Lock-In

Your data can be exported anytime.

Common Questions

Real questions IT managers ask. Real answers.

What if there's a security breach?

We notify you within 48 hours and give you access to our SOC 2 audit reports. Your data sits on tier-1 providers with 99.99%+ uptime and 24/7 monitoring. Encrypted data is unreadable even if breached, and our insurance covers data protection liability.

Will the agent slow down our systems?

Less than 2% CPU overhead. The agent runs lightweight, read-only queries with no data modification, on a schedule you control (default: hourly). It can be paused anytime.

Can we audit your code?

Yes. Independent security audits are available, and we provide source code review for enterprise contracts. You can verify the encryption implementation, and agent logs show exactly what data was collected.

What about data residency?

You choose your provider and region — AWS, Azure, Google Cloud, or Cloudflare, in the region you need (EU, US, APAC, etc.), or your own cloud account. This complies with local data-protection laws and is covered in our agreements.

Can we delete our data?

Anytime, no questions asked. Request deletion and we remove all encrypted data within 30 days. Your evidence ledger can be exported first — full compliance with GDPR/PDPA deletion rights.

Where is my data stored?

On the cloud you choose. Managed storage runs on SOC 2 Type II certified infrastructure, or bring your own AWS, Azure, or Google Cloud account so backups and evidence never leave your control. Either way it's encrypted, and yours to export or delete anytime.

Trust & Transparency

You should know exactly how we protect your data. Here is everything we hand over — on request.

Security assessment report
Data processing agreement (DPA)
SOC 2 Type II audit results
ISO 27001 certification
Encryption documentation
Agent code review access
Breach notification (48 hrs)
Cyber insurance coverage
Full documentation package available under NDA — just ask.

See the Evidence for Yourself

Request our security assessment report, SOC 2 results, and DPA. Bring your toughest questions — we answer all of them.

No credit card required
Cancel anytime
SOC 2 Compliant
256-bit Encryption
99.9% Uptime SLA
ISO 27001