CyberTwin
TRUST // VERIFY OUR WORK

Don't trust the report. Re-check it.

Every attack path, every dollar figure, every no-path verdict CyberTwin produces ships as a signed proof bundle. Drop it into the verifier and your own browser recomputes the hash chain and re-runs the reachability check. We can't see what you check. Nothing is taken on faith.

NO AGENTNO LIVE SCANSIGNED · Ed25519RE-CHECKABLE IN-BROWSER
(01)ANATOMY OF A SIGNED PROOF
PROVENRE-CHECKABLE
CONFIG EXPORTESTATE UPLOADe3b0c4…SHA-2569a5f21…SHA-2564d7ec8…SHA-256IMMUTABLEHASH CHAINPRIVATE KEYEd25519 SIGNATUREYOUR BROWSERRE-CHECK · PROVEN
UPLOAD, NEVER SCANNED

You export a config and send it. The engine never reaches into your network.

SEALED, NOT ASSERTED

The bundle is hashed and signed with an Ed25519 key — tamper it and the check fails.

CHECKED IN YOUR BROWSER

The verifier runs client-side. We never see what you re-check, and nothing uploads.

SCHEMATIC — HASHES SHOWN ARE ILLUSTRATIVE

VERIFY A REAL PROOF BUNDLE
6
Live controls in production
8
Subprocessors, all disclosed
24h
Vuln-disclosure acknowledgement
0
Fabricated figures — ever
(02)THE POSTURE

We never touch your live environment.

Most security tools ask you to install an agent and hand over standing access. CyberTwin asks for a file. That difference is the whole posture — there is nothing of ours inside your walls, and no live blast radius to worry about.

(01)AGENTLESS

Nothing to install

No agent, no sensor, no long-lived credential sitting inside your network. There is nothing of ours running on your machines to compromise, patch, or trust.

(02)UPLOAD — NEVER SCANNED

You hand us the file

We never reach into your environment. You export a config — a firewall rule set, a cloud snapshot, an identity dump — and upload it. The engine reasons over the file you chose to send. Nothing is scanned, probed, or connected live.

(03)NO STANDING ACCESS

No credentials of yours on our side

CyberTwin is upload-based: there is no connector to configure and no key of yours stored with us. Each review starts from a file you chose to hand over, and secrets in it are redacted in memory before anything is written to disk.

(03)YOUR DATA

How we handle your data.

The short version. The full Privacy Policy and Data Processing Agreement are linked at the bottom of this page — this is the plain-language summary of what we take, how long we hold it, and what stays yours.

(01)COLLECT

What we collect

Account details, the environment data you upload, and operational logs. Marketing pages report conversion events (which button was used, no identity) to our own server and load the LinkedIn Insight Tag for ad attribution — the one third-party cookie on the site, disclosed with an opt-out in the privacy policy. The signed-in app sets session cookies only.

(02)RETAIN

How long we keep it

While your account is active. After cancellation the account is read-only for 90 days so you can export, then retained a further 90 days for re-activation before deletion — 180 days total. Audit logs are kept 12 months; billing records as tax law requires.

(03)RIGHTS

Your rights

Access, correction, deletion, and portability on request — email privacy@cybertwin.io and we respond within 30 days. You own the artifacts the engine produces.

(04)RESIDENCY

Data residency

Need your data to live in a specific region? Region-pinned residency is available on Enterprise — contact us to scope it for your organisation.

(04)THE CONTROLS WE RUN

We sell security advice. We run it on ourselves.

The technical measures protecting customer data, in plain language. Every one is live in production today — present tense, no roadmap promises.

CTRL-01

Encryption, in transit and at rest

TLS 1.2 or higher everywhere with HSTS preload. Data encrypted at rest.

CTRL-02

Authentication

Clerk for password and session security; SSO/SAML for Enterprise. MFA enforced on every operational admin account. No custom auth code.

CTRL-03

Tenant isolation

Every query is scoped to the customer's organisation. Cross-tenant boundaries are enforced in code and covered by a dedicated isolation test suite.

CTRL-04

Audit log

A timestamped record of every data-modifying action, available in-product to your org admins and exportable as CSV.

CTRL-05

Secrets management

Secrets live in Fly's managed secret store and reach the app only at runtime — never in source. Every push is scanned for leaked credentials in CI (gitleaks).

CTRL-06

Read-only by design

CyberTwin is upload-based today. If read-only integrations ship, connectors use scope-minimum credentials encrypted at rest with a server-side key (AES-256-GCM), with every sync logged.

(05)STANDARDS

What our program aligns with.

Our security program is built to map onto the criteria customers ask about — so your diligence lands on familiar ground.

SOC 2

Aligned

Controls built to the SOC 2 Trust Services Criteria — security, availability, and confidentiality.

GDPR / UK-GDPR

Aligned

A Data Processing Agreement, a public subprocessor register, and export and deletion on request.

ISO 27001

Aligned

An information-security management approach modelled on the ISO 27001 control set.

Secure SDLC

Practice

OWASP-guided development, dependency and secret scanning on every change, least-privilege access throughout.

ALIGNED = OUR CONTROLS FOLLOW THE CRITERIA. IT IS NOT A CLAIM OF CERTIFICATION.

(06)SUBPROCESSORS

Who we share data with — all of them.

Every third party that processes customer data on our behalf, and exactly what each one touches. We notify customers in writing before adding a subprocessor.

SubprocessorPurposeData accessed
Fly.ioApplication hosting, compute, and the persistent volume holding the database. The sole processor of customer data at rest.All account, environment, finding, and audit-log data; uploaded documents
AnthropicAI analysis via the Claude API — report narrative, intake follow-up questions, document and diagram analysis, copilot question compilation, and optional configuration-review commentaryProfile metadata (industry, size, region, frameworks, budget ceiling) and structured engine output; the free-text intake answers and copilot questions you type; the text, tables and images of documents you choose to upload for document analysis or diagram extraction; and, if you switch on AI commentary for a configuration review, a digest of its findings (check id, severity, title, config section) rather than the configuration file itself. Under Anthropic’s Commercial Terms, Anthropic does not train models on customer content sent through the API.
ClerkAuthentication, session management, SSO/SAMLAuth identifiers (email, hashed password, MFA factors)
PolarPayment processing and subscription billing (merchant of record — Polar takes the payment and handles VAT; card details never touch CyberTwin)Billing identity (name, email, company), payment method, subscription and invoice records
ResendTransactional emailRecipient email addresses, message content
SentryError monitoringError message, stack trace and request metadata (route, record ids), scrubbed in our code before the send: email addresses, bearer/API tokens and secret-looking values are redacted; user, org and session identifiers are replaced with short one-way hashes; any field named like a raw upload, config, document or text body is dropped; every string is truncated.
PostHogMarketing-site product analytics (EU Cloud)Marketing-page behaviour only. Loaded on public pages exclusively — never inside the authenticated product, so no environment, finding, or exposure data reaches it.
LinkedInAd conversion measurement and audience building (Insight Tag)Marketing-page visit signals for ad attribution. Public pages only — the tag never loads inside the authenticated product.
DISCLOSURE

Found a vulnerability?

Email security@cybertwin.io. We acknowledge within 24 hours and aim to triage within 72. Our public security.txt lives at /.well-known/security.txt.

DILIGENCE

Request the security pack

Email us and we'll send the DPA, the subprocessor list, our encryption-in-transit certificate, and an infrastructure architecture overview. Typical turnaround: same business day.