Don't trust the report. Re-check it.
Every attack path, every dollar figure, every no-path verdict CyberTwin produces ships as a signed proof bundle. Drop it into the verifier and your own browser recomputes the hash chain and re-runs the reachability check. We can't see what you check. Nothing is taken on faith.
You export a config and send it. The engine never reaches into your network.
The bundle is hashed and signed with an Ed25519 key — tamper it and the check fails.
The verifier runs client-side. We never see what you re-check, and nothing uploads.
SCHEMATIC — HASHES SHOWN ARE ILLUSTRATIVE
VERIFY A REAL PROOF BUNDLE →Most security tools ask you to install an agent and hand over standing access. CyberTwin asks for a file. That difference is the whole posture — there is nothing of ours inside your walls, and no live blast radius to worry about.
Nothing to install
No agent, no sensor, no long-lived credential sitting inside your network. There is nothing of ours running on your machines to compromise, patch, or trust.
You hand us the file
We never reach into your environment. You export a config — a firewall rule set, a cloud snapshot, an identity dump — and upload it. The engine reasons over the file you chose to send. Nothing is scanned, probed, or connected live.
No credentials of yours on our side
CyberTwin is upload-based: there is no connector to configure and no key of yours stored with us. Each review starts from a file you chose to hand over, and secrets in it are redacted in memory before anything is written to disk.
The short version. The full Privacy Policy and Data Processing Agreement are linked at the bottom of this page — this is the plain-language summary of what we take, how long we hold it, and what stays yours.
What we collect
Account details, the environment data you upload, and operational logs. Marketing pages report conversion events (which button was used, no identity) to our own server and load the LinkedIn Insight Tag for ad attribution — the one third-party cookie on the site, disclosed with an opt-out in the privacy policy. The signed-in app sets session cookies only.
How long we keep it
While your account is active. After cancellation the account is read-only for 90 days so you can export, then retained a further 90 days for re-activation before deletion — 180 days total. Audit logs are kept 12 months; billing records as tax law requires.
Your rights
Access, correction, deletion, and portability on request — email privacy@cybertwin.io and we respond within 30 days. You own the artifacts the engine produces.
Data residency
Need your data to live in a specific region? Region-pinned residency is available on Enterprise — contact us to scope it for your organisation.
The technical measures protecting customer data, in plain language. Every one is live in production today — present tense, no roadmap promises.
Encryption, in transit and at rest
TLS 1.2 or higher everywhere with HSTS preload. Data encrypted at rest.
Authentication
Clerk for password and session security; SSO/SAML for Enterprise. MFA enforced on every operational admin account. No custom auth code.
Tenant isolation
Every query is scoped to the customer's organisation. Cross-tenant boundaries are enforced in code and covered by a dedicated isolation test suite.
Audit log
A timestamped record of every data-modifying action, available in-product to your org admins and exportable as CSV.
Secrets management
Secrets live in Fly's managed secret store and reach the app only at runtime — never in source. Every push is scanned for leaked credentials in CI (gitleaks).
Read-only by design
CyberTwin is upload-based today. If read-only integrations ship, connectors use scope-minimum credentials encrypted at rest with a server-side key (AES-256-GCM), with every sync logged.
Our security program is built to map onto the criteria customers ask about — so your diligence lands on familiar ground.
SOC 2
AlignedControls built to the SOC 2 Trust Services Criteria — security, availability, and confidentiality.
GDPR / UK-GDPR
AlignedA Data Processing Agreement, a public subprocessor register, and export and deletion on request.
ISO 27001
AlignedAn information-security management approach modelled on the ISO 27001 control set.
Secure SDLC
PracticeOWASP-guided development, dependency and secret scanning on every change, least-privilege access throughout.
ALIGNED = OUR CONTROLS FOLLOW THE CRITERIA. IT IS NOT A CLAIM OF CERTIFICATION.
Every third party that processes customer data on our behalf, and exactly what each one touches. We notify customers in writing before adding a subprocessor.
| Subprocessor | Purpose | Data accessed |
|---|---|---|
| Fly.io | Application hosting, compute, and the persistent volume holding the database. The sole processor of customer data at rest. | All account, environment, finding, and audit-log data; uploaded documents |
| Anthropic | AI analysis via the Claude API — report narrative, intake follow-up questions, document and diagram analysis, copilot question compilation, and optional configuration-review commentary | Profile metadata (industry, size, region, frameworks, budget ceiling) and structured engine output; the free-text intake answers and copilot questions you type; the text, tables and images of documents you choose to upload for document analysis or diagram extraction; and, if you switch on AI commentary for a configuration review, a digest of its findings (check id, severity, title, config section) rather than the configuration file itself. Under Anthropic’s Commercial Terms, Anthropic does not train models on customer content sent through the API. |
| Clerk | Authentication, session management, SSO/SAML | Auth identifiers (email, hashed password, MFA factors) |
| Polar | Payment processing and subscription billing (merchant of record — Polar takes the payment and handles VAT; card details never touch CyberTwin) | Billing identity (name, email, company), payment method, subscription and invoice records |
| Resend | Transactional email | Recipient email addresses, message content |
| Sentry | Error monitoring | Error message, stack trace and request metadata (route, record ids), scrubbed in our code before the send: email addresses, bearer/API tokens and secret-looking values are redacted; user, org and session identifiers are replaced with short one-way hashes; any field named like a raw upload, config, document or text body is dropped; every string is truncated. |
| PostHog | Marketing-site product analytics (EU Cloud) | Marketing-page behaviour only. Loaded on public pages exclusively — never inside the authenticated product, so no environment, finding, or exposure data reaches it. |
| Ad conversion measurement and audience building (Insight Tag) | Marketing-page visit signals for ad attribution. Public pages only — the tag never loads inside the authenticated product. |
Found a vulnerability?
Email security@cybertwin.io. We acknowledge within 24 hours and aim to triage within 72. Our public security.txt lives at /.well-known/security.txt.
Request the security pack
Email us and we'll send the DPA, the subprocessor list, our encryption-in-transit certificate, and an infrastructure architecture overview. Typical turnaround: same business day.