Home · Resources · Trust Center

Trust, documented.

CyberCI operates as a security partner to organizations with stringent regulatory and contractual obligations. This page documents the controls, certifications, and practices that support that role.

— Compliance

Certifications and attestations.

Documentation, audit reports, and ongoing assessment activity. Most reports are available under NDA upon request.

SOC 2 Type II

Annual audit covering security, availability, and confidentiality. Latest report: November 2025.

CURRENT

ISO/IEC 27001

Information security management system certification. Recertification cycle: October 2026.

CURRENT

HIPAA Aligned

Operations aligned to HIPAA Security Rule for healthcare customer engagements. BAA available.

CURRENT

PCI-DSS Aware

Operational practices that support customers operating PCI-DSS environments. Not a certified service provider.

CURRENT

NIST CSF 2.0

Internal program mapped to the NIST Cybersecurity Framework, version 2.0. Annual self-assessment.

CURRENT

CSA STAR Level 2

Cloud Security Alliance STAR registry, Level 2 third-party assessment.

CURRENT

Cyber Essentials Plus

UK government-backed certification covering core technical controls. For UK customer engagements.

CURRENT

StateRAMP Moderate

In progress — authorization expected Q3 2026 for public sector engagements.

IN PROGRESS
— Practices

How we operate, in detail.

DATA

Customer data handling

Data is segregated per customer, encrypted in transit and at rest, and retained only for the period documented in your master service agreement. We do not train models on customer data.

ACCESS

Personnel access

All personnel with customer data access undergo background checks and ongoing security awareness training. Access is least-privilege, time-bounded, and logged.

VENDORS

Subprocessor management

A current list of subprocessors is available on request. Material additions are notified to customers in advance with a right to object.

DR

Resilience

Service operations are designed for 99.9% availability with documented business continuity and disaster recovery procedures, tested annually.

DISCLOSURE

Vulnerability disclosure

We operate a coordinated vulnerability disclosure program. Reports may be sent to security@cyberci.co using PGP key 0x4F8B…

PRIVACY

Data protection

GDPR and CCPA aligned. DPA available. Customer data is processed only as instructed and within documented sub-processing relationships.

— Documents

Documents on request.

The following documents are available to current and prospective customers under NDA. Email trust@cyberci.co with your request.