Privacy

Privacy policy

What CyberlySecure LLC collects when you use cyberlysecure.com, why we have it, who else sees it, and what you can ask us to do with it. Written to describe what this site actually does.

Last updated 22 September 2026

This policy covers the website at cyberlysecure.com — the pages you read, the forms you submit, the newsletter, and the analytics that measure how the site is used. It also explains how we treat job applications and vulnerability reports sent to us by email.

1. Who we are

CyberlySecure LLC is a penetration testing firm based in Houston, Texas, working with clients worldwide. For the information described in this policy, we decide why and how it is used — in data-protection terms, we are the controller.

For anything in this policy, including any request about your own data, write to us:

We do not currently publish a postal address or telephone number for privacy requests. Email reaches us fastest, and we answer every request ourselves — there is no automated portal in between.

2. What this policy does not cover: client testing work

When a client hires us to test their systems, we receive very different material: scoping details, credentials and access, network and application data, screenshots and other evidence, and the findings and reports we produce from it. None of that is governed by this policy. It is governed by the engagement agreement, the non-disclosure agreement and the rules of engagement signed with that client, which say how the data is handled, who may see it, and what happens to it when the work ends.

We test only assets a client owns or is authorised to have tested, under written authorization. If you are a client and want to know how your engagement data is handled, ask your engagement lead, or write to hello@cyberlysecure.com.

3. What you give us

Three forms on this site send information to us. Each collects only what it shows on screen:

  • Scoping call request (/contact) — your name and work email, and optionally your company, what you are interested in, what is driving the test, and a free-text note.
  • Attack-surface snapshot — the form in the band at the foot of most pages: your work email, your primary domain, and what is driving the test.
  • Resource requests (/resources) — your work email, and which resource you asked for.

If our API cannot be reached when you submit a form, the page falls back to opening a pre-filled email in your own mail program. Nothing is recorded on our side unless you choose to send it.

Newsletter

The newsletter is double opt-in. You give an email address, we send a confirmation email, and you are subscribed only if you press the link in it. That link stops working after seven days, and asking again within ten minutes will not send a second email. We store your address, the page you signed up from and the time. Every newsletter has an unsubscribe link, and you can also ask us to remove you by email. Unsubscribing marks the record as unsubscribed so we do not email you again; it does not delete the record, though you can ask us to erase it.

Recorded automatically with anything you submit

When you submit a form or sign up to the newsletter, we also record the IP address the request came from, your browser's user-agent string, the page you submitted from and the referring page. We use this to tell real enquiries from automated spam, and to look into abuse. Your message is stored both as the enquiry itself and inside a copy of the notification email it generates.

The forms also run a small proof-of-work check in your browser and include a hidden field that people never see. Both exist to slow down bots, and neither identifies you.

Job applications and vulnerability reports

There is no application form on this site: applications arrive as email to careers@cyberlysecure.com, so we receive whatever you choose to send — usually a CV, a covering note and links — and use it to consider you for the role. Vulnerability reports about our own site reach security@cyberlysecure.com (also listed in our security.txt), and we use the report, your contact details and any evidence you attach to investigate, fix the problem and reply to you.

4. Cookies, analytics and your choice

We set no cookies of our own. What we do use is your browser's local storage, and two measurement services. This section describes all of it, including the parts that run before you choose.

Google Fonts — loads on every page

Our typefaces are served by Google rather than from our own servers. Loading them means Google receives your IP address, your browser's user-agent and the page you are on, on every visit, whatever you choose in the cookie notice. It happens before any consent decision, because the fonts load with the page itself.

Google Analytics

We use Google Analytics 4 to count page views and see which pages are read. The Google tag loads on every page, but whether it may store anything in your browser depends on consent:

  • For visitors in the EEA, the UK and Switzerland, Google is told to store nothing at all until you accept. Google decides who that covers from your IP address.
  • Everywhere else, analytics storage starts switched on. You can switch it off at any time with Cookie preferences in the footer.
  • Whether you are shown the cookie notice is decided separately, from your browser's time zone — the closest signal a site like this has. So a European visitor whose device is set to another time zone may not see the notice, even though storage still stays off for them. Cookie preferences in the footer works for everyone, wherever you are.
  • If you decline, nothing is stored on your device, but the page view is still counted by Google without any identifier attached to it.
  • We run no advertising tags at all, and advertising storage is switched off for everybody, everywhere.

Our own visit measurement

With analytics consent, we also run our own measurement, which records which pages were read, for how long, how far down the page you scrolled and how quickly the page loaded. It starts only when consent is granted, and never on a "no". It records no session replays — we never record your screen, your typing or your mouse.

To do that it keeps identifiers in your browser rather than in cookies:

  • cz_anon — a random identifier in local storage that stays until you clear site data. It is not your name or email, but it is durable, and it links your visits together.
  • cz_sid — a random identifier for the current tab, cleared when you close it.
  • cz_c — present only if you arrived from one of our campaign emails. The link carries an encrypted token, which lets us connect that visit to your contact record. It is kept for the tab only and removed from the address bar.
  • cs-consent — your answer to the cookie notice, so we do not ask again.

These measurements are sent to our analytics service at customerly.us, which is operated on our behalf. Our own measurement does not send your IP address.

Do Not Track and Global Privacy Control

If your browser sends a Do Not Track signal, we do not start our own visit measurement at all. That signal does not stop Google Analytics, which follows your consent choice instead. We do not currently act on the Global Privacy Control signal; if you want analytics off, use Cookie preferences in the footer, or write to us.

The blog editor area is excluded from all site measurement.

5. Why we are allowed to use it

If you are in the UK or the European Economic Area, the law requires us to have a basis for each use. Ours are:

What we doBasis
Answer an enquiry, a snapshot request or a resource requestSteps taken at your request before a possible contract, and our legitimate interest in running the business
Send the newsletterYour consent, given by confirming the sign-up
Record IP, user-agent and referrer with a submissionOur legitimate interest in keeping the site usable and free of spam and abuse
Google Analytics and our own visit measurementYour consent where it is asked for; otherwise our legitimate interest in understanding how the site is used, which you can object to at any time via Cookie preferences
Consider a job applicationSteps taken at your request before a possible employment contract
Investigate a vulnerability reportOur legitimate interest in the security of our own systems
Keep records of what we sent and to whomOur legitimate interest in being able to show what happened, and our legal obligations

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

6. Who else sees it

We keep the list of companies involved deliberately short:

  • Amazon Web Services — hosts this site, our databases and our sign-in, and sends our email. Everything we hold sits in AWS.
  • Google — Google Analytics, as described above, and Google Fonts, which receives a request from your browser on every page.
  • Customerly — the analytics service at customerly.us that receives our own visit measurement, operated on our behalf.

We also share information where we have to: with professional advisers, or with authorities where the law requires it. If the business were ever sold or reorganised, information would pass to the buyer under the same terms.

7. Where it is stored

All of it is stored in the United States, in Amazon Web Services' Northern Virginia region. The pages themselves are delivered from a content network with locations in North America and Europe, so a European visitor is served from nearby — but anything you send us is stored in the US.

If you are in the UK or the EEA, that means your information is transferred to the United States. If you need the details of the safeguards that apply to a particular transfer, ask us and we will set them out.

8. How long we keep it

We keep enquiries, newsletter records and the emails our systems send for as long as we need them for the purpose they were collected for — answering you, running the relationship that may follow, and keeping a record of what was sent. We do not delete them on a fixed schedule, so in practice an enquiry stays with us until we no longer have a reason to keep it, or until you ask us to erase it. If you want yours removed, write to hello@cyberlysecure.com and we will do it.

9. How we protect it

Specifically, and only what is true:

  • The site and our API are served over HTTPS only, with modern TLS, and browsers are told to refuse anything else.
  • A strict content security policy at the edge limits what a page is allowed to load or connect to.
  • Our storage is private and encrypted, reachable only through the content network.
  • Access to the systems holding enquiries is restricted to people who run the business, using credentials held in AWS.
  • The forms are protected against automated abuse, as described above.

We do not hold a security certification such as SOC 2 or ISO 27001, and we do not claim one. No system is perfectly secure; if something does go wrong and it affects your personal data, we will tell the people and authorities the law says we must.

10. Artificial intelligence

Nothing you send through this website — an enquiry, a newsletter sign-up, or anything measured about your visit — is fed into an AI or large-language-model service. We make no automated decisions about you that produce legal or similarly significant effects, and we do not profile you in that sense.

11. Children

This site and our services are meant for organisations and the people who work for them. We do not aim any of it at children and do not knowingly collect personal data from anyone under 16. If we learn that we have, we delete it.

12. Your rights

Wherever you are, you can ask us what we hold about you, ask us to correct it, or ask us to delete it — write to hello@cyberlysecure.com. We may need to check who you are before we act, and we will answer within the time the law allows.

UK and European Economic Area

You have the right to access your data, to have it corrected or erased, to restrict or object to how we use it — including analytics and anything else we do on the basis of legitimate interests — to receive it in a portable form, and to withdraw consent at any time. Withdrawing consent does not undo what was done before.

United States

Depending on your state — California, Virginia, Colorado, Connecticut, Texas and others as their laws come into force — you may have the right to know what we collect, to a copy of it, to have it deleted or corrected, and to opt out of sale or targeted advertising. We do not sell personal information or use it for targeted advertising, so there is nothing to opt out of there. We will not treat you differently for exercising any of these rights.

13. Complaints

Tell us first at hello@cyberlysecure.com — we would rather fix it. If you are not satisfied, people in the EEA can complain to their national data protection authority, people in the UK to the Information Commissioner's Office, and people in the US to their state attorney general.

14. Changes to this policy

We update this page when what we do changes. The date at the top shows when it last changed, and the current version always lives at this address. Please check back from time to time.

Questions about any of this, or a request about your own data: hello@cyberlysecure.com. If you would rather talk it through, book a call.