Privacy policy
What CyberlySecure LLC collects when you use cyberlysecure.com, why we have it, who else sees it, and what you can ask us to do with it. Written to describe what this site actually does.
This policy covers the website at cyberlysecure.com — the pages you read, the forms you submit, the newsletter, and the analytics that measure how the site is used. It also explains how we treat job applications and vulnerability reports sent to us by email.
1. Who we are
CyberlySecure LLC is a penetration testing firm based in Houston, Texas, working with clients worldwide. For the information described in this policy, we decide why and how it is used — in data-protection terms, we are the controller.
For anything in this policy, including any request about your own data, write to us:
- Privacy and data requests, and general enquiries: hello@cyberlysecure.com
- Security problems with our site or systems: security@cyberlysecure.com
- Job applications: careers@cyberlysecure.com
- Partner programs: partners@cyberlysecure.com
We do not currently publish a postal address or telephone number for privacy requests. Email reaches us fastest, and we answer every request ourselves — there is no automated portal in between.
2. What this policy does not cover: client testing work
When a client hires us to test their systems, we receive very different material: scoping details, credentials and access, network and application data, screenshots and other evidence, and the findings and reports we produce from it. None of that is governed by this policy. It is governed by the engagement agreement, the non-disclosure agreement and the rules of engagement signed with that client, which say how the data is handled, who may see it, and what happens to it when the work ends.
We test only assets a client owns or is authorised to have tested, under written authorization. If you are a client and want to know how your engagement data is handled, ask your engagement lead, or write to hello@cyberlysecure.com.
3. What you give us
Three forms on this site send information to us. Each collects only what it shows on screen:
- Scoping call request (/contact) — your name and work email, and optionally your company, what you are interested in, what is driving the test, and a free-text note.
- Attack-surface snapshot — the form in the band at the foot of most pages: your work email, your primary domain, and what is driving the test.
- Resource requests (/resources) — your work email, and which resource you asked for.
If our API cannot be reached when you submit a form, the page falls back to opening a pre-filled email in your own mail program. Nothing is recorded on our side unless you choose to send it.
Newsletter
The newsletter is double opt-in. You give an email address, we send a confirmation email, and you are subscribed only if you press the link in it. That link stops working after seven days, and asking again within ten minutes will not send a second email. We store your address, the page you signed up from and the time. Every newsletter has an unsubscribe link, and you can also ask us to remove you by email. Unsubscribing marks the record as unsubscribed so we do not email you again; it does not delete the record, though you can ask us to erase it.
Recorded automatically with anything you submit
When you submit a form or sign up to the newsletter, we also record the IP address the request came from, your browser's user-agent string, the page you submitted from and the referring page. We use this to tell real enquiries from automated spam, and to look into abuse. Your message is stored both as the enquiry itself and inside a copy of the notification email it generates.
The forms also run a small proof-of-work check in your browser and include a hidden field that people never see. Both exist to slow down bots, and neither identifies you.
Job applications and vulnerability reports
There is no application form on this site: applications arrive as email to careers@cyberlysecure.com, so we receive whatever you choose to send — usually a CV, a covering note and links — and use it to consider you for the role. Vulnerability reports about our own site reach security@cyberlysecure.com (also listed in our security.txt), and we use the report, your contact details and any evidence you attach to investigate, fix the problem and reply to you.
5. Why we are allowed to use it
If you are in the UK or the European Economic Area, the law requires us to have a basis for each use. Ours are:
| What we do | Basis |
|---|---|
| Answer an enquiry, a snapshot request or a resource request | Steps taken at your request before a possible contract, and our legitimate interest in running the business |
| Send the newsletter | Your consent, given by confirming the sign-up |
| Record IP, user-agent and referrer with a submission | Our legitimate interest in keeping the site usable and free of spam and abuse |
| Google Analytics and our own visit measurement | Your consent where it is asked for; otherwise our legitimate interest in understanding how the site is used, which you can object to at any time via Cookie preferences |
| Consider a job application | Steps taken at your request before a possible employment contract |
| Investigate a vulnerability report | Our legitimate interest in the security of our own systems |
| Keep records of what we sent and to whom | Our legitimate interest in being able to show what happened, and our legal obligations |
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
8. How long we keep it
We keep enquiries, newsletter records and the emails our systems send for as long as we need them for the purpose they were collected for — answering you, running the relationship that may follow, and keeping a record of what was sent. We do not delete them on a fixed schedule, so in practice an enquiry stays with us until we no longer have a reason to keep it, or until you ask us to erase it. If you want yours removed, write to hello@cyberlysecure.com and we will do it.
9. How we protect it
Specifically, and only what is true:
- The site and our API are served over HTTPS only, with modern TLS, and browsers are told to refuse anything else.
- A strict content security policy at the edge limits what a page is allowed to load or connect to.
- Our storage is private and encrypted, reachable only through the content network.
- Access to the systems holding enquiries is restricted to people who run the business, using credentials held in AWS.
- The forms are protected against automated abuse, as described above.
We do not hold a security certification such as SOC 2 or ISO 27001, and we do not claim one. No system is perfectly secure; if something does go wrong and it affects your personal data, we will tell the people and authorities the law says we must.
10. Artificial intelligence
Nothing you send through this website — an enquiry, a newsletter sign-up, or anything measured about your visit — is fed into an AI or large-language-model service. We make no automated decisions about you that produce legal or similarly significant effects, and we do not profile you in that sense.
11. Children
This site and our services are meant for organisations and the people who work for them. We do not aim any of it at children and do not knowingly collect personal data from anyone under 16. If we learn that we have, we delete it.
12. Your rights
Wherever you are, you can ask us what we hold about you, ask us to correct it, or ask us to delete it — write to hello@cyberlysecure.com. We may need to check who you are before we act, and we will answer within the time the law allows.
UK and European Economic Area
You have the right to access your data, to have it corrected or erased, to restrict or object to how we use it — including analytics and anything else we do on the basis of legitimate interests — to receive it in a portable form, and to withdraw consent at any time. Withdrawing consent does not undo what was done before.
United States
Depending on your state — California, Virginia, Colorado, Connecticut, Texas and others as their laws come into force — you may have the right to know what we collect, to a copy of it, to have it deleted or corrected, and to opt out of sale or targeted advertising. We do not sell personal information or use it for targeted advertising, so there is nothing to opt out of there. We will not treat you differently for exercising any of these rights.
13. Complaints
Tell us first at hello@cyberlysecure.com — we would rather fix it. If you are not satisfied, people in the EEA can complain to their national data protection authority, people in the UK to the Information Commissioner's Office, and people in the US to their state attorney general.
14. Changes to this policy
We update this page when what we do changes. The date at the top shows when it last changed, and the current version always lives at this address. Please check back from time to time.
Questions about any of this, or a request about your own data: hello@cyberlysecure.com. If you would rather talk it through, book a call.