Trust Center
Everything you need to know about our platform's security, compliance, and transparency. Full alignment with industry-leading security standards.
End-to-End Encryption
AES-256 for rest, TLS 1.3 for transit. Zero-knowledge scan results. Key rotation with forward secrecy.
Isolated Infrastructure
Each scan runs in an isolated container. No cross-tenant access. Dedicated instances for Enterprise plans.
SOC 2 Type II Controls
Infrastructure designed according to SOC 2 Trust Services Criteria (Security, Availability, Confidentiality, Privacy).
Immutable Audit Logging
Complete and immutable audit trails of all actions. SIEM integration. WORM storage for compliance.
MFA, SSO & Zero Trust
Multi-factor authentication via TOTP/WebAuthn. SAML 2.0, OAuth 2.0, OpenID Connect SSO. RBAC + ABAC.
Continuous Patching
Critical security patches applied within 24 hours. CVE databases updated hourly. Automated SBOM generation.
Data Minimization
Data minimization compliant with GDPR Article 5(1)(c). Automated data lifecycle management.
Real-Time Threat Detection
ML-powered anomaly detection. Real-time IDS/IPS. Automated threat intelligence feed integration.
security.txt (RFC 9116)
Our security contact file, fully compliant with IETF RFC 9116. Automatically discovered by search engines and security researchers.
# CyberSec Pro Security Policy
# RFC 9116 Compliant
Contact: mailto:[email protected]
Contact: https://cyber-sec-pro.com/trust-center#responsible-disclosure
Encryption: https://cyber-sec-pro.com/.well-known/pgp-key.txt
Acknowledgments: https://cyber-sec-pro.com/trust-center#acknowledgments
Policy: https://cyber-sec-pro.com/trust-center#responsible-disclosure
Hiring: https://cyber-sec-pro.com/careers
Preferred-Languages: en, tr
Canonical: https://cyber-sec-pro.com/.well-known/security.txt
Expires: 2027-07-31T23:59:59.000Z
Responsible Disclosure & Bug Bounty
1Scope
In-Scope:
- cyber-sec-pro.com (sub-domains)
- app.cyber-sec-pro.com (SaaS platform)
- api.cyber-sec-pro.com (REST & GraphQL API)
- Mobile Apps (iOS / Android)
- Open Source Components (GitHub)
Out-of-Scope:
- Social engineering & phishing
- DDoS / DoS
- Physical security
- Third-party services
2Reporting Channel
Please report security vulnerabilities encrypted with PGP to: [email protected]
Report template:
- Subject: [SECURITY] Short description
- Affected asset: URL / endpoint
- Vulnerability type: (XSS, SQLi, IDOR, etc.)
- Steps to reproduce: (1, 2, 3...)
- Impact: (Data leak, Privilege escalation, etc.)
- CVSS score (optional)
- PoC / Screenshots
3Response SLA
- First response: โค 24 hours
- Status update: โค 72 hours
- Fix or exception: โค 90 days
4Safe Harbor
- No legal action will be taken for reports complying with this policy
- Reporter's identity will be kept confidential
- Will be added to Hall of Fame after remediation
- Testing without written permission is prohibited
$Bug Bounty Reward Table
| Severity | CVSS | Reward |
|---|---|---|
| Critical | 9.0โ10.0 | $5,000 โ $15,000 |
| High | 7.0โ8.9 | $2,000 โ $5,000 |
| Medium | 4.0โ6.9 | $500 โ $2,000 |
| Low | 0.1โ3.9 | $100 โ $500 |
Compliance Frameworks
10/10 CompliantIncident Response SLA
Our incident response procedures compliant with ISO 27035 and NIST SP 800-61 Rev.2:
| Priority | Detection | Response | Notification | Resolution |
|---|---|---|---|---|
| P0 โ Critical | โค 15 min | โค 30 min | โค 1 hour | โค 4 hours |
| P1 โ High | โค 30 min | โค 1 hour | โค 4 hours | โค 24 hours |
| P2 โ Medium | โค 1 hour | โค 4 hours | โค 24 hours | โค 72 hours |
| P3 โ Low | โค 4 hours | โค 24 hours | โค 72 hours | โค 30 days |
Sub-processors
Third-party providers processing data under GDPR Article 28(2). All sub-processors have signed a DPA (Data Processing Agreement).
| Provider | Purpose | Location | DPA |
|---|---|---|---|
| Stripe, Inc. | Payment processing | ABD (EU SCC + DPF) | โ Signed |
| Vercel, Inc. | Frontend hosting & CDN | Global Edge (EU SCC) | โ Signed |
| Cloudflare, Inc. | DDoS protection, WAF, CDN | Global (EU SCC + DPF) | โ Signed |
| AWS (Amazon) | Backend infrastructure, S3 storage | EU (Frankfurt, eu-central-1) | โ Signed |
| PostgreSQL (Supabase) | Relational database | EU (Frankfurt) | โ Signed |
| SendGrid (Twilio) | Transactional email | ABD (EU SCC) | โ Signed |
| Sentry | Error tracking and monitoring | ABD (EU SCC) | โ Signed |
Last updated: July 2026. 30 days prior notice is provided for sub-processor changes.
Data Processing Agreement (DPA)
We provide a Data Processing Agreement (DPA) for all customers under GDPR Article 28. The DPA includes EU Standard Contractual Clauses (EU SCC 2021) and UK IDTA.
DPA Scope
- Purpose and methods of processing
- Types of personal data and data subjects
- List of sub-processors and approval process
- Technical and organizational measures (TOMs)
- Data breach notification procedures (โค72 hrs)
- Data transfer mechanisms (EU SCC, DPF)
DPIA (Data Protection Impact Assessment)
- GDPR Article 35 compliant DPIA completed
- High-risk processing operations documented
- Risk mitigation measures implemented
- Annual review by Data Protection Officer (DPO)
- Available to customers upon request
Security Tests & Audits
Tests conducted by independent third-party security firms. Enterprise customers can access summary reports by signing an NDA.
Cobalt.io โ CREST Certified
Scope: Full platform โ API, Web App, Infrastructure, Mobile
Findings: 0 Critical, 0 High, 2 Medium (fixed), 3 Low (fixed)
NCC Group
Scope: Backend API, Authentication, Authorization, Crypto
Findings: 0 Critical, 0 High, 1 Medium (fixed), 2 Low (fixed)
Bishop Fox
Scope: AWS, Kubernetes, Network Segmentation, IAM
Findings: 0 Critical, 0 High, 0 Medium, 1 Low (fixed)
Mandiant (Google Cloud)
Scope: Social Engineering, Physical, Digital โ Full Kill Chain
Findings: 0 Critical, 1 High (fixed), 2 Medium (fixed)
Security Hall of Fame
We thank the researchers who report vulnerabilities in accordance with our responsible disclosure policy.
You could be the first researcher added to our Hall of Fame by reporting a vulnerability.
Report VulnerabilitySecurity Contact
Security: [email protected]
Legal/DPA: [email protected]
DPO: [email protected]
Privacy: [email protected]
Trust Center last updated: July 2026 ยท Policy version: 2.1.0 ยท Annual review: December 2026