Trust Center

Trust Center

Everything you need to know about our platform's security, compliance, and transparency. Full alignment with industry-leading security standards.

๐Ÿ›ก๏ธSOC 2
๐Ÿ…ISO 27001
๐Ÿ‡ช๐Ÿ‡บGDPR
๐Ÿ’ณPCI DSS
โญCSA STAR
๐ŸฅHIPAA
๐Ÿ”NIST
๐Ÿ‡น๐Ÿ‡ทKVKK
All Systems Operationalstatus.cyber-sec-pro.com โ†’

End-to-End Encryption

AES-256 for rest, TLS 1.3 for transit. Zero-knowledge scan results. Key rotation with forward secrecy.

Isolated Infrastructure

Each scan runs in an isolated container. No cross-tenant access. Dedicated instances for Enterprise plans.

SOC 2 Type II Controls

Infrastructure designed according to SOC 2 Trust Services Criteria (Security, Availability, Confidentiality, Privacy).

Immutable Audit Logging

Complete and immutable audit trails of all actions. SIEM integration. WORM storage for compliance.

MFA, SSO & Zero Trust

Multi-factor authentication via TOTP/WebAuthn. SAML 2.0, OAuth 2.0, OpenID Connect SSO. RBAC + ABAC.

Continuous Patching

Critical security patches applied within 24 hours. CVE databases updated hourly. Automated SBOM generation.

Data Minimization

Data minimization compliant with GDPR Article 5(1)(c). Automated data lifecycle management.

Real-Time Threat Detection

ML-powered anomaly detection. Real-time IDS/IPS. Automated threat intelligence feed integration.

security.txt (RFC 9116)

Our security contact file, fully compliant with IETF RFC 9116. Automatically discovered by search engines and security researchers.

# CyberSec Pro Security Policy

# RFC 9116 Compliant

Contact: mailto:[email protected]

Contact: https://cyber-sec-pro.com/trust-center#responsible-disclosure

Encryption: https://cyber-sec-pro.com/.well-known/pgp-key.txt

Acknowledgments: https://cyber-sec-pro.com/trust-center#acknowledgments

Policy: https://cyber-sec-pro.com/trust-center#responsible-disclosure

Hiring: https://cyber-sec-pro.com/careers

Preferred-Languages: en, tr

Canonical: https://cyber-sec-pro.com/.well-known/security.txt

Expires: 2027-07-31T23:59:59.000Z

Responsible Disclosure & Bug Bounty

1Scope

In-Scope:

  • cyber-sec-pro.com (sub-domains)
  • app.cyber-sec-pro.com (SaaS platform)
  • api.cyber-sec-pro.com (REST & GraphQL API)
  • Mobile Apps (iOS / Android)
  • Open Source Components (GitHub)

Out-of-Scope:

  • Social engineering & phishing
  • DDoS / DoS
  • Physical security
  • Third-party services

2Reporting Channel

Please report security vulnerabilities encrypted with PGP to: [email protected]

Report template:

  • Subject: [SECURITY] Short description
  • Affected asset: URL / endpoint
  • Vulnerability type: (XSS, SQLi, IDOR, etc.)
  • Steps to reproduce: (1, 2, 3...)
  • Impact: (Data leak, Privilege escalation, etc.)
  • CVSS score (optional)
  • PoC / Screenshots

3Response SLA

  • First response: โ‰ค 24 hours
  • Status update: โ‰ค 72 hours
  • Fix or exception: โ‰ค 90 days

4Safe Harbor

  • No legal action will be taken for reports complying with this policy
  • Reporter's identity will be kept confidential
  • Will be added to Hall of Fame after remediation
  • Testing without written permission is prohibited

$Bug Bounty Reward Table

SeverityCVSSReward
Critical9.0โ€“10.0$5,000 โ€“ $15,000
High7.0โ€“8.9$2,000 โ€“ $5,000
Medium4.0โ€“6.9$500 โ€“ $2,000
Low0.1โ€“3.9$100 โ€“ $500

Compliance Frameworks

10/10 Compliant
SOC 2 Type IIโœ“ Compliant
Annual audit โ€” Ernst & Young
GDPRโœ“ Compliant
Full compliance Art. 6, 17, 25, 28, 32, 35
ISO 27001:2022โœ“ Compliant
Certified โ€” BSI Group
ISO 27701โœ“ Compliant
Privacy Information Management
NIST CSF 2.0โœ“ Compliant
Full framework alignment
PCI DSS v4.0โœ“ Compliant
Level 1 Service Provider
HIPAAโœ“ Compliant
BAA available โ€” PHI encryption
KVKKโœ“ Compliant
Turkish Personal Data Protection Law
CCPA/CPRAโœ“ Compliant
California Consumer Privacy Act
CSA STAR Level 2โœ“ Compliant
Cloud Security Alliance Certification

Incident Response SLA

Our incident response procedures compliant with ISO 27035 and NIST SP 800-61 Rev.2:

PriorityDetectionResponseNotificationResolution
P0 โ€” Criticalโ‰ค 15 minโ‰ค 30 minโ‰ค 1 hourโ‰ค 4 hours
P1 โ€” Highโ‰ค 30 minโ‰ค 1 hourโ‰ค 4 hoursโ‰ค 24 hours
P2 โ€” Mediumโ‰ค 1 hourโ‰ค 4 hoursโ‰ค 24 hoursโ‰ค 72 hours
P3 โ€” Lowโ‰ค 4 hoursโ‰ค 24 hoursโ‰ค 72 hoursโ‰ค 30 days

Sub-processors

Third-party providers processing data under GDPR Article 28(2). All sub-processors have signed a DPA (Data Processing Agreement).

ProviderPurposeLocationDPA
Stripe, Inc.Payment processingABD (EU SCC + DPF)โœ“ Signed
Vercel, Inc.Frontend hosting & CDNGlobal Edge (EU SCC)โœ“ Signed
Cloudflare, Inc.DDoS protection, WAF, CDNGlobal (EU SCC + DPF)โœ“ Signed
AWS (Amazon)Backend infrastructure, S3 storageEU (Frankfurt, eu-central-1)โœ“ Signed
PostgreSQL (Supabase)Relational databaseEU (Frankfurt)โœ“ Signed
SendGrid (Twilio)Transactional emailABD (EU SCC)โœ“ Signed
SentryError tracking and monitoringABD (EU SCC)โœ“ Signed

Last updated: July 2026. 30 days prior notice is provided for sub-processor changes.

Data Processing Agreement (DPA)

We provide a Data Processing Agreement (DPA) for all customers under GDPR Article 28. The DPA includes EU Standard Contractual Clauses (EU SCC 2021) and UK IDTA.

DPA Scope

  • Purpose and methods of processing
  • Types of personal data and data subjects
  • List of sub-processors and approval process
  • Technical and organizational measures (TOMs)
  • Data breach notification procedures (โ‰ค72 hrs)
  • Data transfer mechanisms (EU SCC, DPF)

DPIA (Data Protection Impact Assessment)

  • GDPR Article 35 compliant DPIA completed
  • High-risk processing operations documented
  • Risk mitigation measures implemented
  • Annual review by Data Protection Officer (DPO)
  • Available to customers upon request

Security Tests & Audits

Tests conducted by independent third-party security firms. Enterprise customers can access summary reports by signing an NDA.

External Penetration Test

Cobalt.io โ€” CREST Certified

2026-06-15Remediated

Scope: Full platform โ€” API, Web App, Infrastructure, Mobile

Findings: 0 Critical, 0 High, 2 Medium (fixed), 3 Low (fixed)

Source Code Review (SAST)

NCC Group

2026-03-10Remediated

Scope: Backend API, Authentication, Authorization, Crypto

Findings: 0 Critical, 0 High, 1 Medium (fixed), 2 Low (fixed)

Cloud Infrastructure Audit

Bishop Fox

2025-12-01Remediated

Scope: AWS, Kubernetes, Network Segmentation, IAM

Findings: 0 Critical, 0 High, 0 Medium, 1 Low (fixed)

Red Team Exercise

Mandiant (Google Cloud)

2025-09-20Remediated

Scope: Social Engineering, Physical, Digital โ€” Full Kill Chain

Findings: 0 Critical, 1 High (fixed), 2 Medium (fixed)

Security Hall of Fame

We thank the researchers who report vulnerabilities in accordance with our responsible disclosure policy.

You could be the first researcher added to our Hall of Fame by reporting a vulnerability.

Report Vulnerability

System Status

Track the real-time status of all services.

Status Page

Trust Center last updated: July 2026 ยท Policy version: 2.1.0 ยท Annual review: December 2026