SECTION 01
Governance & Accountability
Leadership ownership.Security is owned at the leadership level. The founder and principal engineer is directly responsible for CySLex's security program and for approving any exception to it.
Structured policies.Our internal policies are written against ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, and the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality). We maintain a risk register, an asset inventory, and an access review log, and we review them at least quarterly.
Personnel vetting & training.Every team member and contractor signs a confidentiality agreement and completes security awareness onboarding before receiving access to any client material.
SECTION 02
Client Engagement Data
Client data is the most sensitive information we handle. During assessments, audits, and managed-security work we may receive network diagrams, configuration exports, vulnerability findings, and evidence artifacts.
NDA by default.Every engagement is covered by a mutual non-disclosure agreement before any technical information is exchanged.
Data minimization.We request only the artifacts required for the scope agreed in the Statement of Work (SOW), and we ask clients to redact credentials and personal data before sharing where possible.
Strict segregation.Each client's material is stored in a dedicated, access-controlled workspace. No client data is commingled, and no client data is ever used as example material for another client.
90-day retention & disposal.Engagement artifacts are retained for the duration of the engagement plus 90 days for deliverable support, then securely deleted unless the client requests a different retention period in writing. Final reports are retained per contract.
Ephemeral credentials.If an engagement requires credentials, they are provisioned by the client, scoped to the minimum privilege needed, stored only in an encrypted secrets manager, and revoked at close-out.
SECTION 03
Identity & Access Control
Phishing-resistant MFA.Multi-factor authentication is mandatory on every corporate, cloud, code-hosting, and email account. Phishing-resistant methods (hardware security keys or passkeys) are used for administrative access.
Least privilege RBAC.Access follows least privilege and is role-based. Administrative access to production infrastructure is limited to named individuals and is reviewed quarterly.
Same-day offboarding.Accounts are provisioned and deprovisioned through a documented checklist; departing personnel and contractors lose access the same day the relationship ends.
No generic accounts.Shared or generic accounts are not permitted. All secrets live in a managed secrets store, never in code, chat, or documents.
SECTION 04
Infrastructure & Hosting
Hardened Linux edge.cyslex.com and CySLex-operated services run on hardened Linux hosts behind a reverse proxy with automatic TLS. Only ports 80/443 are exposed; management access is restricted to SSH with key-based authentication from allow-listed sources.
Immutable container workloads.Workloads run in isolated containers. Container images are rebuilt from pinned base images and redeployed rather than patched in place.
Rapid patching SLA.Operating systems and dependencies receive security updates on a defined cadence: critical patches within 72 hours of release, routine patches within 30 days.
Perimeter rate limiting & firewalls.Firewalls, brute-force protection, and rate limiting are enabled at the host and proxy layers.
Privacy anti-bot.Public forms are protected by a privacy-preserving anti-bot challenge; no third-party advertising trackers are loaded on this site.
SECTION 05
Data Protection & Encryption
In transit.TLS 1.2+ is enforced on all public endpoints, with HSTS enabled. Internal service-to-service traffic is confined to private container networks.
At rest.Server volumes, backups, and workstation disks are encrypted with AES-256 or stronger. Client engagement files are additionally stored in encrypted, access-logged repositories.
Encrypted offline backups.Backups are encrypted, taken on a daily schedule, stored in a separate location from production, and restore-tested quarterly.
Website form telemetry.Information submitted through the contact and assessment forms is transmitted encrypted and used only to respond to your inquiry. See our Privacy Policy for details on what we collect and how long we keep it.
SECTION 06
Secure Development
Protected branches & PR reviews.Code is version-controlled with protected main branches; changes are reviewed before merge.
Automated secret scanning & SCA.Dependencies are scanned for known vulnerabilities on every build, and secret-scanning is enabled on all repositories.
CI static analysis.Static analysis and linting run in CI. No credentials or environment-specific configuration are committed to source control.
1-step atomic rollback.Production deployments are reproducible from tagged releases, and rollback is a single-step operation.
SECTION 07
Vulnerability Management & Testing
Continuous attack surface monitoring.We run continuous external attack-surface monitoring against our own domains and IP ranges — the same reconnaissance we perform for clients.
Monthly authenticated scans.Authenticated vulnerability scans of our infrastructure are performed at least monthly.
Annual independent pentest.We commission an independent penetration test of our public-facing assets at least annually and after any significant architectural change.
Remediation windows.Findings are triaged by severity with target remediation windows: Critical — 72 hours; High — 14 days; Medium — 30 days; Low — next scheduled maintenance.
Safe harbor for researchers.Security researchers who identify an issue can report it through our Responsible Disclosure process. We will not pursue legal action against good-faith research conducted within that policy.
SECTION 08
Endpoint Security
EDR & Full-Disk Encryption.All CySLex workstations run full-disk encryption, an endpoint detection and response (EDR) agent, host firewalls, and automatic OS updates.
Remote MDM lock & wipe.Devices are enrolled in management and can be remotely locked or wiped if lost or stolen.
No removable media / personal devices.Client data is never stored on removable media and is not permitted on personal devices.
SECTION 09
Monitoring, Logging & Incident Response
12-month tamper-proof audit logs.Authentication events, administrative actions, and network-edge telemetry are centrally logged, retained for at least 12 months, and protected from modification.
Human review of anomalies.Alerts on anomalous logins, privilege changes, and exposure indicators are reviewed by a human.
IR plan & annual tabletop exercises.We maintain a written incident response plan covering identification, containment, eradication, recovery, and lessons learned, and we exercise it at least annually through tabletop scenarios.
72-hour client notification SLA.If we confirm a security incident that affects a client's data, we notify the affected client without undue delay and no later than 72 hours after confirmation, with a written summary of impact, root cause, and corrective actions once the investigation is complete.
SECTION 10
Business Continuity & Resilience
Strict RTO & RPO targets.We maintain a business continuity and disaster recovery plan for CySLex systems, with a recovery time objective (RTO) of under 4 hours and a recovery point objective (RPO) of under 15 minutes for critical services.
Infrastructure as Code.Infrastructure is defined as code so that it can be rebuilt on alternative hosting if the primary provider becomes unavailable.
Redundant documentation.Key documentation and client deliverables are stored redundantly across independent providers.
SECTION 11
Vendors & Subprocessors
Rigorous vendor vetting.We evaluate every vendor that could touch client or personal data before onboarding, reviewing their security posture, certifications, and data-handling terms.
Minimal subprocessor footprint.We keep the list short. Our core subprocessors are our hosting provider, our email and productivity suite, our code-hosting provider, and our anti-bot/CDN provider. A current list is available on request to clients and prospects under NDA.
Annual contract reviews.Vendor access and contracts are reviewed annually.
SECTION 12
How We Use AI
We help clients govern AI responsibly, and we apply the same rules internally.
Zero client data to public AI.Client data is not submitted to public AI services. Where AI assists our analysis, we use self-hosted or enterprise-tier models under contractual terms that prohibit training on our inputs.
Human-in-the-loop engineering.AI output used in any client deliverable is reviewed by a qualified engineer before it is delivered. AI does not make security decisions on our behalf.
NIST AI RMF classification.Our internal AI usage policy classifies data by sensitivity and defines which tiers may be processed by which model class, consistent with the NIST AI Risk Management Framework.
SECTION 13
Framework Alignment
| Framework / Standard | Alignment Status | Tier |
|---|---|---|
| ISO/IEC 27001:2022 | Policies and controls aligned; formal certification not currently held | Annex A Aligned |
| SOC 2 (Security, Availability, Confidentiality) | Controls aligned; readiness assessment maintained internally | Trust Criteria |
| NIST Cybersecurity Framework 2.0 | Aligned across all six functions (Govern, Identify, Protect, Detect, Respond, Recover) | NIST CSF 2.0 |
| NIST AI Risk Management Framework | Aligned for internal enterprise AI use and client advisory | AI RMF Aligned |
| HIPAA Security Rule | Safeguards applied when engagements involve ePHI; Business Associate Agreement (BAA) available | ePHI Safeguards |
We update this matrix as periodic formal attestations are completed.
SECTION 14
Security Documentation for Procurement
Clients and prospects going through vendor due diligence can request, under NDA:
Our comprehensive information security policy set (ISMS documentation)
Most recent third-party penetration test executive summary
Business continuity and incident response plan executive summaries
Completed standardized security questionnaires (SIG Lite, CAIQ, or client-provided templates)
Evaluating CySLex in your procurement process?
Submit your diligence request or questionnaire to security@cyslex.com
SECTION 15
Contact & Reporting
Security inquiries & procurement.Send due diligence requests and security inquiries directly to security@cyslex.com.
Vulnerability disclosure.Researchers can review our policy and submit findings through our Responsible Disclosure page and /.well-known/security.txt.
Privacy inquiries.For questions regarding data processing and privacy practices, refer to our Privacy Policy.