Security & Trust.
A penetration test gives an outside party temporary, privileged insight into your systems. This page explains how CyberZ handles that responsibility: what we require before testing, how we handle what we see, and how we protect what we produce.
Read this first
CyberZ does not claim security certifications or attestations it does not hold. Items marked [to be completed by CyberZ] are company-specific policy values that will be published once finalized. Nothing here is an invented control.
Confidentiality
Engagement details, findings and customer information are treated as confidential by default.
- A mutual non-disclosure agreement or equivalent confidentiality terms are agreed before scoping details are shared.
- CyberZ does not publish customer names, logos or engagement outcomes without written permission.
- The public certificate verification page shows only the fields the customer has agreed to publish.
Secure report handling
Reports contain vulnerability details and are protected accordingly.
- Reports are delivered through an agreed secure channel — encrypted file transfer or a customer-provided secure document system.
- Reports are not sent as unencrypted email attachments.
- Report evidence is redacted to the minimum needed to reproduce a finding.
Delivery mechanism and encryption standard: [to be completed by CyberZ].
Data minimization
We collect and retain the least data necessary to perform and evidence the assessment.
- Testing prefers synthetic or test data; access to real customer records is avoided unless scope explicitly requires it.
- When a finding exposes data, only enough is captured to prove the finding; bulk extraction is never performed.
- Credentials, tokens and personal data encountered during testing are not stored beyond the engagement.
Testing infrastructure
Testing originates from identified, controlled systems.
- Source IP addresses for testing traffic are provided in advance where applicable so they can be identified and allowlisted.
- Testing systems are dedicated to engagements, kept updated and isolated from unrelated activity.
- Tooling output and working notes are stored on encrypted storage.
Testing infrastructure hardening baseline and endpoint controls: [to be completed by CyberZ].
Communication
Direct, documented communication throughout the engagement.
- Communication channels and emergency contacts are agreed in the Rules of Engagement.
- Critical findings are communicated as soon as they are validated, not held until the final report.
- Sensitive details are exchanged only over the agreed secure channel.
Vulnerability disclosure
If you find a security issue in cyberz.net or in our systems, we want to know.
- Report issues to contact@cyberz.net with enough detail to reproduce the problem.
- We acknowledge reports, do not pursue legal action against good-faith research that respects user privacy and availability, and credit reporters on request.
- Please do not access data that is not yours, degrade availability, or test third-party services on our behalf.
Acknowledgment and remediation timelines, PGP key: [to be completed by CyberZ].
Data retention
Engagement data is kept only as long as agreed, then deleted.
- Working data (requests, screenshots, notes) is deleted after the retest period unless the customer requests otherwise.
- Final reports are retained for an agreed period to support retesting and certificate verification.
- Deletion can be confirmed in writing on request.
Default retention periods for working data and reports: [to be completed by CyberZ].
Rules of Engagement
Every engagement is governed by written Rules of Engagement agreed before testing.
- Authorized and prohibited targets, testing window, methods, exploitation limits and stop conditions are defined.
- Denial-of-service testing is excluded by default.
- Our template is available as a starting point and requires review by your legal counsel.
Secure transfer of credentials
Test accounts and access details are exchanged securely and revoked afterwards.
- Credentials, API keys and VPN access are shared through an agreed secure mechanism — never in plain email or chat.
- Test accounts are created for the engagement and disabled by the customer when it ends.
- CyberZ does not retain customer credentials after the engagement and retest are complete.
Preferred secret-sharing mechanism: [to be completed by CyberZ].
Handling of customer data
Customer data touched during testing is handled under the same rules as findings.
- Any customer data encountered is treated as confidential, minimized, and deleted with the rest of the working data.
- Contact form submissions on this website are emailed to CyberZ and are not stored in a database by this site.
- Sub-processors and tooling that could receive customer data are disclosed on request.
Sub-processor list and applicable data protection terms: [to be completed by CyberZ].
Questions about this page
Security questionnaires, sub-processor lists and confidentiality terms are handled during pre-engagement. Write to contact@cyberz.net. Security assessments represent a point-in-time evaluation and do not constitute a guarantee that the assessed systems remain secure or free from vulnerabilities after the assessment.
Request a security assessment.
Tell us what you need tested, when, and which evidence you need at the end. We reply with scoping questions, not a sales deck.