Privacy
This page provides a general privacy overview for Cyber Op Source documentation and Compliance OS. Engagement-specific agreements, privacy notices, data-processing terms, or client requirements may provide additional or controlling obligations.Information that may be processed
Depending on how you use Compliance OS, information may include:- account identifiers and contact information,
- authentication and authorization metadata,
- client and engagement membership,
- interview responses,
- findings, treatments, notes, and actions,
- evidence and uploaded files,
- client-facing documents,
- governance decisions,
- security, audit, and application activity information,
- technical information needed to operate and protect the service.
Why information is used
Information may be used to:- provide and secure Compliance OS,
- authenticate users and enforce authorization,
- perform contracted cybersecurity or compliance work,
- support collaboration and remediation,
- maintain activity and audit records,
- improve reliability and user experience,
- investigate security or operational issues,
- meet contractual or legal obligations.
Client-controlled content
Organizations and their authorized users determine much of the content submitted during an engagement. Users should avoid providing unrelated personal information or secrets that are not needed for the task.Security
Cyber Op Source uses administrative, technical, and operational safeguards appropriate to the nature of the service. No system can guarantee absolute security. Users share responsibility by protecting credentials, using authorized accounts, and reporting suspicious behavior.Service providers
Cyber Op Source may use infrastructure, identity, security, communications, AI, analytics, or other service providers as necessary to operate approved services. The providers and specific data-handling terms applicable to an engagement may depend on the service configuration and governing agreement.Retention
Retention periods may vary based on contractual commitments, engagement requirements, legal obligations, operational needs, and configured services.Questions or requests
For privacy questions related to a specific engagement, contact your Cyber Op Source engagement representative or the contact identified in your governing agreement.This documentation page is a product-oriented privacy overview and should be reviewed against Cyber Op Source’s final published legal privacy notice before public launch.