Legal
Privacy Policy
Effective Date: July 17, 2026
Last Updated: August 15, 2026
Cybermatic.ai is operated by Ironhawk Group (“Cybermatic.ai,” “Cybermatic,” “Ironhawk Group,” “we,” “us,” or “our”). We respect your privacy and are committed to protecting the personal information and confidential business information entrusted to us.
This Privacy Policy explains how we collect, use, store, disclose, and protect information when you:
- Visit cybermatic.ai or another website that links to this Privacy Policy;
- Create or use a Cybermatic.ai account;
- Connect a cloud environment, SaaS application, or other system to the Cybermatic.ai platform;
- Use our asset discovery, risk analysis, remediation, compliance, artificial intelligence, reporting, or related services;
- Install and use the Cybermatic Device Trust mobile application to enroll a device;
- Request a demonstration, start a trial, purchase a subscription, or contact us;
- Communicate with our sales, support, security, or other teams; or
- Otherwise interact with Cybermatic.ai.
1. Our Privacy Commitments
Cybermatic.ai is designed to help organizations understand and improve their security posture. Our privacy practices are based on the following commitments:
We do not sell personal information.
We do not rent personal information.
We do not share personal information for cross-context behavioral advertising or targeted advertising.
We do not disclose customer information to third parties for their independent marketing purposes.
We disclose information to cloud, payment, security, communications, artificial intelligence, analytics, support, and other service providers only when reasonably necessary to operate, secure, support, and provide the services requested by our customers.
We require service providers to process information only for authorized purposes and do not permit them to use customer information for their own advertising or unrelated commercial purposes.
Our standard cloud security scanning is designed to use read-only access and collect configuration, asset, identity, vulnerability, exposure, and security metadata—not the contents of customer emails, documents, databases, application communications, or stored files.
Cybermatic.ai does not automatically apply remediation changes to a customer environment unless a separate feature is expressly enabled and authorized. Customers remain responsible for reviewing and approving generated remediation commands, code, and recommendations.
2. Scope of This Privacy Policy
This Privacy Policy applies to information processed through Cybermatic.ai’s:
- Websites;
- Software applications;
- Cybersecurity platform;
- Customer portals;
- Demonstration and trial environments;
- Support channels;
- Communications;
- Integrations; and
- Related services.
This Privacy Policy does not apply to:
- Third-party websites, products, platforms, or services that maintain their own privacy policies;
- Personal information processed solely on behalf of a customer when a separate Data Processing Addendum or customer agreement governs that processing;
- Employee, contractor, or job-applicant information covered by a separate privacy notice; or
- Information that has been aggregated or de-identified so that it cannot reasonably be associated with an identifiable individual.
When Cybermatic.ai processes personal information contained in Customer Content on behalf of a business customer, the customer generally determines why and how the information is processed. In that context, the customer is generally the data controller or business, and Cybermatic.ai acts as the data processor, service provider, or contractor.
Individuals seeking to exercise privacy rights involving Customer Content should ordinarily contact the relevant Cybermatic.ai customer first.
Cybermatic Device Trust Mobile Application. Cybermatic offers a mobile application (“Cybermatic Device Trust” or the “App”) that individuals install on a phone or tablet to enroll that device with an organization that uses Cybermatic. The App is intended solely for corporate and bring-your-own-device (“BYOD”) users who enroll using an enrollment token or link provided by their organization. It has no consumer mode and cannot be used without an organization-issued enrollment token. When an individual enrolls a device, the organization (the Customer) receives that device’s security-posture information and generally acts as the data controller or business with respect to it; Cybermatic acts as the processor or service provider. Individuals should review their organization’s own policies before enrolling a personal device.
3. Definitions
For purposes of this Privacy Policy:
Customer
“Customer” means an organization or individual that purchases, accesses, evaluates, or uses the Cybermatic.ai platform or related Services.
Customer Content
“Customer Content” means information, data, prompts, documents, files, configurations, records, credentials, instructions, reports, and other content submitted to, connected to, generated through, or processed by the Services on behalf of a Customer.
Personal Information
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable individual or household.
Depending on applicable law, Personal Information may also be referred to as “personal data.”
Services
“Services” means Cybermatic.ai’s websites, software, platform, applications, support, artificial intelligence features, security assessments, reporting capabilities, and related services.
Service Provider or Subprocessor
“Service Provider” or “Subprocessor” means an organization that processes information on our behalf to help us provide, secure, maintain, improve, or support the Services.
4. Information We Collect
The information we collect depends on how you interact with Cybermatic.ai, which Services you use, which systems you connect, and the choices made by you or your organization.
4.1 Information You Provide Directly
We may collect information that you provide directly to us, including:
- First and last name;
- Business or work email address;
- Telephone number;
- Job title;
- Department;
- Professional role;
- Company or organization name;
- Company size;
- Industry;
- Company website;
- Mailing address;
- Billing address;
- Account username;
- Authentication information;
- Subscription information;
- Transaction and billing information;
- Cloud platforms used by your organization;
- SaaS applications used by your organization;
- Security technologies used by your organization;
- Security and compliance objectives;
- Information included in contact forms;
- Information included in demonstration or trial requests;
- Information included in support requests;
- Information included in partnership or vendor communications;
- Communications with Cybermatic.ai personnel;
- Survey responses;
- Testimonial information;
- Product feedback;
- Information submitted during onboarding;
- Prompts, questions, instructions, and feedback submitted to artificial intelligence features; and
- Any other information you choose to provide.
Please do not provide sensitive personal information that is unnecessary for the requested Service.
4.2 Account and Authentication Information
When you create, administer, or access a Cybermatic.ai account, we may process:
- Account identifiers;
- User identifiers;
- Login timestamps;
- Logout timestamps;
- Authentication tokens;
- Multi-factor authentication status;
- Identity-provider information;
- Session information;
- Password-reset activity;
- Access permissions;
- Workspace membership;
- Organization membership;
- Administrative roles;
- User roles;
- Authentication events;
- Failed login attempts;
- Security alerts; and
- Other security events associated with the account.
Passwords are intended to be handled through secure authentication systems. We do not use account credentials for purposes unrelated to authentication, account security, or providing the Services.
4.3 Billing and Transaction Information
When a Customer purchases a subscription or paid Service, our payment processor may collect payment-card and billing information.
Cybermatic.ai may receive limited transaction information, including:
- Customer or billing name;
- Billing address;
- Subscription plan;
- Payment status;
- Transaction date;
- Invoice number;
- Payment method type;
- Last four digits of a payment card;
- Renewal information;
- Cancellation information;
- Refund information; and
- Tax or accounting information.
Full payment-card numbers and card security codes are generally collected and processed directly by our payment processor and are not intended to be stored by Cybermatic.ai.
4.4 Cloud Connection and Integration Information
When a Customer connects an authorized cloud environment, SaaS application, identity system, security platform, or other integration, we may collect or process:
- Cloud account identifiers;
- Tenant identifiers;
- Subscription identifiers;
- Organization identifiers;
- Project identifiers;
- Workspace identifiers;
- Connection names;
- Integration status;
- Read-only roles;
- Access tokens;
- API keys;
- Temporary credentials;
- Connection credentials;
- Regions;
- Availability zones;
- Service locations;
- Resource names;
- Resource identifiers;
- Resource tags;
- Resource owners;
- Resource relationships;
- Identity and access-management configurations;
- User metadata;
- Role metadata;
- Group metadata;
- Permission metadata;
- Policy metadata;
- Network configurations;
- Firewall configurations;
- Routing configurations;
- Public exposure configurations;
- Storage configurations;
- Encryption configurations;
- Logging configurations;
- Monitoring configurations;
- Backup configurations;
- Cloud-service configuration metadata;
- SaaS application metadata;
- Integration metadata;
- Security-control status;
- Vulnerability information;
- Software-version information;
- Publicly exposed endpoints;
- Security findings;
- Evidence associated with security findings;
- Connection logs;
- Synchronization logs;
- Scan logs; and
- Integration errors.
Customers are responsible for connecting only systems they own or are otherwise authorized to assess.
Cybermatic.ai’s standard cloud posture assessment is designed to examine configuration and security metadata using read-only access.
It is not designed to read the contents of:
- Customer email messages;
- Customer documents;
- Database records;
- Object-storage files;
- Source-code repositories;
- Application messages;
- Application payloads;
- Private communications; or
- Other stored customer content,
unless the Customer deliberately uploads that information or enables a feature that expressly requires access to it.
4.5 Security, Asset, and Compliance Information
To provide asset discovery, risk analysis, remediation, compliance automation, and reporting, we may process:
- Cloud asset inventories;
- SaaS asset inventories;
- Internet-facing asset inventories;
- Shadow information technology findings;
- Security configurations;
- Misconfigurations;
- Security-control gaps;
- Vulnerabilities;
- Common Vulnerabilities and Exposures information;
- Identity and access risks;
- Excessive permissions;
- Exposed services;
- Exposed credentials;
- Risk ratings;
- Risk-prioritization information;
- Attack paths;
- Attack scenarios;
- Exploitability analysis;
- Business-impact analysis;
- Remediation recommendations;
- Terraform code;
- AWS command-line instructions;
- PowerShell code;
- Python code;
- Policy changes;
- Configuration recommendations;
- Compliance-framework selections;
- Compliance-control mappings;
- Policies and procedures;
- Risk assessments;
- Evidence lists;
- Compliance-readiness information;
- Security questionnaires;
- Security scores;
- Risk scores;
- Benchmarks;
- Remediation roadmaps;
- Technical reports;
- Executive reports; and
- Board-level reports.
Some security information may identify or relate to Customer personnel, administrators, contractors, employees, or system users.
We process that information only as necessary to provide the Services and subject to the applicable Customer agreement.
4.6 Artificial Intelligence Inputs and Outputs
When Customers use artificial intelligence-enabled features, we may process:
- User prompts;
- User questions;
- User instructions;
- Conversation history;
- Relevant cloud asset information;
- Security findings;
- Identity information;
- Compliance information;
- Configuration context;
- Generated security explanations;
- Generated remediation commands;
- Generated code;
- Generated policies;
- Generated compliance documents;
- Generated reports;
- Generated recommendations;
- User ratings;
- User corrections;
- User feedback;
- Quality-assurance information; and
- Technical logs needed to operate, secure, and troubleshoot the feature.
We may transmit the minimum amount of information reasonably necessary to approved artificial intelligence infrastructure or model providers acting on our behalf.
We do not permit those providers to use Customer Content for their own advertising or unrelated commercial purposes.
Cybermatic.ai does not use Customer Content to train or improve general-purpose artificial intelligence models.
Artificial intelligence-generated information may contain errors, omissions, inaccurate assumptions, or incomplete recommendations.
Customers are responsible for reviewing outputs before:
- Applying remediation commands;
- Applying code;
- Making configuration changes;
- Adopting generated policies;
- Submitting compliance documentation;
- Providing reports to executives or boards;
- Responding to auditors;
- Making security decisions;
- Making legal decisions;
- Making financial decisions; or
- Making operational decisions.
4.7 Information Collected Automatically
When you use our websites or Services, we may automatically collect:
- Internet Protocol address;
- Browser type;
- Browser version;
- Device type;
- Device identifiers;
- Operating system;
- Language settings;
- Time-zone settings;
- Referring pages;
- Exit pages;
- Pages accessed;
- Features accessed;
- Links selected;
- Date and time of visits;
- Duration of visits;
- Approximate location derived from an Internet Protocol address;
- Cookie identifiers;
- Similar-technology identifiers;
- Application activity;
- API activity;
- Login activity;
- Logout activity;
- Feature usage;
- User-interface interactions;
- Errors;
- Crashes;
- Diagnostic information;
- Performance information;
- Availability information;
- Security events;
- Suspected abuse;
- Fraud indicators; and
- Other technical information necessary to operate and protect the Services.
We use this information for:
- Security;
- Authentication;
- Troubleshooting;
- Product functionality;
- Service measurement;
- Fraud prevention;
- Performance monitoring;
- Availability monitoring;
- Service improvement; and
- Analytics, where legally permitted.
4.8 Information From Third Parties
We may receive information from:
- Your employer;
- Your organization;
- Customer account administrators;
- Authorized resellers;
- Implementation partners;
- Managed service providers;
- Cloud platforms you choose to connect;
- SaaS platforms you choose to connect;
- Identity and authentication providers;
- Payment processors;
- Security providers;
- Fraud-prevention providers;
- Publicly available professional sources;
- Publicly available business sources;
- Referral partners; and
- Other persons or organizations acting at your direction.
4.9 Cybermatic Device Trust Mobile Application
When an individual installs the Cybermatic Device Trust App and enrolls a device, the App collects and transmits a limited set of security-posture signals about that single device, so the enrolling organization can confirm the device meets its security requirements. The App may collect:
- Device name (as assigned by the user, where the operating system permits reading it);
- Device manufacturer and model;
- Operating-system name and version;
- Operating-system security patch level (Android);
- Device-integrity status (whether the device appears jailbroken or rooted);
- Screen-lock configuration status (whether a secure screen lock is present);
- Storage-encryption status (Android);
- A persistent device identifier used to keep the device represented as a single asset (for example, an identifier-for-vendor value on iOS or an equivalent identifier on Android);
- The enrollment token associating the device with an organization’s workspace; and
- Basic diagnostic information needed to transmit reports and troubleshoot errors.
What the App does not collect. The App is designed to read only the device-security signals listed above, about the enrolled device. The App does not access, collect, read, or transmit:
- Text messages, chat messages, or email;
- Photos, videos, or the camera roll;
- Contacts;
- Precise or background location;
- Web-browsing history;
- Keystrokes;
- Microphone or call audio;
- Files or documents stored on the device;
- A list or inventory of other applications installed on the device; or
- The contents or data of any other application.
Camera permission. The App requests camera access for a single purpose: to scan the enrollment QR code provided by the organization. No photographs or video are captured, stored, or transmitted, and the camera is not used for any other purpose.
Reporting cadence. After enrollment, the App reports the device-posture signals listed above when the App is opened and, where the operating system permits, periodically in the background. An enrolled device that has not reported for an extended period may be shown to the organization as inactive.
Information collected by the App is transmitted over an encrypted connection to the organization’s Cybermatic workspace and is handled in accordance with this Privacy Policy and the applicable Customer agreement.
5. How We Use Information
We may use information for the following purposes.
5.1 Providing the Services
We may use information to:
- Create accounts;
- Administer accounts;
- Create workspaces;
- Administer workspaces;
- Authenticate users;
- Authorize users;
- Connect authorized cloud environments;
- Connect authorized SaaS environments;
- Validate connections;
- Discover assets;
- Inventory assets;
- Identify vulnerabilities;
- Identify misconfigurations;
- Identify identity risks;
- Identify exposed endpoints;
- Identify security-control gaps;
- Analyze attack scenarios;
- Analyze exploitability;
- Analyze business impact;
- Prioritize risks;
- Generate remediation guidance;
- Generate remediation code;
- Generate security policies;
- Generate compliance documents;
- Generate control mappings;
- Operate Cybermatic Copilot and related artificial-intelligence functionality;
- Generate risk scores;
- Generate benchmarks;
- Generate reports;
- Generate roadmaps;
- Store Customer settings;
- Store Customer preferences;
- Process subscriptions;
- Process payments;
- Provide technical support;
- Provide implementation support;
- Fulfill Customer instructions; and
- Provide other requested Services.
5.2 Securing the Services
We may use information to:
- Protect Customer accounts;
- Protect Customer environments;
- Protect Cybermatic.ai systems;
- Detect suspicious activity;
- Detect unauthorized activity;
- Prevent fraud;
- Prevent abuse;
- Prevent attacks;
- Prevent misuse;
- Enforce access controls;
- Monitor platform availability;
- Monitor platform integrity;
- Maintain audit logs;
- Maintain security logs;
- Investigate suspected security incidents;
- Investigate confirmed security incidents;
- Validate connection permissions;
- Protect Cybermatic.ai;
- Protect Customers;
- Protect users;
- Protect the public;
- Enforce contractual requirements; and
- Enforce acceptable-use requirements.
5.3 Communicating With You
We may use contact information to:
- Respond to inquiries;
- Provide Customer support;
- Send account notices;
- Send authentication notices;
- Send billing notices;
- Send service notices;
- Provide information about scans;
- Provide information about security findings;
- Provide information about reports;
- Provide information about platform activity;
- Communicate about demonstrations;
- Communicate about trials;
- Communicate about subscriptions;
- Communicate about renewals;
- Communicate about cancellations;
- Send security notifications;
- Send legal notifications;
- Request feedback;
- Provide educational information;
- Provide product information; and
- Send promotional communications where permitted.
You may unsubscribe from marketing communications by using the unsubscribe mechanism in the message or by contacting us.
You may continue to receive non-promotional communications necessary to:
- Administer your account;
- Provide the Services;
- Process transactions;
- Address security issues;
- Comply with law; or
- Enforce our agreements.
5.4 Maintaining and Improving the Services
We may use information to:
- Diagnose technical problems;
- Measure platform reliability;
- Measure platform performance;
- Understand feature usage;
- Understand product adoption;
- Develop improvements;
- Test improvements;
- Improve user experience;
- Improve security analyses;
- Evaluate generated outputs;
- Improve output accuracy;
- Maintain quality controls;
- Maintain safety controls;
- Develop new features;
- Develop new Services; and
- Create aggregated or de-identified statistics.
When practical, we use aggregated, de-identified, or minimized information for analytics and improvement activities.
5.5 Complying With Law and Protecting Legal Interests
We may use information to:
- Comply with applicable laws;
- Comply with regulations;
- Comply with court orders;
- Respond to lawful government requests;
- Maintain financial records;
- Maintain tax records;
- Maintain business records;
- Establish legal claims;
- Exercise legal claims;
- Defend legal claims;
- Investigate alleged contractual violations;
- Protect our rights;
- Protect our property;
- Protect our personnel;
- Protect our Customers;
- Protect users;
- Protect the public; and
- Cooperate with courts, regulators, law enforcement agencies, and other authorities when legally required.
6. Legal Bases for Processing
Where European Economic Area, United Kingdom, Swiss, or similar data-protection laws apply, our legal bases for processing may include the following.
6.1 Performance of a Contract
We may process information when necessary to:
- Create an account;
- Administer an account;
- Provide requested Services;
- Perform scans;
- Perform security analyses;
- Generate requested outputs;
- Process subscriptions;
- Process payments;
- Provide support; or
- Fulfill a Customer agreement.
6.2 Legitimate Interests
We may process information based on our legitimate interests in:
- Operating the Services;
- Maintaining the Services;
- Improving the Services;
- Protecting the security of the platform;
- Protecting Customers;
- Protecting users;
- Preventing fraud;
- Preventing abuse;
- Communicating with business Customers;
- Communicating with prospective Customers;
- Maintaining business records;
- Understanding service performance;
- Improving product functionality;
- Establishing legal claims; and
- Defending legal claims.
We consider the potential impact on individuals before relying on legitimate interests.
6.3 Consent
We may rely on consent for:
- Certain cookies;
- Certain analytics technologies;
- Optional marketing communications;
- Certain integrations;
- Testimonials;
- Optional product research;
- Processing that applicable law requires to be consent-based; or
- Other optional activities presented at the time consent is requested.
You may withdraw consent at any time.
Withdrawal of consent does not affect processing that occurred before the withdrawal.
6.4 Legal Obligation
We may process information when necessary to comply with:
- Tax requirements;
- Accounting requirements;
- Regulatory requirements;
- Judicial requirements;
- Law-enforcement requirements;
- Security-notification requirements;
- Recordkeeping requirements; and
- Other legal obligations.
6.5 Protection of Vital Interests
In limited circumstances, we may process information when necessary to protect an individual’s life, safety, or vital interests.
7. How We Disclose Information
We do not sell personal information.
We do not rent personal information.
We do not share personal information for cross-context behavioral advertising or targeted advertising.
We do not provide Customer information to third parties for their independent marketing purposes.
We may disclose information only in the limited circumstances described below.
7.1 Service Providers and Subprocessors
We may provide information to vetted Service Providers that perform services for us, including:
- Cloud-hosting providers;
- Cloud-storage providers;
- Database providers;
- Serverless-computing providers;
- Infrastructure providers;
- Content-delivery providers;
- Domain-name providers;
- Network providers;
- Traffic-management providers;
- Authentication providers;
- Identity-management providers;
- Artificial intelligence model providers;
- Artificial intelligence inference infrastructure providers;
- Payment processors;
- Subscription-management providers;
- Email providers;
- Customer-communications providers;
- Logging providers;
- Monitoring providers;
- Diagnostic providers;
- Error-management providers;
- Security providers;
- Fraud-prevention providers;
- Incident-response providers;
- Customer-support providers;
- Ticketing providers;
- Document-generation providers;
- File-processing providers;
- Analytics providers, where enabled;
- Backup providers;
- Disaster-recovery providers;
- Professional advisers;
- Auditors;
- Consultants; and
- Other vendors needed to provide Customer-requested functionality.
These organizations may process information only as necessary to provide services to Cybermatic.ai or our Customers and subject to contractual or legal restrictions.
They are not authorized to use Customer Content for:
- Their independent advertising;
- Their independent marketing;
- Data brokerage;
- Profiling unrelated to the Services;
- Training general-purpose artificial intelligence models; or
- Other unrelated commercial purposes.
Current infrastructure or Service Provider categories may include:
- Amazon Web Services for cloud infrastructure;
- Cloudflare or similar providers for network, security, or content-delivery services;
- Stripe or similar providers for payment processing;
- Authentication and identity providers;
- Approved artificial intelligence infrastructure or model providers;
- Email and communications providers; and
- Security-monitoring providers.
The providers used for a particular Customer may vary based on:
- Product configuration;
- Customer location;
- Data location;
- Selected features;
- Service availability; and
- Technical requirements.
Customers may request additional information about material subprocessors by contacting info@cybermatic.ai.
7.2 Disclosures at the Customer’s Direction
We may disclose information when a Customer:
- Activates an integration;
- Exports a report;
- Shares a report;
- Invites another user;
- Authorizes a managed service provider;
- Authorizes a consultant;
- Authorizes an auditor;
- Authorizes a partner;
- Directs us to transmit information to a third party;
- Requests a third-party integration; or
- Otherwise requests or consents to the disclosure.
The Customer is responsible for evaluating the privacy and security practices of recipients selected by the Customer.
7.3 Disclosures Within a Customer Organization
Customer account administrators may be able to:
- View organization-user information;
- Add users;
- Remove users;
- Assign roles;
- Remove roles;
- Access account activity;
- Access audit information;
- View Customer Content;
- Access security findings;
- Access generated documents;
- Access generated reports;
- Configure integrations;
- Disconnect integrations;
- Manage accounts;
- Suspend accounts;
- Delete accounts; and
- Delete Customer data.
If your account is associated with an employer or other organization, that organization may control your account and related information.
7.4 Legal Requirements and Protection
We may disclose information when we reasonably believe disclosure is necessary to:
- Comply with applicable law;
- Comply with legal process;
- Respond to a valid subpoena;
- Respond to a valid court order;
- Respond to a valid warrant;
- Respond to a lawful government request;
- Protect the rights of Cybermatic.ai;
- Protect the property of Cybermatic.ai;
- Protect the safety of Cybermatic.ai personnel;
- Protect Customers;
- Protect users;
- Protect the public;
- Investigate fraud;
- Investigate abuse;
- Investigate security incidents;
- Investigate violations of our agreements;
- Prevent illegal activity;
- Address illegal activity;
- Establish legal claims;
- Exercise legal claims; or
- Defend legal claims.
Where legally permitted, we may notify the affected Customer before disclosing Customer Content in response to a government or legal request.
7.5 Business Transactions
If Cybermatic.ai or Ironhawk Group is involved in a:
- Merger;
- Acquisition;
- Financing;
- Reorganization;
- Bankruptcy;
- Sale of assets;
- Corporate restructuring; or
- Similar business transaction,
information may be reviewed, transferred, or disclosed as part of that transaction.
Any recipient will remain subject to applicable privacy obligations.
Where required, we will provide notice of material changes affecting the handling of Personal Information.
7.6 Professional Advisers
We may provide limited information to:
- Attorneys;
- Accountants;
- Auditors;
- Insurers;
- Financial institutions;
- Consultants; and
- Other professional advisers,
when reasonably necessary for them to provide services to us and subject to applicable confidentiality obligations.
7.7 With Your Consent
We may disclose information for another purpose when you or the relevant Customer:
- Directs us to do so;
- Requests the disclosure; or
- Provides valid consent.
8. No Sale or Advertising-Based Sharing
Cybermatic.ai does not:
- Sell Personal Information for money;
- Sell Personal Information for other valuable consideration;
- Rent Customer information;
- Rent account information;
- Provide Customer cloud information to data brokers;
- Provide Customer security information to data brokers;
- Share Personal Information for cross-context behavioral advertising;
- Share Personal Information for targeted advertising;
- Use Customer Content to build advertising profiles;
- Permit Service Providers to advertise to individuals using Customer Content;
- Disclose contact-form information to third parties for their independent marketing; or
- Use security findings for unrelated advertising purposes.
Limited disclosure to Service Providers acting on our behalf is not intended to constitute a sale of Personal Information.
Those providers receive information only as reasonably necessary to provide contracted services.
9. Cookies and Similar Technologies
Cybermatic.ai may use:
- Cookies;
- Local storage;
- Log files;
- Session identifiers; and
- Similar technologies.
9.1 Strictly Necessary Technologies
Strictly necessary technologies may be used to:
- Authenticate users;
- Maintain sessions;
- Protect accounts;
- Prevent fraud;
- Prevent abuse;
- Balance traffic;
- Remember privacy choices;
- Operate essential website functions;
- Operate essential platform functions;
- Maintain security; and
- Maintain availability.
Disabling strictly necessary technologies may prevent portions of the Services from functioning.
9.2 Functional Technologies
Functional technologies may remember:
- Language preferences;
- Regional preferences;
- Display preferences;
- Accessibility preferences;
- Previously selected settings; and
- Other optional functionality.
9.3 Analytics Technologies
Where enabled and legally permitted, analytics technologies may help us understand:
- Website traffic;
- Page performance;
- Feature adoption;
- Product usage;
- Errors;
- General usage patterns;
- Navigation patterns; and
- The effectiveness of product, educational, or marketing content.
Where required, we will request consent before placing non-essential cookies or similar technologies.
You may adjust available choices through:
- Browser settings;
- Device settings; or
- Other available privacy controls.
9.4 Advertising Technologies
Cybermatic.ai does not use Customer Content for advertising and does not share Personal Information for cross-context behavioral advertising.
If we introduce advertising technologies in the future, we will:
- Update this Privacy Policy;
- Provide legally required notices;
- Provide legally required choices; and
- Obtain consent where required.
9.5 Global Privacy Control and Do Not Track
Where legally required, we recognize supported opt-out preference signals, including Global Privacy Control.
Because Cybermatic.ai does not currently sell Personal Information or share it for cross-context behavioral advertising, an opt-out signal should not materially change those practices.
Some browsers provide a “Do Not Track” setting. There is not currently a universally accepted standard for responding to all Do Not Track signals.
We will continue to evaluate applicable legal and technical standards.
10. Artificial Intelligence and Automated Processing
Cybermatic.ai uses artificial intelligence to support functions such as:
- Security-risk analysis;
- Security finding explanations;
- Attack-scenario explanations;
- Risk prioritization;
- Remediation guidance;
- Remediation code generation;
- Command generation;
- Compliance-document generation;
- Security-question responses;
- Executive reporting;
- Board-level reporting;
- Product support;
- Service improvement; and
- Quality assurance.
Cybermatic.ai’s artificial intelligence features are designed to assist human decision-making.
They are not intended to make final decisions that produce legal or similarly significant effects concerning an individual without appropriate human review.
Nothing generated by the platform should be treated as:
- Legal advice;
- Regulatory advice;
- Financial advice;
- An audit opinion;
- A compliance certification;
- A guarantee of security;
- A guarantee that vulnerabilities do not exist;
- A substitute for a qualified security professional;
- A substitute for a qualified legal professional;
- A substitute for a qualified compliance professional; or
- A substitute for professional judgment.
Customers should review artificial intelligence-generated:
- Remediation commands before execution;
- Code before execution;
- Configuration recommendations before implementation;
- Policies before adoption;
- Compliance documents before submission;
- Security findings before taking consequential action;
- Reports before providing them to executives;
- Reports before providing them to boards;
- Reports before providing them to auditors;
- Reports before providing them to insurers;
- Reports before providing them to regulators; and
- Reports before relying on them for legal, security, or business purposes.
11. Customer Responsibilities
Customers are responsible for:
- Ensuring they have authority to provide information to Cybermatic.ai;
- Connecting only systems they are authorized to assess;
- Obtaining required permissions;
- Providing legally required notices to personnel and users;
- Establishing an appropriate lawful basis for information placed in the Services;
- Managing account permissions;
- Managing user roles;
- Protecting Customer-side credentials;
- Protecting access tokens;
- Reviewing generated outputs;
- Reviewing remediation instructions;
- Reviewing code before execution;
- Configuring available retention settings;
- Configuring available deletion settings;
- Responding to privacy requests involving information the Customer controls;
- Maintaining appropriate backups;
- Complying with industry-specific obligations;
- Complying with jurisdiction-specific obligations; and
- Complying with contractual obligations.
Unless expressly authorized under a written agreement, Customers should not submit:
- Protected health information regulated by the Health Insurance Portability and Accountability Act;
- Full payment-card data;
- Card security codes;
- Social Security numbers;
- Equivalent government identifiers;
- Biometric templates;
- Highly sensitive consumer records;
- Classified government information;
- Export-controlled technical data;
- Criminal-justice information;
- Information subject to special government handling requirements; or
- Other regulated information requiring contractual safeguards that Cybermatic.ai has not agreed to provide.
12. Data Security
Cybermatic.ai uses administrative, technical, physical, and organizational safeguards designed to protect information against:
- Unauthorized access;
- Unauthorized disclosure;
- Unauthorized alteration;
- Misuse;
- Loss;
- Destruction;
- Theft;
- Accidental exposure; and
- Unlawful processing.
Depending on the system and information involved, safeguards may include:
- Encryption in transit;
- Encryption at rest;
- Read-only cloud-access architecture;
- Least-privilege permissions;
- Role-based access controls;
- Multi-factor authentication;
- Logging;
- Monitoring;
- Customer-workspace segregation;
- Secure credential management;
- Secure secrets management;
- Vulnerability management;
- Patch management;
- Backup controls;
- Recovery controls;
- Security testing;
- Code review;
- Employee confidentiality obligations;
- Contractor confidentiality obligations;
- Security-awareness practices;
- Incident-response procedures;
- Vendor risk-management practices; and
- Periodic review of security controls.
Access to Customer Content is restricted to authorized personnel and Service Providers with a legitimate need to access it for:
- Support;
- Security;
- Operations;
- Troubleshooting;
- Legal compliance; or
- Another authorized purpose.
No computer system, cloud service, network, or transmission method can be guaranteed to be completely secure.
Customers are responsible for:
- Using strong authentication;
- Enabling multi-factor authentication when available;
- Safeguarding credentials;
- Limiting user permissions;
- Reviewing account activity;
- Revoking unnecessary access;
- Securing Customer-managed devices; and
- Promptly notifying us of suspected unauthorized access.
To report a suspected security issue, contact info@cybermatic.ai and include “Security” in the subject line.
13. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:
- Provide the Services;
- Maintain account functionality;
- Maintain security;
- Prevent fraud;
- Comply with law;
- Resolve disputes;
- Enforce agreements;
- Maintain financial records;
- Maintain tax records; and
- Maintain legitimate business records.
Retention periods depend on factors such as:
- The type of information;
- The sensitivity of the information;
- The Customer’s subscription;
- The Customer’s configuration;
- The duration of the Customer relationship;
- Whether the information is needed to provide a requested feature;
- Security requirements;
- Fraud-prevention requirements;
- Backup cycles;
- Disaster-recovery cycles;
- Contractual requirements;
- Legal limitation periods;
- Tax requirements;
- Accounting requirements;
- Regulatory requirements; and
- Other recordkeeping obligations.
13.1 Account and Contact Information
Account and contact information may be retained while an account or business relationship remains active and afterward as reasonably necessary for:
- Administration;
- Legal compliance;
- Dispute resolution;
- Contract enforcement;
- Fraud prevention; and
- Security.
13.2 Customer Content
If a free trial ends without conversion to a paid subscription, associated Customer Content is retained for approximately thirty (30) days following the end of the trial so the Customer can resume where they left off, and is then deleted or scheduled for deletion, subject to the backup-rotation, legal, security, and fraud-prevention considerations described in this Privacy Policy. We will attempt to notify the account email before deletion occurs.
Customer Content is generally retained while needed to provide the Services or as directed by the Customer.
Following account closure or termination, Customer Content may remain for a limited period to support:
- Account recovery;
- Orderly deletion;
- Legal requirements;
- Security investigations;
- Fraud prevention;
- Contract enforcement; and
- Secure backup rotation.
13.3 Connection Credentials and Tokens
Connection credentials and tokens may be retained while necessary to maintain an authorized integration.
Customers may disconnect integrations or revoke access through:
- Cybermatic.ai;
- The relevant cloud provider;
- The relevant SaaS provider;
- The relevant identity provider; or
- Another connected platform.
Credentials may remain in protected backups for a limited period before being overwritten through normal backup rotation.
13.4 Billing Records
Billing and transaction records may be retained as required for:
- Tax purposes;
- Accounting purposes;
- Transaction management;
- Fraud prevention;
- Chargeback management;
- Dispute resolution; and
- Legal compliance.
13.5 Security and Audit Logs
Security and audit logs may be retained for periods reasonably necessary to:
- Protect the Services;
- Detect threats;
- Investigate incidents;
- Prevent abuse;
- Enforce agreements;
- Support audits; and
- Satisfy security or legal requirements.
13.6 Support Communications
Support communications may be retained while needed to:
- Resolve the issue;
- Maintain service history;
- Improve support;
- Investigate recurring problems;
- Protect security; and
- Satisfy legal obligations.
When retention is no longer justified, we will delete, de-identify, aggregate, or securely isolate the information, subject to technical and legal limitations.
14. Deletion and Account Closure
Customers may request account closure or deletion by contacting:
Email: info@cybermatic.ai
Subject line: Account Closure or Privacy Request
Before completing a request, we may need to:
- Verify the requester’s identity;
- Verify the requester’s authority;
- Confirm the scope of the request;
- Coordinate with an account administrator;
- Preserve information required by law;
- Preserve information necessary for security;
- Preserve information necessary for fraud prevention;
- Preserve billing records;
- Preserve information related to legal claims;
- Preserve information necessary for contract enforcement; or
- Explain information that cannot reasonably be deleted from active backups immediately.
Mobile device unenrollment. An individual may stop the Cybermatic Device Trust App from collecting and transmitting device-posture information at any time by unenrolling the device within the App, which removes the stored enrollment token and cancels background reporting, or by uninstalling the App. A Customer administrator may also remove an enrolled device from the organization’s workspace. Following unenrollment or removal, previously reported device-posture records are retained or deleted in accordance with the retention and backup practices described in Section 13.
Deleting information may prevent continued use of some or all Services.
When an individual’s request concerns information controlled by a Cybermatic.ai Customer, we may:
- Direct the individual to the Customer;
- Notify the Customer;
- Assist the Customer as required by contract; or
- Assist the Customer as required by law.
15. International Data Transfers
Cybermatic.ai and its Service Providers may process information in the United States and other countries where we or our providers maintain operations.
These countries may have privacy and data-protection laws that differ from those in your jurisdiction.
Where required, we use recognized safeguards for international transfers, which may include:
- Standard contractual clauses;
- Data-processing agreements;
- Contractual confidentiality requirements;
- Contractual security requirements;
- Adequacy decisions;
- Transfer-risk assessments;
- Technical safeguards;
- Organizational safeguards; or
- Other legally recognized transfer mechanisms.
You may contact us for additional information about safeguards applicable to your information.
16. Your Privacy Rights
Depending on your location and applicable law, you may have the right to:
- Know whether we process your Personal Information;
- Request access to Personal Information;
- Request information about categories of information collected;
- Request information about sources of information;
- Request information about the purposes of processing;
- Request information about recipients;
- Obtain a copy of Personal Information;
- Correct inaccurate Personal Information;
- Delete Personal Information;
- Restrict certain processing;
- Object to certain processing;
- Request data portability;
- Withdraw consent;
- Opt out of certain targeted advertising;
- Opt out of certain sales;
- Opt out of certain sharing;
- Opt out of certain profiling;
- Limit certain uses of sensitive Personal Information;
- Appeal a decision concerning a privacy request;
- Lodge a complaint with a data-protection authority; and
- Receive equal service and treatment without unlawful discrimination for exercising privacy rights.
These rights are not absolute.
Applicable law may permit or require us to deny or limit a request when information is needed to:
- Complete a transaction;
- Provide a requested Service;
- Maintain security;
- Detect fraud;
- Prevent abuse;
- Exercise free-speech rights;
- Exercise other legal rights;
- Comply with law;
- Establish legal claims;
- Exercise legal claims;
- Defend legal claims;
- Maintain legally privileged information; or
- Fulfill another legally recognized exception.
16.1 Submitting a Privacy Request
Submit privacy requests using the following contact information:
Email: info@cybermatic.ai
Subject line: Privacy Request
Mailing Address:
Cybermatic.ai by Ironhawk Group
Privacy Team
9330 Lyndon B Johnson Fwy
Suite 900
Dallas, TX 75243
United States
Please describe:
- The privacy right you wish to exercise;
- The information or account involved;
- Your relationship with Cybermatic.ai;
- Your state or country of residence; and
- How we can contact you.
16.2 Verification
We may verify a request by asking for information that reasonably matches our records.
We will request only the information reasonably necessary to verify:
- Identity;
- Authority;
- Account ownership; and
- The scope of the request.
We may deny or limit a request when:
- We cannot reasonably verify the requester;
- We cannot verify the requester’s authority;
- The request appears fraudulent;
- The request appears abusive;
- The request is excessive;
- The request is unauthorized; or
- Applicable law permits or requires denial.
16.3 Authorized Agents
Where permitted, you may authorize an agent to submit a request on your behalf.
We may require:
- Written authorization;
- Verification of your identity;
- Evidence of the agent’s authority;
- Direct confirmation from you; or
- Other legally permitted documentation.
16.4 Appeals
If applicable law provides an appeal right and we deny a privacy request, you may appeal by:
- Replying to our decision; or
- Emailing info@cybermatic.ai with “Privacy Appeal” in the subject line.
17. Additional Notice for California Residents
This section supplements the remainder of this Privacy Policy for California residents.
17.1 Categories of Personal Information
Depending on your interaction with us, we may collect the following categories of Personal Information.
Identifiers
Examples include:
- Name;
- Email address;
- Internet Protocol address;
- Account identifier;
- User identifier; and
- Company contact information.
Customer-Record Information
Examples include:
- Telephone number;
- Mailing address;
- Billing address; and
- Payment-related information.
Commercial Information
Examples include:
- Subscription information;
- Transaction history;
- Trial history;
- Demonstration history;
- Service history; and
- Product-interest information.
Internet or Electronic-Network Activity
Examples include:
- Website usage;
- Login activity;
- Application activity;
- API activity;
- Device information;
- Browser information;
- Cookie information; and
- Security logs.
Approximate Geolocation
Examples include general location inferred from an Internet Protocol address.
Professional or Employment-Related Information
Examples include:
- Employer;
- Job title;
- Department;
- Professional role; and
- Business contact information.
Sensitive Personal Information
Examples may include:
- Account login credentials;
- Authentication tokens;
- Cloud connection credentials;
- API credentials; and
- Other information needed to authenticate or maintain an authorized connection.
Inferences
Examples may include:
- Security-risk classifications;
- Account-security assessments;
- Product-interest information;
- Service-usage patterns; and
- Risk-prioritization information derived from other data.
Customer-Provided Content
Customer-provided content may fall within one or more categories depending on what the Customer submits.
17.2 Sources of Personal Information
We may collect Personal Information from:
- You;
- Your organization;
- Account administrators;
- Connected systems;
- Connected integrations;
- Payment processors;
- Identity providers;
- Service Providers;
- Referral partners;
- Implementation partners; and
- Automatically collected website and platform activity.
17.3 Business and Commercial Purposes
We may use these categories of Personal Information to:
- Provide the Services;
- Support the Services;
- Authenticate users;
- Authorize users;
- Process payments;
- Protect security;
- Prevent fraud;
- Prevent abuse;
- Communicate with Customers;
- Improve performance;
- Improve functionality;
- Maintain records;
- Comply with law;
- Enforce agreements; and
- Perform the purposes described elsewhere in this Privacy Policy.
17.4 Categories of Recipients
We may disclose Personal Information to:
- Cloud and infrastructure providers;
- Payment processors;
- Authentication providers;
- Identity providers;
- Security providers;
- Monitoring providers;
- Artificial intelligence infrastructure providers;
- Artificial intelligence model providers;
- Communications providers;
- Support providers;
- Professional advisers;
- Government authorities when legally required;
- Parties involved in a business transaction; and
- Other recipients at the Customer’s direction.
17.5 Sale and Sharing
Cybermatic.ai has not sold Personal Information and does not sell Personal Information.
Cybermatic.ai has not shared Personal Information for cross-context behavioral advertising and does not share Personal Information for cross-context behavioral advertising.
Cybermatic.ai does not knowingly sell or share the Personal Information of individuals under 16 years of age.
17.6 Sensitive Personal Information
We use sensitive Personal Information only as reasonably necessary to:
- Authenticate users;
- Protect accounts;
- Maintain authorized integrations;
- Provide requested Services;
- Prevent fraud;
- Prevent security incidents;
- Detect security incidents;
- Investigate security incidents;
- Comply with law; and
- Perform other purposes permitted without a right to limit.
We do not use sensitive Personal Information to infer characteristics about individuals for advertising purposes.
17.7 California Privacy Rights
Subject to applicable law, California residents may request:
- Access to categories of Personal Information;
- Access to specific pieces of Personal Information;
- Correction of inaccurate Personal Information;
- Deletion of Personal Information;
- Information about sources;
- Information about purposes;
- Information about recipients;
- Opt-out of sale;
- Opt-out of sharing;
- Limitation of certain sensitive-information uses; and
- Non-discriminatory treatment.
Because we do not sell Personal Information or share it for cross-context behavioral advertising, an opt-out request should not materially change our current practices.
We will nevertheless process legally recognized preference signals and requests as required by law.
18. Rights in Other United States Jurisdictions
Residents of United States jurisdictions with comprehensive privacy laws may have rights similar to those described above, including rights to:
- Access Personal Information;
- Correct Personal Information;
- Delete Personal Information;
- Obtain a portable copy of Personal Information;
- Opt out of certain processing;
- Opt out of certain sales;
- Opt out of certain targeted advertising;
- Opt out of certain profiling; and
- Appeal a decision.
Cybermatic.ai does not:
- Sell Personal Information;
- Use Customer Content for targeted advertising;
- Share Personal Information for cross-context behavioral advertising; or
- Profile individuals in furtherance of decisions producing legal or similarly significant effects.
We will respond to verified requests in accordance with applicable law.
19. Rights in the European Economic Area, United Kingdom, and Switzerland
Depending on applicable law, individuals may have rights to:
- Be informed about processing;
- Access Personal Information;
- Correct inaccurate Personal Information;
- Request erasure;
- Restrict processing;
- Object to processing based on legitimate interests;
- Object to direct marketing;
- Receive portable data;
- Withdraw consent;
- Obtain information about international-transfer safeguards; and
- Lodge a complaint with a supervisory authority.
You may also have the right to object to a decision based solely on automated processing when that decision produces legal or similarly significant effects.
Cybermatic.ai’s artificial intelligence features are intended as decision-support tools and are not designed to make final decisions producing legal or similarly significant effects concerning individuals without meaningful human involvement.
20. Children’s Privacy
Cybermatic.ai is a business-to-business cybersecurity platform and is not intended for children or individuals under 18 years of age.
We do not knowingly collect Personal Information directly from children.
If we learn that a child has provided Personal Information without appropriate authorization, we will take reasonable steps to delete it.
Contact info@cybermatic.ai if you believe a child has provided Personal Information to us.
21. Third-Party Services and Links
The Services may contain links to or integrations with:
- Third-party websites;
- Cloud platforms;
- SaaS applications;
- Identity providers;
- Payment processors;
- Security platforms;
- Communications providers; and
- Other third-party services.
This Privacy Policy does not govern third parties’ independent practices.
Their privacy policies, terms, and contracts govern information they process for their own purposes.
Connecting a third-party service may authorize information to flow between that service and Cybermatic.ai.
Customers should review:
- The permissions requested;
- The information exchanged;
- The third party’s privacy practices;
- The third party’s security practices; and
- The third party’s contractual terms,
before enabling an integration.
22. Security Incident Communications
If we determine that a security incident involving Personal Information requires notice under applicable law or contract, we will provide legally required notices to:
- Affected Customers;
- Affected individuals;
- Regulators;
- Government authorities; or
- Other required recipients.
Customers are responsible for maintaining accurate:
- Account-contact information;
- Administrative-contact information;
- Billing-contact information; and
- Security-contact information.
23. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- Changes to the Services;
- New features;
- New integrations;
- Changes to Service Providers;
- Changes to subprocessors;
- Security developments;
- Operational developments;
- Legal requirements;
- Regulatory requirements; or
- Changes to our privacy practices.
We will post the updated Privacy Policy on this page and revise the “Last Updated” date.
If a change materially affects how we use Personal Information, we will provide additional notice when required.
Such notice may include:
- An account notice;
- An email;
- A website banner;
- A platform notification; or
- A request for consent.
24. Contact Us
Questions, complaints, concerns, or requests relating to this Privacy Policy may be directed to:
Cybermatic.ai by Ironhawk Group
Privacy Team
9330 Lyndon B Johnson Fwy
Suite 900
Dallas, TX 75243
United States
Email: info@cybermatic.ai
Phone: (800) 439-3040
Website: https://cybermatic.ai
For suspected security vulnerabilities or security incidents, include “Security” in the email subject line.
For privacy-rights requests, include “Privacy Request” in the email subject line.
For appeals of privacy-rights decisions, include “Privacy Appeal” in the email subject line.
We will review privacy complaints and attempt to resolve legitimate concerns in accordance with applicable law.