Skip to content

Security

Security at Cybermatic

You trust us with the map of your weaknesses. This page describes, in plain terms and without overstatement, how that data is protected. Our own trust page, with live-verified controls, is published with the same Trust Center feature our customers use.

Infrastructure

  • ·Runs on AWS (us-east-1) using managed, serverless services — no long-lived servers to patch, no shared hosts.
  • ·Every customer's data is stored under its own workspace key in encrypted storage (AES-256 at rest, TLS 1.2+ in transit). Files you upload — policies, NDA documents — live in an encrypted bucket that is never public.
  • ·Cloud connections are read-only by design: the roles we ask for can list and describe, never create, modify, or delete. You review the permissions before granting them and can revoke them from your console at any time.

Backups & resilience

  • ·Point-in-time recovery on every database table (any second in the last 35 days) plus scheduled backups copied to a second AWS region (us-west-2).
  • ·Customer documents are versioned, replicated to the second region, and additionally held in an object-locked backup store that cannot be deleted early — even by an administrator.
  • ·Restores are tested; deletion protection is enabled on production tables.

Monitoring & availability

  • ·Every public component is probed every five minutes by an independent monitor; the results, response times, and 90-day uptime are published on our status page.
  • ·Alarms page the team on API errors, failed scheduled jobs, silent agent fleets, email-delivery problems, and component outages.
  • ·Enterprise plans carry a written 99.9% monthly uptime SLA, measured from that same probe record.

Access to your data

  • ·Support access to a customer workspace is read-only (every write is refused server-side), limited to 60 minutes, requires a recorded reason, is written to the workspace's audit trail, and triggers an email to the workspace owner at the moment it starts.
  • ·Team access inside your workspace is role-based per product (administrator / viewer); destructive capabilities such as remote wipe are a separate, owner-granted privilege with their own audit entries.
  • ·We never sell customer data, never share it with third parties beyond the sub-processors required to run the service, and never use it to train models.

Authentication & keys

  • ·Sign-in is backed by Amazon Cognito with password policies and MFA; Enterprise plans add self-serve SAML single sign-on (Entra ID, Okta, any SAML 2.0 IdP) so your MFA, conditional-access, and offboarding policies apply automatically.
  • ·API keys are workspace-scoped, read-only, shown once, stored hashed, rate-limited, and revocable instantly; every call is attributed to its key.
  • ·Agent updates are signed; agents verify the manifest signature before installing any update.

Application security

  • ·Public endpoints (trust pages, request forms, NDA links, marketplace fulfillment) are rate-limited per source and protected against automated submission.
  • ·All customer-facing changes are deployed through reviewed builds; secrets are held in AWS Secrets Manager and replicated to the second region.
  • ·Quarantined files stay on your endpoints in local encrypted stores — only detection metadata reaches Cybermatic.

Reporting a vulnerability

Found something? Email info@cybermatic.ai with the details and steps to reproduce. We acknowledge reports within two business days, keep you informed through the fix, and never pursue good-faith researchers who respect customer data and give us reasonable time to remediate.

System status & uptime →Privacy policy →API documentation → Security questions →