Legal

Privacy Policy

Last updated: August 24, 2026 · Cyber Global Technologies LLC
The short version: for the Live Review, we only touch what's already public on your site — no account, no data collection beyond your submission form. For the Deep Review, repo access is read-only, time-boxed, and revoked at the end of the engagement — nothing is cloned or retained. This page explains exactly what we collect and why.

1.What We Collect

When you submit the Live Review or Deep Review intake form, we collect: your name, company, email address, the product URL(s) or repository details you provide, and any notes you include. For the Deep Review specifically, we also collect your typed electronic signature and a timestamp, as confirmation of the signed NDA and Services Agreement.

We do not use cookies, analytics trackers, or session recording on this site beyond what's needed to serve the page itself.

2.How Audits Are Performed

TierWhat we accessHow
Live ReviewYour product's public-facing pages, forms, and checkout flowSame way any visitor or customer would — no credentials, no account access
Deep ReviewRead-only access to specified code repositoriesGranted by you (e.g. a scoped deploy key or time-limited collaborator invite), revoked by you at any time, and by us automatically at engagement end

We do not request write access, admin access, or access to production credentials, customer data, or infrastructure secrets as part of either tier. If a Deep Review finding requires us to reference something sensitive we encountered (e.g. an exposed key), we describe the finding and its location without reproducing the sensitive value itself in our report.

3.Third-Party AI Processing

Portions of our internal review process use Anthropic's Claude API to assist in analyzing code and drafting findings. We do not submit your full repository to any AI provider — only the specific code sections relevant to a given check, as needed to generate that portion of the report. Per Anthropic's commercial API terms, submitted data is not used to train their models by default.

4.Data Retention & Deletion

Repository access: revoked at the end of the engagement (or immediately upon your request). We do not retain clones or copies of your source code after the engagement concludes.

Findings reports: retained for 12 months after delivery, in case you need to reference or re-request your report, then deleted. You may request earlier deletion at any time.

Contact/intake form data: retained for our own billing and engagement records. To request deletion of your information, email privacy@cyberglobal.ai with the subject line "Data Request" and we'll respond within 5 business days.

5.Confidentiality

For Deep Review engagements, confidentiality of everything we access is governed by the Mutual Non-Disclosure Agreement signed at engagement start — see the Deep Review signing page for the full text. Live Review findings are shared only with you; we do not publish, reference, or discuss specific client findings without explicit permission.

6.Do Not Submit Regulated Data You're Not Authorized to Share

If your product handles PHI, financial account data, or other regulated information, do not include real instances of that data in your intake form notes or point us at systems containing live customer PHI/PII beyond what's necessary for the engagement. If a Deep Review engagement will unavoidably expose us to such data as part of reviewing your code (not the data itself, but code that processes it), let us know in advance so we can scope access accordingly.

7.Payments

Payments are processed securely through Stripe, which follows PCI-DSS standards. We never see or store your full card details.

8.Contact

Questions about this policy or a data request: email privacy@cyberglobal.ai. General inquiries: info@cyberglobal.ai.