When you submit the Live Review or Deep Review intake form, we collect: your name, company, email address, the product URL(s) or repository details you provide, and any notes you include. For the Deep Review specifically, we also collect your typed electronic signature and a timestamp, as confirmation of the signed NDA and Services Agreement.
We do not use cookies, analytics trackers, or session recording on this site beyond what's needed to serve the page itself.
| Tier | What we access | How |
|---|---|---|
| Live Review | Your product's public-facing pages, forms, and checkout flow | Same way any visitor or customer would — no credentials, no account access |
| Deep Review | Read-only access to specified code repositories | Granted by you (e.g. a scoped deploy key or time-limited collaborator invite), revoked by you at any time, and by us automatically at engagement end |
We do not request write access, admin access, or access to production credentials, customer data, or infrastructure secrets as part of either tier. If a Deep Review finding requires us to reference something sensitive we encountered (e.g. an exposed key), we describe the finding and its location without reproducing the sensitive value itself in our report.
Portions of our internal review process use Anthropic's Claude API to assist in analyzing code and drafting findings. We do not submit your full repository to any AI provider — only the specific code sections relevant to a given check, as needed to generate that portion of the report. Per Anthropic's commercial API terms, submitted data is not used to train their models by default.
Repository access: revoked at the end of the engagement (or immediately upon your request). We do not retain clones or copies of your source code after the engagement concludes.
Findings reports: retained for 12 months after delivery, in case you need to reference or re-request your report, then deleted. You may request earlier deletion at any time.
Contact/intake form data: retained for our own billing and engagement records. To request deletion of your information, email privacy@cyberglobal.ai with the subject line "Data Request" and we'll respond within 5 business days.
For Deep Review engagements, confidentiality of everything we access is governed by the Mutual Non-Disclosure Agreement signed at engagement start — see the Deep Review signing page for the full text. Live Review findings are shared only with you; we do not publish, reference, or discuss specific client findings without explicit permission.
If your product handles PHI, financial account data, or other regulated information, do not include real instances of that data in your intake form notes or point us at systems containing live customer PHI/PII beyond what's necessary for the engagement. If a Deep Review engagement will unavoidably expose us to such data as part of reviewing your code (not the data itself, but code that processes it), let us know in advance so we can scope access accordingly.
Payments are processed securely through Stripe, which follows PCI-DSS standards. We never see or store your full card details.
Questions about this policy or a data request: email privacy@cyberglobal.ai. General inquiries: info@cyberglobal.ai.