Security
Security at CyberAwareHub
We sell security awareness training. It would be a poor look to be careless with your data, so here is how we handle it.
Your data, and who controls it
When your organisation enrols its people, you remain in control of their data. We process it only on your instructions, under a Data Processing Agreement that meets Article 28 of the GDPR. You can export your data at any time, and we delete or return it within 30 days of you leaving.
Individual users can download everything we hold about them, and delete their account, directly in their settings. No support ticket, no waiting.
How we protect accounts
- Two-factor authentication, which you can require across your whole organisation
- Strong passwords enforced everywhere — minimum twelve characters with mixed case, numbers and symbols, applied consistently at sign-up, password change and reset
- We never see your password. Authentication is handled by a specialist provider, and second-factor secrets are encrypted while backup codes and device tokens are stored only as one-way hashes
- Automatic protection against password guessing on every sign-in route — and if that protection cannot run, we refuse the request rather than let it through
That last point is worth spelling out, because it is where systems usually fail quietly: when a security control breaks, ours denies access instead of waving traffic past.
Keeping organisations separate
Every request is checked against the organisation of the signed-in user, and never against an identifier supplied by the browser. An independent review of every part of our application found no way for one customer to reach another's data.
Encryption and infrastructure
Everything is encrypted in transit, and your data is encrypted at rest. Card details go straight to Stripe and never touch our systems.
We publish our full list of sub-processors, including where each one processes data, and we give customers 30 days' notice before that list changes.
Where your data lives
Our servers are currently in the United Kingdom, which the EU recognises as providing an adequate level of protection, and our email provider processes in the United States under approved safeguards. We are moving to EU hosting, and our sub-processors page always shows the current position.
We would rather tell you exactly where your data is than say something vaguer that sounds better.
Audit trail
Significant actions are recorded with who did what and when, and your managers can review that log for their own organisation. Audit records are written before the action they describe, so the record of a deletion outlives the deletion.
Independent assurance
We completed a structured internal security review across authentication, access control, configuration, data handling and GDPR obligations in August 2026, covering every part of the application, and we fixed what it found.
Note
We have not yet had an independent penetration test, and we are not ISO 27001 certified. An external test is our next assurance milestone. We would rather tell you that than let you discover it in a questionnaire — and if either matters for your procurement, talk to us about timing.
Reporting a vulnerability
If you believe you have found a security issue, email our security contact at [SECURITY_EMAIL]. We will acknowledge within two business days and keep you updated. We will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.
Documentation for security reviews
Available on request to customers and prospective customers:
- Data Processing Agreement
- Completed security questionnaire
- Data protection impact assessment input pack
- Retention schedule
- Mapping of our training content to NIS2 Article 21(2)(g) and ISO 27001:2022 control 6.3
Request documentation Contact [SECURITY_EMAIL] or [PRIVACY_EMAIL].