Trust & Compliance

Security, Data Handling & GDPR

The overwhelming majority of what we process is open-source and commercial threat intelligence โ€” not client personal data. Here is how we handle data, our security posture, and our GDPR position.

๐Ÿ‡ช๐Ÿ‡บ EU-based (Netherlands)๐Ÿ”’ Encrypted & isolated๐Ÿ“„ DPA on request๐ŸŸข TLP:GREEN feed
1

What we process

  • Threat intelligence (primary): public indicators (IPs, domains, hashes), CVE / vulnerability data, ransomware leak-site postings and malware signatures โ€” from OSINT, commercial and government sources. Not client personal data.
  • Client profile: sector, operating regions, technology stack and security tooling โ€” business metadata used to tailor intelligence.
  • Limited personal data: client contact details (name, work email) for account access and briefing delivery.
  • Exposure monitoring (opt-in): where a client subscribes to leaked-credential / dark-web monitoring, we process breached data relating to that client's own organisation, solely to alert them to their exposure.
2

What we never do

  • We never sell or rent client data.
  • We never use client data to train AI models.
  • We never share data between tenants โ€” strict logical isolation, continuously audited.
  • We do not repurpose leaked-credential data beyond alerting the affected client.
3

Hosting & data residency

  • EU-based (Netherlands) โ€” data held within the EU.
  • Origin infrastructure is not exposed to the public internet (reverse-tunnel ingress); TLS enforced end-to-end; automated bot / abuse protection at the edge.
  • Multi-tenant platform with strict per-tenant isolation, enforced in code and verified by an automated isolation check on every deployment.
4

Security controls

  • Encryption: TLS in transit; sensitive secrets encrypted at rest.
  • Access control: role-based, least-privilege; authorisation re-derived on every request; server-side sessions.
  • Change safety: deployments gated by automated tests with rollback; tenant-isolation checks run each release.
  • Backups: encrypted, portable backups of application data and configuration.
5

Data retention & deletion

  • Threat-intel indicators are aged out automatically under a time-to-live policy.
  • Client account & profile data is retained for the contract term and deleted on request or termination.
  • Backups are held for a limited window, then securely destroyed. Specific periods are set out in the Data Processing Agreement.
6

GDPR position

  • Roles: the client is the Controller; CoreCyberOps acts as Processor, processing personal data only on documented client instruction.
  • Legal basis: performance of contract and legitimate interest in security.
  • DPA: a Data Processing Agreement is available on request.
  • Data-subject rights (access, rectification, erasure) are supported via the client Controller.
7

Sub-processors & breach notification

  • Sub-processors: a current list (hosting, email delivery and enrichment providers) is provided on request; clients are notified of material changes.
  • Breach notification: on a confirmed incident affecting a client's data, we notify that client without undue delay, with impact, scope and remediation. Incident response is our core competency.
Privacy & security contact: [email protected] PGP: corecyberops.com/pgp.asc DPA & sub-processor list: available on request
This overview summarises current practices; a full Data Processing Agreement and security documentation are available under NDA.
CoreCyberOps ยท Threat Intelligence  ยท  Overview  ยท  Security