We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Security

Responsible disclosure

Found a security issue in our platform, website or services? Report it to us and we will acknowledge and triage it. We do not pursue researchers who act in good faith.

How to report

Email security@cybersigmacs.com with a clear description of the issue, the affected asset or URL, the steps to reproduce it, and any supporting proof of concept. Please give us reasonable time to investigate and remediate before any public disclosure.

Scope

This policy covers CyberSigma-operated assets — our website (cybersigmacs.com), the SigmaTrust and SigmaTrust Privacy platforms, and our other product workspaces. Third-party services we do not operate are out of scope; report those to the relevant provider.

Please avoid

  • Accessing, modifying or deleting data that is not yours.
  • Denial-of-service testing, spam, or social-engineering of our staff or customers.
  • Any action that degrades service for other users.

Our safe-harbour commitment

If you make a good-faith effort to comply with this policy, we will treat your research as authorised, work with you to understand and resolve the issue quickly, and not pursue or support legal action against you for the report.

What to expect

We acknowledge reports and begin triage promptly. In the event of a reportable security incident affecting customer data, we notify affected customers within a 6-hour SLA, in line with CERT-In directions and our contractual commitments. We will keep you informed of remediation progress and, where appropriate, credit your contribution.

Related

For architecture, SLA, subprocessor, penetration-test and other trust documents, see the Trust Center document request workflow. To request our Data Processing Addendum (DPA), use the same workflow.