Privacy Policy
Last updated August 12, 2026
1. Scope
This Privacy Policy explains how StudioCyber handles personal and business information in connection with inquiries, proposals, penetration testing, security assessments, retesting, reporting, and related professional services. It also covers the limited information collected through studiocyber.co, which serves as an introduction to the business and a way to request services.
A written services agreement, statement of work, data-processing agreement, or rules of engagement may contain additional or more specific requirements for a client engagement. Those terms control where they conflict with this general policy.
2. Information handled in connection with services
Depending on the engagement, StudioCyber may handle:
- Client and relationship information: names, business contact details, job roles, company information, communications, proposals, contracts, and billing records.
- Scoping and authorization information: target systems, applications, APIs, networks, cloud environments, mobile applications, AI systems, testing windows, points of contact, rules of engagement, and evidence of authorization.
- Access information: test accounts, temporary credentials, access instructions, allowlisted addresses, and configuration details provided for an authorized assessment.
- Testing and system information: requests and responses, logs, screenshots, configuration details, application behavior, model outputs, prompts, network information, and other technical data observed or generated during authorized testing.
- Findings and work product: vulnerability details, proof-of-concept material, affected assets, risk analysis, remediation guidance, reports, presentation materials, and retest results.
- Incidental personal information: personal information that may be present in or exposed by a client system while an authorized assessment is being performed.
3. How information is obtained
We receive information directly from clients, prospective clients, their personnel, and authorized representatives. We also generate or observe information while performing authorized services against the systems and environments included in the agreed scope. Additional information may come from vetted specialists, service providers, and public or commercially available sources used to support an engagement.
4. How information is used
StudioCyber may use information to:
- evaluate inquiries and prepare scopes, proposals, and agreements;
- confirm authorization and establish rules of engagement;
- perform penetration testing and other requested assessments;
- document evidence, analyze risk, and prepare findings and reports;
- communicate with clients and coordinate remediation and retesting;
- select and manage vetted specialists matched to the agreed scope;
- secure our systems, detect misuse, and maintain business records;
- comply with legal obligations and enforce agreements; and
- improve internal methods using aggregated or de-identified information that does not identify a client or individual.
Where applicable law requires a legal basis, processing may be necessary to take steps at a client's request, perform a contract, pursue legitimate business and security interests, comply with law, or act with consent.
5. Client instructions and responsibilities
StudioCyber handles engagement information only for legitimate, authorized purposes and within the agreed scope. Clients are responsible for having authority to provide systems, accounts, data, and instructions for testing, and for identifying any legal, regulatory, contractual, or data-handling restrictions that apply.
When StudioCyber processes personal information on a client's behalf, the client's documented instructions and the applicable services or data-processing agreement govern that processing.
6. How information is disclosed
We may disclose information to:
- vetted specialists and subcontractors when their expertise is required for an engagement and subject to confidentiality and scope restrictions;
- providers supporting secure communications, file transfer, cloud infrastructure, email, business operations, and security;
- professional advisers such as attorneys, accountants, auditors, and insurers;
- authorities or other parties when required by law or reasonably necessary to protect rights, safety, systems, or users; and
- a successor or prospective successor in connection with a merger, financing, acquisition, reorganization, or sale of business assets.
StudioCyber does not sell personal information and does not share personal information for cross-context behavioral or targeted advertising.
7. Confidentiality and security
We use reasonable administrative, technical, and organizational safeguards designed to protect engagement information. Access is limited to people and providers who need it for an authorized business purpose. Findings, reports, credentials, and client system information are treated as confidential in accordance with the applicable agreement.
No transmission or storage method is completely secure. Clients should not send credentials, private keys, exploit material, regulated data, or sensitive production data through the public website form. StudioCyber will establish an appropriate transfer method when sensitive information is required for an engagement.
8. Retention and disposal
We retain information for as long as reasonably necessary to scope and perform services, deliver and support reports, complete retests, maintain required business records, meet contractual or legal obligations, resolve disputes, and protect our services. Engagement agreements may establish specific retention or return requirements.
When information is no longer required, we take reasonable steps to delete, return, anonymize, or securely dispose of it, subject to backup cycles, legal obligations, and the need to preserve records relating to claims or completed work.
9. Website and inquiry information
The website may collect the name, email address, company, and project details submitted through its contact form. Website hosting and infrastructure providers may also generate internet protocol addresses, browser and device details, requested pages, timestamps, and security or diagnostic logs. Limited cookies or similar technologies may be used to operate and secure the site.
This information is used to respond to inquiries, operate and protect the website, prevent abuse, and maintain business records. The website is not intended to collect sensitive engagement material.
10. International processing
StudioCyber, its specialists, and its service providers may process information in the United States and other countries where privacy laws may differ from those in your location. Where required, we use appropriate safeguards for cross-border transfers.
11. Privacy rights
Depending on where you live and the context in which information is processed, you may have rights to request access, correction, deletion, or a portable copy; to object to or restrict certain processing; to withdraw consent; or to appeal a decision. These rights may be subject to legal exceptions and, for client-controlled engagement data, may need to be exercised through the client.
To submit a request, email ilan@studiocyber.co. We may verify your identity and authority before completing a request. We will not discriminate against you for exercising an applicable privacy right.
12. Children's privacy
StudioCyber provides business-to-business services and does not knowingly solicit or collect personal information directly from children under 13. If you believe a child has provided information directly to us, contact us so we can review and delete it where appropriate.
13. Changes to this policy
We may update this policy as our services, practices, or legal obligations change. The revised policy will be posted on this page with an updated effective date. Material changes may also be communicated through an appropriate business channel.
14. Contact
Questions or requests concerning this policy may be sent to ilan@studiocyber.co.