Trust Center

The EPCYBER Intelligence Platform publishes its commitments in writing.

The documents below describe how we handle data, who we choose to work with, what conduct we require from clients, and the standards we hold ourselves to.

They are written in plain language, kept current, and designed to be read by procurement counsel, compliance teams, prospective clients, and anyone evaluating whether EIP is the right partner for serious work.

We update these documents as our practices, our scale, and the legal environment evolve. Where a change is material, the updated date at the top of each document reflects when the change was made. If you have a question that isn't answered here, or if you need additional documentation as part of a procurement or due-diligence process, contact us.

Privacy Statement

How we collect, use, and protect personal data when you visit our websites, contact us, subscribe to our blog, purchase or attend training, or engage with us as a client or partner. Covers US state privacy laws, and the controller / processor distinction that governs platform use by clients. Published by EPCYBER and applies across all EPCYBER properties, including EIP.

Read the Privacy Statement →

Acceptable Use Policy

The conduct expected of clients, authorized users, and other parties who access or use the EIP platform. Sets the minimum baseline alongside the Master Services Agreement and other contractual terms. Covers permitted use, prohibited use, client responsibilities, and enforcement.

Read the Acceptable Use Policy →

Information Security

Our approach to information security — principles, architecture, data handling, vendor posture, personnel, incident response, compliance, and threat awareness. A public overview suitable for procurement evaluation, with detailed documentation provided privately on request.

Read the Information Security overview ↓

Subprocessors

A current list of material subprocessors — hosting, infrastructure, identity management, payment processing, and other services — is available on request to clients and prospective clients under appropriate confidentiality terms. We notify clients of material changes in accordance with applicable agreements.

Available on request

Supply-chain integrity

We evaluate any potential vendor against criteria including jurisdiction, ownership, and security posture. We do not engage vendors whose ownership, jurisdiction, or compliance posture would create unacceptable risk for the missions our clients support. Vendor changes affecting client engagements are notified in accordance with applicable agreements.

Policy in effect
Information Security

Our approach to information security.

A public overview of our approach to information security, suitable for procurement evaluation. Detailed documentation is provided privately on request.

Principles

We apply least privilege, defense in depth, and data minimization. Security is treated as a design constraint, not an afterthought.

Architecture and data handling

Access is controlled and logged. Data is segregated and handled according to its sensitivity, with encryption in transit and at rest where appropriate.

Vendor posture

We evaluate vendors against jurisdiction, ownership, and security criteria, and we do not engage vendors whose posture would create unacceptable risk for the missions our clients support.

Personnel

Personnel are subject to appropriate screening for their role, bound by confidentiality obligations, and granted access on a need-to-know basis.

Incident response

We maintain incident-response procedures and notify affected clients of material incidents in accordance with applicable agreements and law.

Compliance and threat awareness

We align our controls with recognized standards and maintain awareness of the threat environment relevant to the ecosystems we cover.

Questions, or documentation for procurement and due diligence: demo@epcyber.com · Security-specific inquiries: security@epcyber.com