The EPCYBER Intelligence Platform publishes its commitments in writing.
The documents below describe how we handle data, who we choose to work with, what conduct we require from clients, and the standards we hold ourselves to.
They are written in plain language, kept current, and designed to be read by procurement counsel, compliance teams, prospective clients, and anyone evaluating whether EIP is the right partner for serious work.
We update these documents as our practices, our scale, and the legal environment evolve. Where a change is material, the updated date at the top of each document reflects when the change was made. If you have a question that isn't answered here, or if you need additional documentation as part of a procurement or due-diligence process, contact us.
Privacy Statement
How we collect, use, and protect personal data when you visit our websites, contact us, subscribe to our blog, purchase or attend training, or engage with us as a client or partner. Covers US state privacy laws, and the controller / processor distinction that governs platform use by clients. Published by EPCYBER and applies across all EPCYBER properties, including EIP.
Read the Privacy Statement →Acceptable Use Policy
The conduct expected of clients, authorized users, and other parties who access or use the EIP platform. Sets the minimum baseline alongside the Master Services Agreement and other contractual terms. Covers permitted use, prohibited use, client responsibilities, and enforcement.
Read the Acceptable Use Policy →Information Security
Our approach to information security — principles, architecture, data handling, vendor posture, personnel, incident response, compliance, and threat awareness. A public overview suitable for procurement evaluation, with detailed documentation provided privately on request.
Read the Information Security overview ↓Subprocessors
A current list of material subprocessors — hosting, infrastructure, identity management, payment processing, and other services — is available on request to clients and prospective clients under appropriate confidentiality terms. We notify clients of material changes in accordance with applicable agreements.
Available on requestSupply-chain integrity
We evaluate any potential vendor against criteria including jurisdiction, ownership, and security posture. We do not engage vendors whose ownership, jurisdiction, or compliance posture would create unacceptable risk for the missions our clients support. Vendor changes affecting client engagements are notified in accordance with applicable agreements.
Policy in effectOur approach to information security.
A public overview of our approach to information security, suitable for procurement evaluation. Detailed documentation is provided privately on request.
Principles
We apply least privilege, defense in depth, and data minimization. Security is treated as a design constraint, not an afterthought.
Architecture and data handling
Access is controlled and logged. Data is segregated and handled according to its sensitivity, with encryption in transit and at rest where appropriate.
Vendor posture
We evaluate vendors against jurisdiction, ownership, and security criteria, and we do not engage vendors whose posture would create unacceptable risk for the missions our clients support.
Personnel
Personnel are subject to appropriate screening for their role, bound by confidentiality obligations, and granted access on a need-to-know basis.
Incident response
We maintain incident-response procedures and notify affected clients of material incidents in accordance with applicable agreements and law.
Compliance and threat awareness
We align our controls with recognized standards and maintain awareness of the threat environment relevant to the ecosystems we cover.
Questions, or documentation for procurement and due diligence: demo@epcyber.com · Security-specific inquiries: security@epcyber.com