Privacy Policy
Last updated: September 2026
StrikeCyber Inc. ("StrikeCyber", "we", "us", "our") is an offensive cyber security firm operating across the United States. Protecting information is our profession, and it is central to how we run our own business. This Privacy Policy explains how we collect, use, secure, disclose and retain personal information, and the rights you have in relation to it.
The United States has no single federal privacy statute covering all personal information. We handle personal information in accordance with applicable state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states as they take effect. Where sector-specific law applies to information we handle on a client's behalf, including HIPAA or the Gramm-Leach-Bliley Act, that law and our engagement agreement govern.
This policy applies to our website at strikecyber.com, our client portal and platform, and the delivery of our services. It does not override any separate written agreement, statement of work, business associate agreement or rules of engagement, which govern how we handle data within a specific engagement.
Personal information we collect
Information you give us. Your name, business email address, telephone number, employer, job title and any details you include when you contact us, request a consultation, report an incident or subscribe to our research.
Engagement information. When we deliver services, we necessarily encounter information within your environment. That may include employee names and email addresses, credentials discovered during testing, system and network configuration, and, depending on scope, personal information held in the systems being tested. We treat all of it as confidential client data governed by your engagement agreement, not as data we hold for our own purposes.
Portal and platform information. Account identifiers, authentication events, access logs and the actions you take within our client portal.
Website information. IP address, browser and device characteristics, referring pages and the pages you view, collected through analytics as described below.
We do not seek sensitive personal information about you as an individual, and we ask that you do not send it to us through our website forms.
How we use your information
We use personal information to respond to your enquiries, scope and deliver engagements, operate and secure our platform, issue reports and invoices, meet our legal and contractual obligations, and send research or service updates you have asked for. We use it to improve our services and, where you have not opted out, to contact you about services related to those you have already discussed with us.
We do not sell personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under California law. We have not done so in the preceding twelve months.
AI-assisted processing
Our methodology is AI-augmented. Automated tooling performs reconnaissance, correlation and repetitive validation, and assists in drafting findings. Every finding is reviewed and confirmed by a human operator before it reaches a report.
Where we use third-party AI services in delivering an engagement, we use them under enterprise agreements that prohibit training on our inputs and provide zero data retention. Your data is not pooled with other clients' data, is not used to improve public models, and is not sold.
How we protect and isolate your data
Client findings, reports and engagement records are isolated per client and stored in access-limited environments we control. Access is granted on a least-privilege basis, is logged, and is reviewed. We apply encryption in transit and at rest, multi-factor authentication for administrative access, and the segregation controls we would expect to find when assessing a client.
No control set is absolute, and we will not claim otherwise. If a security incident affecting your personal information occurs, we will act as described under Security incidents below.
Disclosure and sub-processors
We disclose personal information only where necessary, to:
- Service providers and sub-processors who support our operations, including cloud infrastructure, communications, email delivery, analytics and professional advisers, under contracts requiring confidentiality and appropriate security;
- Your organization, where you are an authorized contact on an engagement;
- Regulators, law enforcement or courts, where we are legally required to do so; and
- A successor entity, in connection with a merger, acquisition or sale of assets, subject to this policy.
We do not disclose client engagement data to any party outside the engagement without your instruction, except where legally compelled.
Where your information is held
Our infrastructure is located in the United States. Where a service provider processes information outside the United States, we require contractual protections consistent with this policy. Where an engagement agreement specifies data residency requirements, those requirements govern.
Cookies, analytics and your choices
Our website uses cookies and similar technologies for basic operation and for analytics that help us understand how the site is used. We use Google Analytics through Google Tag Manager. You can control cookies through your browser settings.
We honor the Global Privacy Control and other recognized opt-out preference signals sent by your browser as a valid request to opt out of sale and sharing where applicable law provides that right.
Retention
We retain personal information only as long as needed for the purpose it was collected, to meet legal, tax and professional obligations, and to resolve disputes. Engagement records and reports are retained for the period specified in your engagement agreement; where none is specified, our default retention period is seven years from the end of the engagement, after which records are securely destroyed. Enquiry information from prospects who do not proceed is deleted within a reasonable period.
Security incidents
If we become aware of a security incident that has compromised personal information we hold, we will investigate promptly, take steps to contain and remediate it, and notify affected individuals and, where required, state attorneys general or other regulators, within the timeframes set by applicable state breach notification law. Where the affected information belongs to a client environment, we will notify you without unreasonable delay so that you can meet your own notification obligations, and we will support you in doing so.
Your privacy rights
Depending on where you live, you may have the right to:
- Know and access the categories and specific pieces of personal information we hold about you;
- Correct inaccurate personal information;
- Delete personal information we hold about you;
- Obtain a portable copy of personal information you provided to us;
- Opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or profiling with legal or similarly significant effects. We do not carry out any of these activities; and
- Not be discriminated against for exercising any of these rights.
To exercise a right, contact us using the details below. We will verify your identity before acting, which may require us to ask for information sufficient to confirm you are the person the information relates to. We will respond within the period required by applicable law, generally 45 days, and may extend once where permitted.
Authorized agents. You may use an authorized agent to submit a request. We may ask the agent for proof of authorization and may still verify your identity directly.
Appeals. If we decline your request, you may appeal by replying to our decision. We will respond to an appeal within the period required by your state's law, generally 45 or 60 days, and will explain our reasoning. If your appeal is denied, you may contact your state attorney general.
Engagement data. Where your personal information appears in a client environment we assessed, the client is the controller of that information and we act on its instructions. Please direct your request to that organization; if you contact us, we will refer you to them.
Third-party links
Our website and research contain links to third-party sites. We are not responsible for their content or privacy practices, and we encourage you to read their policies.
Children
Our services are provided to organizations, not to consumers, and our website is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. The current version is always available at this page, and the date it was last updated appears above. Material changes will be highlighted here.
Contact
Questions, requests and complaints about privacy can be sent to info@strikecyber.com, or by mail to StrikeCyber Inc., 3723 Greenville Ave STE 55230, Dallas, TX 75206.
If you are not satisfied with our response, you may contact the attorney general in your state, or, if you are a California resident, the California Privacy Protection Agency.
