Privacy policy
This policy describes what Cyber Ambush collects, why we collect it, who we share it with, and the choices you have. Cyber Ambush is operated by Sterling Readiness Group, LLC, which is the controller of personal data processed through the service.
Effective date: September 17, 2026
What we collect
The categories of information we process when you use Cyber Ambush.
- Account data: name, work email, department, organization and assigned role.
- Exercise data: scenarios, injects, planning guidance, Participant responses, decisions, timestamps and after-action reports.
- Contact form submissions: name, work email, organization, sector, team size, vector of interest and message text.
- Server and security logs: standard request, error and security logs needed to operate and protect the service.
Why we process it
The purposes for which we use the data we collect.
- To provide and operate the Cyber Ambush platform.
- To produce after-action reports for each exercise.
- To respond to inquiries submitted through the contact form.
- To keep the service secure and to investigate abuse or errors.
What we do not want
Content that should not be entered into an exercise or submitted to us.
- The platform is designed for synthetic scenario content.
- Customers must not submit regulated personal data, live case material or production secrets into an exercise or contact form.
- We do not knowingly collect special-category or sensitive personal data.
Who we share it with
How we disclose personal data and the limits we apply.
- We share data with the subprocessors listed in the Subprocessors table on our Security page.
- We do not sell personal data.
- We do not share personal data for cross-context behavioral advertising.
AI processing
How large language models are used with exercise content.
- Exercise content is sent to a large language model through our AI gateway provider for exercise planning and scenario drafting, for response assessment and for after-action report drafting.
- We do not train models on customer exercise content.
- See the How exercise data reaches the AI section on our Security page for more detail.
Retention and deletion
How long we keep data and how to request deletion.
- Exercise records, decisions and after-action reports are retained for as long as your organization keeps its account so they remain available as audit evidence.
- An after-action report can be exported at any time.
- On written request, whether during the subscription or after termination, we will permanently delete an organization's exercise data and personal data within 30 days and confirm when the deletion is complete.
- We will retain data beyond that period only where applicable law requires it, and only for as long as that requirement lasts.
- Contact form submissions are kept no longer than needed to handle the inquiry.
Your rights
Choices you have about your personal data.
- You may request access, correction, deletion, portability or object to processing of your personal data.
- To exercise any of these rights, email privacy@sterlingllc.com, the privacy mailbox of Sterling Readiness Group, LLC, which operates Cyber Ambush. You can also use the contact page if you prefer.
- We do not discriminate against anyone who exercises their privacy rights.
Cookies
What cookies and similar technologies the site uses.
The site uses a session cookie to keep you signed in. We do not use third-party advertising or analytics trackers.
Children
Age limits for using the service.
Cyber Ambush is not directed to, and we do not knowingly collect personal data from, anyone under 16.
International transfers
Where personal data is processed.
Personal data is processed in the United States.
Changes to this policy
How we notify you of updates.
We may update this policy from time to time. The effective date at the top of the page shows when it was last revised. Continued use of Cyber Ambush after a change means you accept the revised policy.
Data processing addendum
The agreement that governs how we process personal data on your behalf.
Our Data Processing Addendum describes the roles, categories of data, subprocessors, security measures, breach notification and deletion obligations that apply when we process personal data for your organization.
How to contact us
Questions, requests and concerns about this policy.
Sterling Readiness Group, LLC is the controller of personal data processed through Cyber Ambush.
Sterling Readiness Group, LLC41 Peabody St
Nashville, TN 37210
United States
+1 629-280-5900
If you have questions about this policy or want to exercise your rights, email privacy@sterlingllc.com or reach out through the contact page.