TRUST CENTER

Your exercise data is protected.

Cyber Ambush holds a record of how your organization responds under pressure. Here's how we protect it and what's next. We are continuously improving our security.

Detailed controls are on Security & Compliance; what's coming is on our public roadmap.

01 / Compliance status

Where we stand

SOC 2 Type I

IN PROGRESS

We're completing our SOC 2 Type I examination; the report will be available under NDA once issued. Need it for a vendor review? Email cyberambush@sterlingllc.com.

SOC 2 Type II

PLANNED

Follows our Type I report, covering the operating effectiveness of our controls over time.

NIST-aligned exercises

AVAILABLE

Exercises and AARs map to NIST CSF 2.0, SP 800-61r3, SP 800-84 and HSEEP.

Data Processing Addendum

AVAILABLE

Our DPA covers roles, subprocessors, breach notification and deletion.

Read the DPA →

02 / Security controls

Security controls at a glance

03 / Subprocessors

Who processes data for us

  • Lovable

    Lovable Labs Incorporated · United States

    Application hosting, build and content delivery for cyberambush.com

    Data: Application code and every request served to the application

  • Supabase

    Supabase, Inc. · United States

    Postgres database, authentication (including multi-factor authentication) and file storage

    Data: Organizations, accounts, exercises, injects, responses, decisions, after-action reports

  • Amazon Web Services

    Amazon Web Services, Inc. · United States

    Cloud infrastructure beneath the database and storage provider

    Data: The same records at rest, encrypted by the platform

  • Lovable AI gateway

    Lovable Labs Incorporated · United States

    Routes AI requests to the model provider for the planning assistant, response assessment and after-action report drafting

    Data: Scenario and inject text, planning guidance, Participant responses

  • Google (Gemini models)

    Google LLC · United States

    Large language model inference reached through the AI gateway

    Data: The exercise text listed in the row above, for the duration of the request

  • Resend

    Resend, Inc. · United States

    Transactional email delivery (invitations, reminders, after-action notices)

    Data: Recipient name and email address, exercise name, join link

04 / Vulnerability disclosure

Report a security issue

Found a security vulnerability in Cyber Ambush? Email support@sterlingllc.com with "Security" in the subject line. We are constantly improving our product and services.

05 / Documents

Documents on request

Security questionnaire, architecture overview and current SOC 2 status, available to customers and prospects. Email cyberambush@sterlingllc.com.