TRUST CENTER
Your exercise data is protected.
Cyber Ambush holds a record of how your organization responds under pressure. Here's how we protect it and what's next. We are continuously improving our security.
Detailed controls are on Security & Compliance; what's coming is on our public roadmap.
01 / Compliance status
Where we stand
SOC 2 Type I
IN PROGRESSWe're completing our SOC 2 Type I examination; the report will be available under NDA once issued. Need it for a vendor review? Email cyberambush@sterlingllc.com.
SOC 2 Type II
PLANNEDFollows our Type I report, covering the operating effectiveness of our controls over time.
NIST-aligned exercises
AVAILABLEExercises and AARs map to NIST CSF 2.0, SP 800-61r3, SP 800-84 and HSEEP.
Data Processing Addendum
AVAILABLEOur DPA covers roles, subprocessors, breach notification and deletion.
Read the DPA →02 / Security controls
Security controls at a glance
- Multi-factor authentication enforced for every account
- Organization data isolation enforced in the database on every request
- Encryption in transit (HTTPS/TLS) and at rest
- Role-based access: AI support limited to Sponsors and Operators
- Audit trail of who released injects, committed responses, approved guidance and called ENDEX
- No training of AI models on customer exercise content
- Synthetic-data-only design: no PHI, payment data or production secrets
- Automated access-rule and dependency scanning before release
- Deletion of your data within 30 days of written request
03 / Subprocessors
Who processes data for us
| Provider | Legal entity | Purpose | Data processed | Location |
|---|---|---|---|---|
| Lovable | Lovable Labs Incorporated | Application hosting, build and content delivery for cyberambush.com | Application code and every request served to the application | United States |
| Supabase | Supabase, Inc. | Postgres database, authentication (including multi-factor authentication) and file storage | Organizations, accounts, exercises, injects, responses, decisions, after-action reports | United States |
| Amazon Web Services | Amazon Web Services, Inc. | Cloud infrastructure beneath the database and storage provider | The same records at rest, encrypted by the platform | United States |
| Lovable AI gateway | Lovable Labs Incorporated | Routes AI requests to the model provider for the planning assistant, response assessment and after-action report drafting | Scenario and inject text, planning guidance, Participant responses | United States |
| Google (Gemini models) | Google LLC | Large language model inference reached through the AI gateway | The exercise text listed in the row above, for the duration of the request | United States |
| Resend | Resend, Inc. | Transactional email delivery (invitations, reminders, after-action notices) | Recipient name and email address, exercise name, join link | United States |
Lovable
Lovable Labs Incorporated · United States
Application hosting, build and content delivery for cyberambush.com
Data: Application code and every request served to the application
Supabase
Supabase, Inc. · United States
Postgres database, authentication (including multi-factor authentication) and file storage
Data: Organizations, accounts, exercises, injects, responses, decisions, after-action reports
Amazon Web Services
Amazon Web Services, Inc. · United States
Cloud infrastructure beneath the database and storage provider
Data: The same records at rest, encrypted by the platform
Lovable AI gateway
Lovable Labs Incorporated · United States
Routes AI requests to the model provider for the planning assistant, response assessment and after-action report drafting
Data: Scenario and inject text, planning guidance, Participant responses
Google (Gemini models)
Google LLC · United States
Large language model inference reached through the AI gateway
Data: The exercise text listed in the row above, for the duration of the request
Resend
Resend, Inc. · United States
Transactional email delivery (invitations, reminders, after-action notices)
Data: Recipient name and email address, exercise name, join link
04 / Vulnerability disclosure
Report a security issue
Found a security vulnerability in Cyber Ambush? Email support@sterlingllc.com with "Security" in the subject line. We are constantly improving our product and services.
05 / Documents
Documents on request
Security questionnaire, architecture overview and current SOC 2 status, available to customers and prospects. Email cyberambush@sterlingllc.com.