How we handle your exercise data.
A provider of crisis exercises has to make its own security verifiable. This page states what applies today, and what we deliberately do not claim.
Built to stay out of your production environment.
Verdus Cyber runs entirely in the browser. The exercise simulates your crisis: it never connects to the systems that would be in one.
- Browser-based: no agent, no VPN, no software rollout
- No access to your production systems: the crisis is simulated, your infrastructure stays untouched
- Tenant-isolated exercise workspace per customer
- TLS encryption for all data in transit
- Encryption at rest as a standard of the hosting infrastructure; we name it as such, not as a certificate of our own
Four commitments, in writing.
Exercise data (injects, decisions, debrief results) belongs to you. These four rules are part of the contract, not of a marketing page.
A data processing agreement (Art. 28 GDPR) including the subprocessor list is part of every engagement, not an optional add-on.
You can export your exercise data whenever you ask: during the engagement and at its end.
We delete your exercise data on request. No silent archives, no retention you did not agree to.
Exercise data is processed solely to prepare, run and debrief your exercise. It is not used for advertising and not passed to third parties.
Who runs the infrastructure.
Two companies process data on our behalf. Here they are: by name, with what they do.
Vercel Inc.
Hosts this marketing website and processes technically necessary connection data in server logs. Details in the privacy policy.
Supabase
Operates the tenant-isolated platform database and the realtime engine behind the exercise workspace.
We disclose hosting locations and EU data residency options in the first call: before you sign anything, and before we promise anything we cannot show.
No badges we haven't earned.
Trust pages usually collect seals. Ours states plainly which audits we have not been through, and what you can verify instead.
We do not claim
- ISO 27001 certification
- SOC 2 attestation
Until an accredited auditor has actually issued them, these badges will not appear on this site.
What you can verify instead
- We answer your security questionnaire (CAIQ / SIG Lite) before contract signature
- Architecture review in the demo call (bring your security team)
- Named subprocessors and a DPA including the subprocessor list before signature
Found a weakness? Tell us directly.
If you discover a vulnerability in the platform or on this website, write to us. Security reports are read with priority, and every submission gets an answer.
Questions security teams ask.
Where does our exercise data live?
In a tenant-isolated workspace on the platform database, operated by Supabase. This marketing website is hosted separately by Vercel and sets no cookies and no tracking. Hosting locations and EU data residency options are disclosed in the first call.
Who sees the exercise results?
The participants and facilitators of your exercise: nobody else. Tenant isolation keeps every customer workspace separate, and results are not passed to third parties.
Does our IT need to install anything?
No. The exercise runs in the browser: no agent, no VPN, no software rollout, and no access to your production systems.
How long is exercise data stored?
For the duration of your engagement. You can export it at any time and have it deleted on request; retention beyond the engagement (for example, year-over-year comparison) happens only if you ask for it.
Is there a data processing agreement (DPA)?
Yes. A DPA under Art. 28 GDPR, including the subprocessor list, is the contract standard in every engagement, and you receive it before signature.
Bring your security questionnaire.
Book a demo and put the architecture in front of your security team, then we answer CAIQ or SIG Lite before you sign.