Security & Trust

How we handle your exercise data.

A provider of crisis exercises has to make its own security verifiable. This page states what applies today, and what we deliberately do not claim.

Architecture

Built to stay out of your production environment.

Verdus Cyber runs entirely in the browser. The exercise simulates your crisis: it never connects to the systems that would be in one.

  • Browser-based: no agent, no VPN, no software rollout
  • No access to your production systems: the crisis is simulated, your infrastructure stays untouched
  • Tenant-isolated exercise workspace per customer
  • TLS encryption for all data in transit
  • Encryption at rest as a standard of the hosting infrastructure; we name it as such, not as a certificate of our own
trust boundary
────────────────────────
browser-based: no agent, no VPN
no access to production systems
tenant-isolated workspace
TLS in transit
encrypted at rest (hosting standard)
Your data, your control

Four commitments, in writing.

Exercise data (injects, decisions, debrief results) belongs to you. These four rules are part of the contract, not of a marketing page.

01
DPA as the contract standard

A data processing agreement (Art. 28 GDPR) including the subprocessor list is part of every engagement, not an optional add-on.

02
Export at any time

You can export your exercise data whenever you ask: during the engagement and at its end.

03
Deletion on request

We delete your exercise data on request. No silent archives, no retention you did not agree to.

04
Purpose-bound processing

Exercise data is processed solely to prepare, run and debrief your exercise. It is not used for advertising and not passed to third parties.

Subprocessors

Who runs the infrastructure.

Two companies process data on our behalf. Here they are: by name, with what they do.

Website hosting

Vercel Inc.

Hosts this marketing website and processes technically necessary connection data in server logs. Details in the privacy policy.

Platform database & realtime

Supabase

Operates the tenant-isolated platform database and the realtime engine behind the exercise workspace.

We disclose hosting locations and EU data residency options in the first call: before you sign anything, and before we promise anything we cannot show.

What we don't claim

No badges we haven't earned.

Trust pages usually collect seals. Ours states plainly which audits we have not been through, and what you can verify instead.

We do not claim

  • ISO 27001 certification
  • SOC 2 attestation

Until an accredited auditor has actually issued them, these badges will not appear on this site.

What you can verify instead

  • We answer your security questionnaire (CAIQ / SIG Lite) before contract signature
  • Architecture review in the demo call (bring your security team)
  • Named subprocessors and a DPA including the subprocessor list before signature
Report a vulnerability

Found a weakness? Tell us directly.

If you discover a vulnerability in the platform or on this website, write to us. Security reports are read with priority, and every submission gets an answer.

info@verduscyber.com

Bring your security questionnaire.

Book a demo and put the architecture in front of your security team, then we answer CAIQ or SIG Lite before you sign.

Privacy policy · Legal notice (Impressum)