[ P-01 — DATA COLLECTION ]
What XCYB Collects
XCYB collects information directly provided by organizations and individuals through active intake processes. Collection does not occur passively outside of these interactions.
Organizational inquiry information. Organization name, operational role, briefing type selection, organizational scale, contact email, and operational context notes submitted through the briefing intake form.
Consultation and assessment data. Technical and organizational information provided during strategic briefings, deployment evaluations, infrastructure assessments, and enterprise consultations.
Capability submissions. Work samples, research documents, architecture materials, and operational records submitted as part of capability assessments or recruitment evaluation.
Direct correspondence. Any communication exchanged during an active engagement, evaluation, or consultation process.
XCYB does not deploy advertising trackers, behavioral profiling systems, or third-party analytics that collect information about individuals not engaged in an active intake process.
[ P-02 — INFORMATION USAGE ]
How XCYB Uses Collected Information
Information collected through XCYB intake processes is used exclusively for operational purposes directly related to the engagement or evaluation for which it was submitted.
Operational routing. Directing briefing requests to the appropriate XCYB operational team for review and processing.
Evaluation processing. Assessing organizational fit, operational alignment, and deployment qualification for potential XCYB engagements.
Engagement management. Conducting follow-up communications, structured briefings, and consultations with organizations that have been admitted to an active engagement process.
Capability assessment. Reviewing submitted records during recruitment, capability evaluation, and selection processes.
XCYB does not use submitted information for advertising, remarketing, or commercial profiling. Submitted information is not sold, licensed, or transferred to third parties for commercial purposes.
[ P-03 — SECURITY COMMITMENT ]
How XCYB Protects Submitted Information
As a sovereign defense infrastructure organization, XCYB applies the same operational security posture to its own data handling that it architects for its clients.
Information submitted to XCYB is treated with institutional confidentiality equivalent to operational client data. It does not leave the organization.
Restricted access. Information is accessible only to XCYB operational personnel with a direct need-to-know in relation to the active intake or engagement.
No third-party commercial sharing. XCYB does not share intake or consultation information with third-party commercial vendors, data brokers, or partner organizations for commercial purposes.
Engagement-scoped retention. Information is not retained beyond the operational engagement lifecycle without active, explicit engagement authorization from the submitting organization.
Confidentiality by default. Organizational details, infrastructure context, and operational information disclosed during any XCYB process are treated as confidential by default — not as shareable intelligence.
[ P-04 — AI INTERACTION NOTICE ]
Autonomous Briefing Intelligence
XCYB is developing an autonomous briefing intelligence system (AEON) to assist with pre-qualification, consultation routing, and operational intake processing.
Information handling. When deployed, information submitted through the AEON briefing intelligence system will be processed for intake evaluation and operational routing purposes.
No training use. Interactions with the autonomous briefing system are not stored for model training, behavioral profiling, or any purpose beyond the immediate intake evaluation.
Human review. The autonomous briefing system does not make final engagement or access decisions. All engagements are reviewed and authorized by XCYB operational personnel.
Policy applicability. Information processed through the AI intake system is subject to the same data handling practices described throughout this policy.
[ STATUS: DEPLOYMENT PENDING ]
The autonomous briefing intelligence system is not yet in active deployment. This section is provided in advance of system activation as part of XCYB's commitment to transparency regarding AI use in its operational intake processes.
[ P-05 — DATA PROTECTION ]
Your Rights Over Submitted Data
Organizations and individuals that have submitted information through XCYB intake processes may request review, correction, or deletion of that information.
Data review. Request a summary of what information XCYB holds from a specific intake submission or engagement.
Data correction. Request correction of inaccurate or outdated information submitted through an intake or consultation process.
Data deletion. Request deletion of submitted information. XCYB will process deletion requests within 30 days, except where retention is required to fulfill active operational obligations.
Response commitment. XCYB will acknowledge and respond to all data requests within 30 operational days of receipt.
Following the conclusion of an engagement or evaluation, XCYB retains organizational data only for a period sufficient to fulfill any outstanding operational obligations. There is no indefinite retention.
[ P-06 — INFRASTRUCTURE & DATA RESIDENCY ]
Infrastructure and Data Residency
XCYB TECH operates its web infrastructure on Cloudflare's global network. Information submitted through XCYB intake channels is processed and transmitted over Cloudflare's infrastructure, which maintains enterprise-grade security, DDoS mitigation, and TLS encryption in transit.
Data in transit. All information submitted through XCYB intake channels is encrypted in transit using TLS. No unencrypted transmission of intake data occurs.
Infrastructure jurisdiction. XCYB's web infrastructure operates on Cloudflare's global network. Cloudflare's data processing agreements and sub-processor disclosures are available at cloudflare.com/privacypolicy.
Residency options for regulated deployments. Organizations operating under jurisdictional data residency requirements — including EU, GCC, or government mandates — may request information on available data residency configurations during the deployment review process.
Enterprise DPA. Data Processing Agreements for enterprise and regulated deployment engagements are available upon request. Raise this requirement during the briefing or deployment evaluation process.
For questions regarding infrastructure jurisdiction, data residency configurations, or enterprise DPA requirements, use the XCYB operational intake channel and identify the inquiry as infrastructure-related.
[ P-07 — CONTACT ]
Privacy Inquiries
For privacy-related inquiries, data requests, or concerns regarding how XCYB handles submitted information, use the XCYB operational intake channel. Identify the inquiry as privacy-related in the operational context field.
This policy applies to all information submitted through XCYB TECH's operational intake channels, websites, and direct correspondence, effective June 2025.
XCYB TECH reserves the right to update this policy as operational practices evolve. Material changes will be reflected in the effective date above.