Last updated · 11 September 2026

Privacy Notice

This notice explains what personal data the CyberKSA platform holds, why it holds it, who can reach it, and what you can ask us to do with it. It covers the platform itself: the public pages, the console our testers work in, and the portal your own people sign in to.

01What we hold

For the people who use the platform: a name, a work email address, a role, and the record of when they signed in and from where. For an engagement: the scope you agreed with us, the findings our testers raise, the evidence attached to them, and the messages exchanged about them. Evidence is whatever a tester captures to prove a finding, and it can contain data from your systems.

02Why we hold it

To carry out the security testing you engaged us for, to produce the report at the end of it, to let your own people follow the findings and their remediation, and to keep a record of who did what, which a security engagement requires and a regulator may ask for.

03Where it goes

Nowhere. Findings, evidence and report documents stay inside the platform. They are not synchronised to any external service, analytics provider or ticketing system on their own. Where you ask us to push a finding into your own tracker, that happens only after somebody on your side signs an undertaking, only for the finding named in it, and the platform records that it happened. Email is the one other way anything leaves: notifications, sign-in codes, and a report you have asked us to send.

04Who can reach it

Our testers and reviewers assigned to your engagement, and your own people whom you have given portal access. A person given access to your organisation sees your projects and nothing else: every internal endpoint refuses them. A finding is not visible to your side until a reviewer publishes it, and a report document is not readable until a team lead approves its release. Both actions are recorded with who took them and when.

05How long we keep it

Engagement data is kept for the term of the contract and for the period agreed in it afterwards, so that a retest can be compared against the original test and so that we can answer a question about a finding a year later. CONFIRM: the default period. Sign-in records are kept for twelve months. When a retention period ends, the data is deleted rather than archived.

06How it is protected

Signing in requires a password and a one-time code sent to your email. Credentials for any tracker you connect are encrypted before they are stored, so a copy of the database is not a set of live keys into your systems. Every action that changes a finding, releases a report, or grants access is written to an audit trail.

07Your rights

Under the Saudi Personal Data Protection Law you may ask what we hold about you, ask for it to be corrected, ask for it to be deleted where we are not required to keep it, and object to how it is used. Write to the address below and we will answer within thirty days. If you are not satisfied, you may complain to the Saudi Data and Artificial Intelligence Authority.

08Cookies

The platform sets a cookie to keep you signed in and a cookie to remember which language you chose. There is no advertising cookie and no third-party analytics on any page, signed in or not.

09Contact

Questions about this notice, or a request about your data: ops@cyber.com.sa. CONFIRM: the data protection officer's named contact.

See also
Terms of Use