How CyberPocket handles your alerts, your data, and your trust.
Defensive-only alert analysis for the 71% of organizations without a SOC. Deterministic redaction. Zero-retention by default. No model training on customer data. Everything below is verifiable in product, in our public docs, or in the downloadable whitepaper.
Maintained by the CyberPocket team. This page is not an independent certification; it documents the controls we operate today and the assurance work in progress.
Security & Privacy Whitepaper
PDF · 10 pages · v1.0
Threat model, redaction pipeline, encryption, access, retention, audit logging, incident response, compliance roadmap.
Investor Pitch Deck
PDF · 22 slides
Problem, product, market, traction, unit economics, GTM, FAQ on security/privacy/compliance, $4.5M seed ask.
Investor One-Pager
PDF · 1 page
Key metrics, traction, unit economics, and the $4.5M seed ask on a single sheet.
Posture at a glance
The defaults you can hold us to.
Encryption — in transit, at rest, in use
TLS 1.3 + HSTS, AES-256 at rest, redaction before any prompt leaves our backend.
Access control & privileged operations
Per-workspace RBAC, RLS on every tenant table, two-person break-glass.
Deterministic redaction
Side-by-side diff of what was scrubbed, before the prompt is dispatched.
Retention, DSARs, and deletion
Zero-retention by default for anonymous; self-serve purge for authenticated.
Audit logging
Privileged actions written server-side to an append-only table.
Incident response & continuity
1-hour Sev-1 acknowledgment; 72-hour customer notification; written post-mortem.
Compliance & assurance
SOC 2 Type II readiness in progress; ISO 27001 planned; honest status markers.
Need a DPA, security questionnaire, or pen-test summary?
Email trust@cyberpocket.org. We'll tell you straight what we can and cannot sign today.