§ Legal · Privacy Policy

Privacy Policy

Last updated: July 1, 2026 · How cybersoftware collects, uses, and protects your data.

1. The short version

cybersoftware is a SOC 2 compliance platform. To do that job we handle sensitive information about your company's systems and controls. We collect only what we need to deliver the service, we do not sell your data, and we do not train AI models on it. You can export or delete your data at any time. Below is the full version of those promises.

2. Who we are

"cybersoftware" ("we" / "us" / "our") is a company registered in Delaware, with its team based in Houston, Texas. This policy covers the cybersoftware website and platform. It does not cover the independent U.S. CPA firms who perform your SOC 2 examination. They are separate entities with their own privacy practices, and we are not a CPA firm.

3. What we collect

We collect information in three ways:

  • Information you give us. Account details (name, work email, company), intake responses about how your company runs, evidence files you upload, policy drafts, and anything you send us through the contact form or by email.
  • Information from your use of the platform. Operational telemetry such as log entries, feature usage, and error reports. Our backend logging is limited to operational metadata and does not capture request or response body content.
  • Information collected automatically on the website. Basic analytics (see cookies and analytics below) and standard request data like IP address and browser type.

4. How we use it

We process your data solely to deliver and improve the service: to run your readiness assessment, surface gaps, generate policies tied to your specific environment, map evidence to controls, prepare the package your auditor reviews, process payments, respond to your questions, and keep the platform secure and working. We do not use your data to benefit other customers, and we do not sell it to anyone.

5. Who we share it with

We share data only where it is necessary to run the service, and only with providers bound to protect it:

  • Your assigned CPA firm. The independent auditor engaged for your examination receives the evidence and artifacts needed to review your controls, through access restricted to your engagement.
  • Amazon Web Services (AWS). Hosting and encrypted storage. Evidence files are stored in AWS S3 with access restricted by signed URLs available only to you and your assigned auditor.
  • Stripe. Payment processing. Card details are handled by Stripe; we do not store full card numbers.
  • HubSpot. Receives what you send through the contact form on this site, so we can respond to inbound requests.
  • Anthropic Claude via AWS Bedrock. Generates policy drafts and remediation guidance from your intake answers and evidence. This content is not used to train the model, and your data is not retained for that purpose.
  • Google Analytics. Aggregate, privacy-conscious website usage measurement.

We may also disclose data if required by law, to enforce our terms, or to protect the rights and safety of our users. If cybersoftware is ever involved in a merger or acquisition, we will give notice before your data becomes subject to a different privacy policy.

6. How we protect it

Evidence files are stored encrypted in AWS S3 with access restricted by signed URLs scoped to you and your assigned auditor. Access to production systems is limited and logged. We design for the same rigor we help our customers demonstrate, grounding evidence in real sources rather than auto-generating it. No system is perfectly secure, and we cannot guarantee absolute security.

7. How long we keep it

We retain your data for as long as your account is active and as needed to provide the service and meet legal obligations. Your Type 1 report and any completed Type 2 reports remain accessible regardless of subscription status. You may request export or deletion at any time (see your rights below).

8. Your rights

You own your data. You can access, correct, export, or delete it, and you can object to or restrict certain processing. To make a request, email surya@cybersoftware.com. We honor export requests within 30 days and deletion requests within 60 days, subject to legal retention obligations. Where local law (such as GDPR or CCPA) grants additional rights, we honor those too, and we do not sell personal information as those laws define it.

9. Cookies and analytics

We use a small number of cookies and similar technologies to keep you signed in, remember preferences, and measure website usage through Google Analytics. Analytics data is aggregate and used to understand what is working on the site, not to build advertising profiles. You can block cookies in your browser settings; some features (such as staying signed in) may not work correctly if you do. For the full breakdown, see our Cookie Policy.

10. AI and your data

cybersoftware uses large language models (currently AWS Bedrock with Anthropic Claude) to draft policies and remediation guidance grounded in your intake answers and evidence. Your data is used to generate output for you. It is not used to train the underlying models, and it is not shared with other customers. You and your auditor remain the final reviewers of everything generated.

11. Children

cybersoftware is a business tool and is not directed to anyone under 18. We do not knowingly collect personal information from children.

12. International users

We operate from the United States, and your data is processed here. If you use the service from outside the U.S., you consent to that transfer. We apply the same protections described in this policy regardless of where you are located.

13. Changes to this policy

We may update this policy as the product, our providers, or the law change. The "Last updated" date at the top reflects the most recent change. Material changes that affect an active engagement will be announced by email in advance.

14. Contact

Questions about your privacy, or a request about your data, should go to surya@cybersoftware.com. This policy works alongside our Terms of Service.

Plain-English footnote: we sell SOC 2 readiness, not your data. We collect what we need to get you audit ready and nothing extra. If any of this is unclear or you want something changed about how we handle your data, email Surya directly and we will make it right.

cybersoftware

SOC 2 Type 1 and Type 2 for startups. From assessment to audit ready report. $2,000 one time for platform onboarding, or $4,000 with the SOC 2 Type 1 examination and report included. Then $600 a month on a 12 month term, or $7,000 for the first 12 months in one invoice.
Your first SOC 2 Type 2 audit is included in that term.

© 2026 cybersoftware. All rights reserved.Contact: surya@cybersoftware.com

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms. The audit opinion is theirs alone.
We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.