Everything we claim, and how to check it
We sell verification for a living, so it would be strange to ask you to take our own claims on faith. Below is every material assertion this website makes, its current status, and where you can independently confirm it.
- Cyberross OÜ
- Ahtri tn 12, 10151 Tallinn, Estonia
- Estonia — European Union
- 2021
“Cyberross” is a registered European Union trade mark.
- EUTM 018977523
- Word mark
- EUIPO — Alicante
- 7 May 2024
- 23 January 2034
- 9, 42
Self-reported figures are marked as such. We would rather publish an unaudited number honestly labelled than imply an audit that has not happened.
| Claim | Basis | Status |
|---|---|---|
| €90M Client losses prevented | Fraud blocked and breach costs avoided, 2021–2025, client-attested | Self-reported |
| 57+ Investigations closed | Full-scope incident and forensic engagements carried to conclusion | Self-reported |
| 47 min Median responder engagement | First analyst on the bridge after hotline trigger, trailing 12 months | Self-reported |
| 32+ Enterprise customers | Organisations above 500 employees under active contract | Self-reported |
| ISO/IEC 27001 | Information security management system certification. Certificate number and certifying body to be published. | Self-reported |
| EUTM 018977523 | EU trade mark register, EUIPO — publicly searchable | Third-party verified |
We will share the underlying engagement records behind any figure above under NDA. Ask during a scoping call.
Where does our data live?
Inside the European Union. Cyberross is an Estonian company; assessment data, engagement records and telemetry are processed and stored in EU data centres, and are never transferred to a third country without an explicit written instruction from you.
Who can see it?
Only the named delivery team assigned to your engagement, under least-privilege access with logged retrieval. We will provide the access log on request.
How long is it kept?
Engagement data is retained for the contractual period and then destroyed. Forensic evidence is retained only as long as you instruct, because you may need it for litigation or an insurance claim.
Do you use sub-processors?
A short list, published in the data processing agreement and updated with notice before any change. We do not add a sub-processor mid-engagement without telling you.
Can we audit you?
Yes. Enterprise agreements include an audit right, and we will complete your security questionnaire without charging for it.
Found something? Tell us.
We operate a CERT. It would be poor form not to accept reports about our own estate. We do not pursue researchers acting in good faith.
- security@cyberross.com
- /.well-known/security.txt
- Within 2 business days
- English, Estonian