Skip to content

Trust centre

Everything we claim, and how to check it

We sell verification for a living, so it would be strange to ask you to take our own claims on faith. Below is every material assertion this website makes, its current status, and where you can independently confirm it.

Legal identity

Legal entity
Cyberross OÜ
Registered office
Ahtri tn 12, 10151 Tallinn, Estonia
Jurisdiction
Estonia — European Union
Founded
2021

Registered trade mark

“Cyberross” is a registered European Union trade mark.

Registration
EUTM 018977523
Type
Word mark
Office
EUIPO — Alicante
Registered
7 May 2024
Renewal due
23 January 2034
Nice classes
9, 42
Verify on the EUIPO public register

Claim register

Self-reported figures are marked as such. We would rather publish an unaudited number honestly labelled than imply an audit that has not happened.

ClaimBasisStatus
90M Client losses preventedFraud blocked and breach costs avoided, 2021–2025, client-attestedSelf-reported
57+ Investigations closedFull-scope incident and forensic engagements carried to conclusionSelf-reported
47 min Median responder engagementFirst analyst on the bridge after hotline trigger, trailing 12 monthsSelf-reported
32+ Enterprise customersOrganisations above 500 employees under active contractSelf-reported
ISO/IEC 27001Information security management system certification. Certificate number and certifying body to be published.Self-reported
EUTM 018977523EU trade mark register, EUIPO — publicly searchableThird-party verified

We will share the underlying engagement records behind any figure above under NDA. Ask during a scoping call.

Your data

Where does our data live?

Inside the European Union. Cyberross is an Estonian company; assessment data, engagement records and telemetry are processed and stored in EU data centres, and are never transferred to a third country without an explicit written instruction from you.

Who can see it?

Only the named delivery team assigned to your engagement, under least-privilege access with logged retrieval. We will provide the access log on request.

How long is it kept?

Engagement data is retained for the contractual period and then destroyed. Forensic evidence is retained only as long as you instruct, because you may need it for litigation or an insurance claim.

Do you use sub-processors?

A short list, published in the data processing agreement and updated with notice before any change. We do not add a sub-processor mid-engagement without telling you.

Can we audit you?

Yes. Enterprise agreements include an audit right, and we will complete your security questionnaire without charging for it.

Responsible disclosure

Found something? Tell us.

We operate a CERT. It would be poor form not to accept reports about our own estate. We do not pursue researchers acting in good faith.

Report to
security@cyberross.com
Machine-readable
/.well-known/security.txt
Acknowledgement
Within 2 business days
Preferred languages
English, Estonian
Report a vulnerability