Trust & security
Know how access, data and AI are handled.
Security should be explained in plain language before a system touches real business information. CYBERNOX uses project-specific controls and does not market certifications or compliance claims it cannot substantiate.
01 / CURRENT PRACTICES
Practical controls before marketing claims.
These statements describe the current website direction and project approach. A customer agreement may add stronger or more specific requirements.
Access is limited to the job
We prefer scoped accounts and the minimum permissions required for the agreed work instead of broad access whenever the platform allows it.
Secrets stay out of public code
Production credentials and provider keys belong in protected environment settings, not public pages or committed example files.
Public enquiries use first-party storage
The public contact form stores submitted business enquiries in the CYBERNOX website database for review. The application does not store raw IP addresses in its enquiry or site-event tables.
Testing is separated from customer promises
The Live Business Lab is a demonstration environment. Real customer actions require explicit setup, approved information and project-specific controls.
AI receives boundaries
Customer-facing AI should use approved information, defined actions and a clear path to a person when the situation needs judgment or approval.
Project risk changes the controls
A simple public website has different requirements from a system that touches customer records, phone calls, payments or regulated information. Controls are scoped to the project.
02 / WHEN AI TALKS TO CUSTOMERS
AI gets a job description. People keep responsibility.
Customer-facing AI should not receive unlimited authority. The business defines approved information, allowed actions, escalation and situations that need a person.
Approved information
Use business information that has been reviewed for the job.
Defined actions
Limit what the system may answer, collect, update or trigger.
Human handoff
Move unusual, sensitive or important situations to a person.
Review real use
Improve rules from observed behaviour instead of assuming the first version is perfect.
Security requirements change with the business risk.
A website enquiry, a CRM workflow and a system that handles regulated information should not be treated as the same project. We identify the information, providers, permissions and human responsibilities before implementation.
No public statement on this page replaces a security review or project agreement.
03 / BUYER QUESTIONS
Direct answers about risk and responsibility.
01Is CYBERNOX AI SOC 2 or ISO 27001 certified?+
This website does not claim SOC 2, ISO 27001 or another security certification. If a buyer requires a particular certification, that requirement should be raised before the project is approved.
02Does CYBERNOX AI claim HIPAA, GDPR, PIPEDA or PCI compliance?+
No blanket compliance claim is made on this website. Applicable privacy, payment or industry requirements depend on the project, the data involved, the providers used and the customer’s own obligations.
03Who owns customer data and custom code?+
Ownership, licensing, export and handoff terms should be written in the project agreement. This public page does not replace a customer contract.
04Which providers does the current website use?+
The public site is hosted on Vercel and uses Neon for first-party enquiry and limited website-event storage. The Live Business Lab can also use other configured providers for AI or verified phone demonstrations.
05What happens when a business stops using CYBERNOX?+
Offboarding requirements depend on the system. The project agreement should define account access, data export, credential rotation, code handoff and any continuing third-party services.