What we collect, what we publish, what we protect.
How the Cyber 360 Program handles the information you submit, what appears publicly on the register, and how assessment evidence is protected.
Concept draft for program review · Final policy language subject to Program Office and counsel review
Information We Collect Through This Website
This website collects information only when you choose to submit it:
- Assessment requests, organization name, location information, contact details, industry, number of users, number of locations, desired certificate level, and your message.
- Contact form submissions, name, organization, email, phone, inquiry type, optional certificate number or verification code, and your message.
- Certificate lookups, the certificate number and verification code you enter, along with limited technical information (such as IP address and request timing) used solely for rate limiting, bot protection, and abuse prevention on the verification service.
Submitted information is used to respond to your inquiry, administer the certification program, and maintain internal program records. It is not sold or shared for marketing purposes.
No Billing or Payment Information
This website does not collect, store, display, or process billing or payment information of any kind, no payment card numbers, bank details, invoices, or payment status. Billing and payment matters are handled outside this website; please contact the program office directly by phone.
Public Verification Data
When a certificate’s public verification profile is published, its register entry displays only approved, public-safe certificate information:
- Certified organization / location display name
- City and state (unless configured to be hidden)
- Certificate level, status, and certificate number
- Issue date, expiration or renewal date, and last assessment date
- A limited reviewed-scope summary and plain-language level summary
- Curated public achievements approved by the program administrator
- Program administrator information and an inquiry method
Verification is lookup-based only. There is no public directory, no browse function, and no search by organization name, city, state, level, expiration date, or status. Verification pages use non-guessable codes, are rate limited, and are excluded from search engine indexing.
Information That Is Never Published
The following are never displayed publicly, regardless of certificate status:
- Internal record identifiers
- Detailed review findings, technical reports, or vulnerability details
- Network diagrams, user lists, or security tool screenshots
- Passwords, keys, tokens, or secrets
- Personal information or protected health information
- Insurance documents and internal correspondence
- Improvement roadmaps or planned security changes
- Billing information and assessor compensation information (not stored on this website at all)
How Assessment Evidence Is Protected
Evidence shared during an assessment is treated as confidential program material:
- Uploaded files default to internal-only visibility; broader visibility requires explicit administrator action.
- Backend access requires authentication with multi-factor authentication and role-based permissions.
- Sensitive data is protected by encryption and restricted access.
- Public achievements appear only after explicit administrator approval of public-safe wording.
- Important backend activity, including certificate status changes, is recorded in an internal audit log.
Cookies & Analytics
This website is designed to operate with minimal client-side storage: session information for the secured portal, and short-lived technical data supporting bot protection and rate limiting on the verification service. Any analytics used in production will be privacy-respecting and will not be applied to certificate verification pages in a way that identifies verifiers.
Data Retention
Program records, including certificate history after expiration, replacement, suspension, or revocation, are retained as required to administer the program, preserve the integrity of issued certificates, and meet the program’s operational obligations.
Privacy Inquiries
Questions about this policy or about information you’ve submitted? Use the contact form and select “Privacy inquiry,” or write to the Cyber 360 Program Office at [email protected].
Concept draft for program review, final policy language subject to Program Office and counsel review.