Skip to content
DataCycles
Back to site

Security Declaration

Updated at: 2026-08-13

This declaration summarises the technical and organisational measures we apply to our own systems and to client data we process during an assessment.

Site security

This site is served over TLS, sets standard security response headers, and makes zero third-party network requests — a claim you can verify by inspecting the network panel of your browser.

Data at rest in our database and file storage is encrypted by default through our infrastructure provider, Cloudflare, in addition to TLS in transit.

Data location

Data is stored and processed within the European Union — our database and file storage both run under a formal EU jurisdiction restriction on our infrastructure provider, Cloudflare, not just default regional placement.

Sub-processors

We use Cloudflare (Pages, Workers, D1, R2, Browser Rendering, Access) as our infrastructure provider. We do not use any other sub-processor for assessment data.

Assessment data handling

Data captured during an assessment (cookie and storage values) is truncated and hashed before storage; we do not retain plaintext values.

Raw artifacts such as screenshots are retained for 30 days and then deleted; derived findings are retained for the life of the engagement.

Access control

Access to assessment data and reports is restricted to identified DataCycles personnel and authenticated via Cloudflare Access; there is no publicly accessible reporting interface.

Operational security

Multi-factor authentication is enforced on the Cloudflare account and other accounts with access to client or assessment data.

The working device used for engagements is fully disk-encrypted, and credentials are managed through a password manager rather than reused or written down.

No local, unencrypted copies of client data are kept after an engagement — assessment artifacts live only in the retention-governed storage described above.

Incident response

If we identify that data we hold has been affected by a security incident, we will notify affected clients within 72 hours of becoming aware, consistent with GDPR Article 33. No security incidents have occurred to date.