Trust & Safety

Security Policy

Last updated: June 1, 2026

As a cybersecurity company, we hold ourselves to the highest security standards. This page describes how we protect your data and what to do if you discover a security issue.

Encryption at rest

All data stored in Supabase is encrypted at rest using AES-256 encryption. Your data is protected even if the database is compromised.

Encryption in transit

All API calls and web traffic use TLS 1.3. HTTP is permanently redirected to HTTPS. No data travels unencrypted.

Password security

All passwords are hashed using bcrypt with 12 salt rounds before storage. We never store or transmit plaintext passwords.

Authentication

JWT tokens with short expiry windows. Role-based access controls (RBAC) ensure users only access their own data.

Rate limiting

All authentication endpoints are rate-limited to prevent brute force and credential stuffing attacks.

Infrastructure

Hosted on Railway and Vercel with automatic security patches, DDoS protection, and 99.9% uptime SLA.

Responsible Disclosure

We take security vulnerabilities seriously. If you discover a security issue in CyberShield, please report it responsibly:

We will acknowledge receipt within 24 hours and aim to resolve critical issues within 72 hours.

What We Do With Reports

Report a security issue

Email: security@cybrshieldtech.com