Public trust center

Clear practices for a product built around employee records.

Review how CyberPrimer approaches privacy, security, retention, accessibility, support boundaries, and service communications before enrolling an organization.

01

Privacy notice

What information is used, why it is needed, and the choices available to organizations and enrollees.

02

Security practices

Organization isolation, access controls, recovery, activity records, and responsible disclosure.

03

Terms & service boundaries

Permitted use, customer responsibilities, evidence limitations, and support scope.

04

Accessibility

Keyboard, contrast, responsive design, readable content, and how to report a barrier.

Data retention

Records follow the organization lifecycle.

Training and evidence records are retained for the active service relationship and configured recovery period. Authorized Global Administrators control organization deletion and restore. A minimal deletion ledger may remain for accountability.

Service providers

Limited subprocessors support delivery.

Infrastructure, transactional email, storage, and payment providers may process only the information needed for their function. The current list is available on request while the formal public register is prepared.

Service communications

Operational notices stay distinct from guarantees.

CyberPrimer communicates material platform incidents and recovery status through registered manager contacts. A public status page and formal incident-notification schedule may be added as service volume grows.