Trust center
Overview
Cye is committed to maintaining a robust information security and privacy program that safeguards the confidentiality, integrity, and availability of our systems and customer data.
This is governed by approved security policies and implemented through defined controls covering access management, data protection, security monitoring, incident response, secure development, and third-party risk management, in alignment with industry best practices and applicable regulatory requirements.
Our Trust Center provides visibility into our certifications, compliance, and security and privacy practices, along with answers to common security questions. Additional materials, including SOC 2 Type II reports and full policy documents, are available upon request under NDA via your Account Manager.
Compliance & Certifications


Security Assurance
- Cye's Risk Management Approach
- Data Privacy
- Data Access
- Data Retention
- Data Disposal
- Cye's Platform
- Data Center Security
- Infrastructure Security
- Application Security
- Operational Security
- Human Resource Security
- Data Encryption
- Availability Procedures
- Disaster Recovery Plan (DRP)
Cye AI Governance
FAQ
Cye maintains independent third-party assurance and certifications, including ISO 27001, CREST and SOC 2 Type II. For a more detailed list, check out the certifications section.
Compliance & Certifications

ISO/IEC 27001:2022
Cye is ISO/IEC 27001:2022 certified, demonstrating that our Information Security Management System (ISMS) is independently assessed against the leading standard for information security governance and risk management.
DownloadSOC 2 Type II
Cye is SOC 2 Type II compliant, meaning an independent auditor has evaluated the design and operating effectiveness of our security controls. The report is available upon request under NDA via your Account Manager at Cye.
GDPR
Cye is committed to protecting personal data and supporting customers' obligations under the EU/EEA General Data Protection Regulation (GDPR).
CREST
Cye has successfully met the CREST requirements for Penetration Testing, demonstrating alignment with recognized standards for professional security testing. This provides assurance that our penetration testing services are delivered in accordance with CREST expectations for quality and methodology.
Download
ISO/IEC 42001:2023
Cye is ISO/IEC 42001 certified, demonstrating that our Artificial Intelligence Management System (AIMS) is independently assessed against the leading international standard for responsible AI governance, risk management, and oversight.
DownloadSecurity Assurance
The Cye Risk Management program is an essential management function and is critical for implementing and maintaining a high standard of security. The process of identifying risk, assessing risk, and taking steps to reduce risk to an acceptable level is an iterative process followed by Cye risk and control teams, covering initial assessments, risk mitigation and evaluation activities. The entire process is managed and tracked via Cye's platform, to provide a comprehensive, continuous view of the organizational risk landscape, as well as facilitate an informative, data-driven decision-making process of the mitigation aspects.
Cye AI Governance
Cye integrates AI functionalities that support Cyber Risk & Threat Exposure Management workflows – while maintaining strong security, privacy, and operational controls. Our AI features are designed with security and privacy by design, clearly labeled in the product UI, and governed with human oversight so users can review, override, or disregard AI outputs at any time.
Cye AI is built to protect customer information: we use private LLM deployments and enforce strict access controls and logging. We do not train or fine-tune AI models on customer data, and customers can opt out of the AI chatbot through their Cye support contact.
For a deeper overview, download our full AI Governance document.

Frequently Asked Questions
Assurance & Compliance
Cye maintains independent third-party assurance and certifications, including ISO 27001, CREST and SOC 2 Type II. For a more detailed list, check out the certifications section.