Skip to content
days until launch · 31 July 2026 ·
Cyber Toolbox
Security & trust

How we protect your data.

Cyber Toolbox holds the evidence, decisions and regulator clocks for your most sensitive work. Here is how that is kept isolated, access-controlled and auditable — in plain language.

In active development (alpha) — we position our posture honestly

Organisation isolation

Every record is scoped to your organisation. Isolation is enforced in the application and verified in our tests — not a configuration you have to remember to set.

Chain-of-custody & audit

Evidence is hashed, the collector is recorded immutably, and every access is logged. Operator actions and billing changes land in an append-only audit trail — the foundation for answering “who did what, when”.

Hardened sign-in

Sign in with email one-time codes, passkeys, or an optional authenticator-app 2FA — with step-up auth required on high-consequence actions.

Role-based access

Access is governed by role, so people see and do what their role allows — and high-consequence actions are gated and logged.

SSO at Enterprise

Enterprise customers can front their organisation with their own SSO / IdP, so access follows your existing identity controls and joiner-mover-leaver process.

Maturing toward SOC 2

Audit trail, access controls and change-management discipline are designed with SOC 2 in mind. We are in active development (alpha/beta) and say “maturing toward SOC 2 readiness”, not “certified”, until certification exists.

Running a security review?

Send us your security questionnaire or due-diligence request and we’ll work through it. You can also read our security.txt.

Contact security

Trust the record. Coordinate the response.