Skip to content

Version 2026-08-01 | Effective August 1, 2026 | Last updated August 1, 2026

Privacy Notice

This Privacy Notice explains how CyberBit Solutions LLC collects, uses, shares, and protects information across the CyberBit Solutions website, request and intake forms, Free Check, newsletter, payment handoff, and customer services.

CyberBit asks for business context, not secrets. Do not submit passwords, private credentials, payment card numbers, private customer records, or other sensitive data through a public form or ordinary email.

1. Information you provide

CyberBit collects information you submit directly through forms, email, service workflows, and support conversations. The fields vary by the action you choose.

  • Contact information, such as your name, email address, phone number if provided, and support messages.
  • Business information, such as company name, website or domain, industry context, service requested, deadline, and intake details.
  • Website, hosting, CMS, vendor, platform, email provider, Microsoft 365 or Google Workspace, DNS, form, access, and project details you choose to provide for a service request.
  • High-level Pentest qualification information, such as the organization, application URL, ownership context, application type, authentication model, user-role count, API context, data categories, business reason, timing, and authorization confirmations.
  • Personal Cybersecurity request information, such as contact details, selected service, high-level account or device category, concern, urgency, and safety confirmations.
  • Domain, website, email, and public-signal details submitted for the Free Website, Email & Domain Check or another review request.
  • Request notes, questionnaire context, scan IDs, report or checklist context, and other non-secret details you choose to provide.
  • Newsletter information, such as email address, signup source, subscription status, unsubscribe status, and delivery events.
  • Limited payment and order information CyberBit receives from Stripe, such as payment status, checkout references, receipt context, amount, and transaction identifiers.
  • For an Instant Signal Brief purchase, the exact sanitized completed Free Check snapshot, integrity and methodology versions, opaque order and access references, purchaser delivery email, payment state, and report-fulfillment status.

2. Website and technical information

Normal website operation generates limited technical information used for delivery, diagnostics, security, anti-abuse controls, and aggregate understanding of website use.

  • Page path, referring page, sanitized campaign or query information, interaction events, timestamps, and form-submission metadata.
  • Browser, device, operating-system, user-agent, and basic site-performance or error information.
  • Approximate city, region, country, or time-zone information supplied by hosting or network headers. This is not precise GPS or device location.
  • Basic anti-abuse and security signals, including request timing, rate-limit information, and honeypot or bot indicators.
  • A random anonymous browser identifier and session identifier used to understand visits without creating a named customer profile.
  • An IP address may be processed transiently to deliver and protect the site. Where the website visit tracker creates a durable visit record, it stores a masked IP and a one-way salted hash rather than the raw address. A successfully completed, user-initiated IP Check may also include the returned IP, IP version, available coarse network or location details, browser summary, timestamp, route, and opaque execution reference in a minimized internal operational email.
  • Email operations may retain a versioned keyed recipient fingerprint, masked address, opaque workflow or request reference, provider message or event identifier, delivery status, timestamps, and sanitized failure or suppression categories. The email ledger does not store message bodies, submitted form content, raw webhook payloads, or a raw recipient address.
  • Free-tool infrastructure performs passive public DNS lookups. When a valid MTA-STS marker is found, the Business Email Trust Check may request only the fixed canonical public policy file at the submitted domain's mta-sts hostname. That public host receives a standard server request and may retain ordinary access logs under its operator's practices.
  • A successfully completed, user-initiated Free Scan or Business Email Trust Check may create a minimized internal operational email containing the normalized public domain, high-level result status, timestamps, route, and opaque execution reference. Tool-use alerts exclude cookies, authentication values, complete request headers, session identifiers, and unrelated visitor history.

3. Information you should not submit

CyberBit performs defensive, authorized work. Do not submit secrets or unrelated sensitive personal information through website forms, email, scan flows, or request notes.

  • Passwords or passphrases
  • MFA, recovery, or backup codes
  • Private keys, seed phrases, access tokens, or API keys
  • SSNs, identity documents, bank details, or full account numbers
  • Full payment card numbers
  • Private admin links, customer records, medical records, or unrelated sensitive personal information
  • Screenshots or attachments that expose private credentials or records

If an agreed service later requires account access, evidence, or test accounts, CyberBit will arrange a safer method after scope and authorization are confirmed, such as screen share, delegated access, customer-controlled entry, or a separately agreed secure transfer process.

4. How information is used

  • Provide requested services, including public-facing checks, advisory reviews, reports, checklists, website or account-baseline work, authorized testing qualification, and scoped support.
  • Respond to requests and support questions, assess fit, confirm scope, and coordinate an authorized handoff.
  • Prepare Website, Email & Domain Security Snapshots, Free Website, Email & Domain Check follow-ups, service checklists, and other customer-facing materials.
  • Create and deliver a paid automated Instant Signal Brief from the exact completed Free Check snapshot without running another scan.
  • Send transactional emails, such as request confirmations, payment or order updates, report delivery notes, checklist emails, and minimized internal operational tool-use messages.
  • Send newsletter emails only when you subscribe or otherwise opt in, with an unsubscribe option.
  • Process payments and reconcile service requests with payment and order status.
  • Improve the website, services, forms, internal workflows, and support experience.
  • Protect against spam, abuse, fraud, unauthorized requests, security issues, and misuse of CyberBit services.

5. Payments and external links

Stripe collects payment-card and checkout information directly under its own terms and privacy notice. CyberBit receives limited order and payment-status information needed to reconcile the purchase and deliver the service, but does not store full payment card numbers.

For an Instant Signal Brief, Stripe-confirmed payment creates a durable report entitlement tied to the exact completed Free Check snapshot. CyberBit stores the public-signal snapshot and minimum order, delivery, integrity, and access information needed to provide the secure web report and PDF. The report process does not rerun the scan or add IP Check, location, cookie, request-header, or card data.

Optional booking and third-party resource links take you to another provider. Information you choose to submit there is processed under that provider's terms and privacy practices.

6. Service providers

CyberBit uses the following verified providers to operate the current website and service workflows. Each provider processes information under its own terms and privacy practices.

  • Vercel hosts and delivers the website and may provide request, network, performance, and security information.
  • Google Public DNS may receive a queried public domain when a free tool uses its DNS-over-HTTPS fallback after local DNS resolution fails.
  • Airtable supports request, order, Free Check, newsletter, and website-visit workflow records.
  • Neon hosts the minimized email delivery ledger and the durable Instant Signal Brief scan snapshot, order, entitlement, Stripe-event, and fulfillment records.
  • Resend sends transactional and newsletter email and provides delivery-event information.
  • Stripe hosts payment checkout and processes payment information. CyberBit does not receive or store full payment card numbers.
  • A configured booking provider processes information you choose to submit after following an optional booking link.
  • Professional service providers may process limited information when reasonably needed for business records, tax, accounting, safety, or legal obligations.

7. Information sharing

  • CyberBit does not sell personal information.
  • CyberBit shares information with service providers only as needed to operate the website, process payments, send email, track requests, schedule meetings, deliver services, and protect the business.
  • CyberBit may share information when required by law, legal process, tax or accounting obligations, security needs, dispute prevention, fraud prevention, or safety concerns.
  • CyberBit may coordinate with a customer-authorized vendor, IT provider, developer, broker, insurer, website host, email provider, or similar party when the customer asks CyberBit to help with a handoff or response.

8. Browser storage, analytics, and logs

CyberBit uses browser local storage for an anonymous visit identifier and session storage for a session identifier and session state. These identifiers support privacy-conscious visit measurement and do not contain your name, email address, submitted domain, form message, or payment data.

Visit records can include page paths, referring pages, sanitized campaign information, browser or device summaries, approximate network-derived location, and non-sensitive interaction events. Sensitive query keys are removed before visit data is stored. CyberBit does not use this system to collect passwords, private credentials, precise GPS location, or form-message contents.

Domains, scan findings, raw recipient addresses, email message content, and provider message identifiers are not attached to browser analytics. Standard hosting, database, and provider systems may still retain ordinary operational request logs under their own practices.

9. Retention and security

CyberBit retains information as needed for service delivery, records, customer support, security, dispute prevention, payment reconciliation, tax or accounting needs, and legal or business obligations. Different records, including minimized email delivery and suppression evidence, may be kept for different periods based on those purposes.

Instant Signal Brief snapshots, orders, entitlements, and fulfillment evidence are retained as needed for digital delivery, support, payment reconciliation, dispute prevention, accounting, and legal or business obligations. CyberBit does not promise permanent hosting; customers should download their PDF. Refunded, disputed, expired, or revoked entitlements may no longer provide report access.

CyberBit uses reasonable safeguards for information it handles. No website, email system, workflow tool, payment provider, or internet transmission can be guaranteed 100% secure.

10. Your choices

  • You can unsubscribe from marketing or newsletter emails using the unsubscribe option in those emails.
  • You can choose not to submit optional form fields.
  • You can control cookies and browser storage through your browser settings, although some site functions may not work correctly if those features are disabled.
  • You can contact CyberBit to ask privacy questions or request correction or deletion where applicable and operationally possible.
  • Some information may need to be retained for records, service delivery, payment reconciliation, security, dispute prevention, tax, accounting, or legal or business obligations.

11. Children and international use

CyberBit services are not directed to children under 13. Personal Cybersecurity services may involve family context, but service requests should be submitted by an adult or authorized representative.

CyberBit operates from the United States. If you use the website or services from outside the United States, you understand that information may be processed in the United States.

12. Updates, related policies, and contact

CyberBit may update this Privacy Notice as services, tools, providers, or business operations change. The updated version will be posted on this page with a new version and last updated date.

The Terms of Service explain website and service terms. The Security Disclosure Policy explains how to report a possible security concern about CyberBit's public website.

For privacy questions, correction requests, deletion requests, or support questions, contact CyberBit:

CyberBit Solutions LLC

CyberBit Solutions LLC54 State St, Ste 804Albany, NY 12207-2524

Privacy and support email

support@cyberbitsolutions.com