How we approach protecting the Service and the data in it.
Last updated: September 1, 2026
We sell to security teams, so we expect to be asked. This page says what we do at a level we can stand behind, and does not describe how the system is built. A published inventory of individual controls is a map for anyone probing us, and a commitment about each item on it; neither serves a customer well.
CyberExchange runs on major cloud infrastructure in the United States, using managed services for hosting, storage and data. Data is encrypted in transit, and stored on infrastructure that encrypts data at rest. We take backups of customer data.
Access to the Service and to the data behind it is scoped: an account, a credential, or a component gets what its role requires and no more. Access to production is limited to the people who need it, over authenticated channels, and to credentials issued for that purpose.
Changes run through an automated test suite before release, including checks written specifically to catch authorization and data-exposure mistakes. We apply security updates to the systems the Service runs on.
If a security incident affects your data, we will tell you without undue delay after becoming aware of it. Our Data Processing Addendum sets out the commitment where we process personal data on your behalf.
If you have found a vulnerability, our Vulnerability Disclosure Policy explains how to report it and what protection you have when you do. Anything else security-related goes to team@cyberexchange.ai.
We do not hold a SOC 2 report, an ISO certification, or any other third-party security attestation, and we do not claim one. We do not offer an uptime commitment or a service level agreement; the Terms of Service state the position on availability.
If your procurement process needs something we do not have, tell us rather than assume. We would rather have that conversation early.
You control who you invite into your account, what they can reach, and what you put into the Service. API keys and MCP tokens are credentials: protect them, rotate them if they are exposed, and tell us so we can revoke them.
For any question about these documents — including a privacy request, a security report, a copyright or accuracy complaint, or a billing dispute — write to us. One address reaches us for all of it.
IT-Harvest, LLC
Email: team@cyberexchange.ai
Website: it-harvest.com
Notices: 850 New Burton Rd., Suite 201, Dover, Delaware 19904, Kent County