CYVRIX Trust Centre

Trust should be supported by evidence.

CYVRIX is committed to clear, responsible technology delivery. We do not use credentials, customer claims or performance statistics to create an impression that cannot be substantiated.

Our approach

A dependable standard for public information.

Evidence-led credentials

We publish certifications, partner relationships, customer references and testimonials only when their supporting evidence, authority and review status are current.

Security-first delivery

Technology work is approached with proportionate security, clear ownership and practical communication in mind from discovery through to delivery.

Clear data handling

Our privacy information explains how we handle enquiry data. We keep requests focused on the information needed to respond appropriately.

Responsible reporting

If you believe you have identified a security concern affecting CYVRIX, please contact us with enough detail for an appropriate response.

Credentials and references

Published only when ready for public scrutiny.

Each public credential, partner logo, testimonial and case study is subject to verification and, where needed, permission and expiry checks before it can appear on the website.

Public entries are deliberately selective: current evidence and appropriate authority take priority over the volume of logos or claims.

Where we currently stand

What we hold, and what we are working towards.

We would rather tell you exactly where we are than leave an impression that flatters us. This is the current position.

In progress

ISO/IEC 27001

Information security management system certification

Implementation is underway. CYVRIX is not certified to ISO/IEC 27001 and does not claim to be.

We will publish the certificate details here once certification is awarded, and not before.

We hold no other certification or accreditation at present. Where a service page describes readiness work for a standard such as Cyber Essentials, that means helping you prepare and remediate; the certification decision rests with the certification body.

How this site is secured

The technical measures actually in place.

Every item below is implemented on this platform today. We list specifics rather than general assurances, because a specific claim is one you can check.

Transport and browser protection

  • HTTPS enforced with HSTS, including subdomains and preload
  • Content Security Policy restricting scripts, styles, frames and form targets
  • Clickjacking blocked by frame-ancestors none and X-Frame-Options DENY
  • MIME sniffing disabled and a restrictive Permissions-Policy applied

Authentication and access

  • Sessions carried in a signed, HTTP-only cookie with an eight-hour expiry
  • Passwords stored as salted hashes, never in recoverable form
  • Role-based access enforced in middleware and again on the server
  • Failed, throttled and successful sign-ins recorded for review

Abuse and input handling

  • Rate limiting on sign-in and on every public form, by address and by email
  • Server-side schema validation on all submitted data
  • Uploaded documents scanned for macros, active content and unsafe structure before acceptance
  • Output encoded, and CMS content never rendered as raw markup

Monitoring and audit

  • Administrative actions written to an append-only audit log
  • Security Centre checks headers, dependencies, database reachability and privileged accounts
  • Findings classified by severity with the remediation step recorded
  • Application errors captured for investigation

Data handling

  • Data hosted on managed UK-accessible infrastructure with encryption in transit
  • Optional analytics loaded only after explicit consent
  • Secrets held in the server environment, never in the repository or the browser
  • Newsletter unsubscribe links signed so they cannot be forged

Change control

  • Type checking and linting run before a release is built
  • Database changes applied through reviewed migrations, never ad hoc
  • Public credentials gated behind verification, permission and expiry checks
  • Dependencies checked against published versions for known staleness

These measures reduce risk; they do not eliminate it, and we do not claim they do. We hold no security certification at present. If you identify a concern affecting CYVRIX, please contact us with enough detail for us to investigate.

Need to discuss a technology or security concern?

Start with a practical conversation. We will help identify the most appropriate next step without making assumptions about your environment.

Read our privacy information