Privacy Notice — Overview

Short version: We collect only what we need to scope and deliver your technical evidence review. We do not sell your data, share it with advertisers, or use it for any purpose other than delivering our services and communicating with you about your engagement.

Cyber Audit Pro ("we," "us," "our") is a cybersecurity consulting firm based in Conroe, Texas. This Privacy Notice explains how we collect and use information when you visit cyberaudit.kerget.com, complete our pre-audit questionnaire, or engage us as a client.

By using our website or services, you agree to the practices described in this policy. If you do not agree, please do not submit information through our website.

Data We Collect

Information you provide directly

When you complete the contact form, pre-audit questionnaire, or communicate with us directly:

Data TypeExamplesPurpose
Contact informationName, email, phone number, companyDiscovery call scheduling, engagement communication
Organization detailsEmployee count, industry, locationReview scoping and fee estimation
Insurance informationCarrier name, renewal date, premium rangeScoping the review to questionnaire categories
Technical environmentCloud providers, vendors, infrastructure typeReview planning and evidence checklist customization
Incident historyPrior incidents, past claims (voluntary disclosure)Review scoping; not shared without consent

Browser-stored data (localStorage)

The pre-audit questionnaire and evidence checklist use your browser's localStorage to save your progress. This data never leaves your device and is not transmitted to our servers unless you explicitly submit a form. You can clear it at any time through your browser settings or using the "Clear" button in the tool.

Data sensitivity warning: Do not submit passwords, secrets, API keys, private keys, regulated customer records, or production credentials through website forms. Any access for an engagement must be handled through a written authorization and agreed access process.

Contact Form Processing

When you submit a discovery request through our website, we collect the information you provide, such as your name, company, business email address, phone number if provided, renewal timing, preferred contact method, and message. We use this information only to respond to your inquiry, evaluate whether a discussion is appropriate, and communicate about requested services.

Form submissions are processed through Formspree, a third-party form-processing provider. Do not submit passwords, access credentials, policy documents, screenshots, incident details, or other sensitive client information through the website contact form.

How We Use Data

We use your information only for the following purposes:

  • Responding to discovery call requests and scoping inquiries
  • Delivering technical evidence review services you have engaged us to perform
  • Communicating about your engagement, including report delivery and follow-up
  • Improving our services and website based on aggregate usage patterns
  • Complying with legal obligations and recordkeeping requirements

We do not use your information for marketing to third parties, profiling, or automated decision-making.

Data Sharing

We do not sell, rent, or trade your personal information. We may share limited data in the following circumstances:

  • With your explicit consent: We share evidence review reports and evidence packages with your designated broker or underwriter contacts only at your direction.
  • Service providers: We use website hosting and essential infrastructure providers to operate the site and deliver requested services.
  • Legal compliance: We may disclose information if required by law, court order, or to protect our legal rights.
  • Business transfer: In the event of a sale or merger, client data would be disclosed as part of due diligence under NDA.
Engagement data: Client-specific scope, data handling, access controls, retention, confidentiality, and contractual terms are established in the signed engagement agreement.

Retention & Deletion

Browser localStorage remains on your device until you clear browser data or use the tool's Clear button. Client-specific scope, data handling, access controls, retention, confidentiality, and contractual terms are established in the signed engagement agreement.

To request deletion of information submitted through the contact form, contact us at audit@kerget.com. Some records may be retained where required for legal or business recordkeeping purposes.

Cookies & Browser Storage

Our browser-based tools use localStorage for progress saving and do not require advertising tracking scripts.

Our tools (pre-audit form, evidence checklist) use localStorage — not cookies — for progress saving. This data remains on your device.

Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (subject to legal retention requirements)
  • Object to or restrict certain processing
  • Data portability — receive your data in a structured format

Texas residents: Under Texas HB 4 (Texas Data Privacy and Security Act), you have the right to access, correct, delete, and obtain a copy of your personal data. To exercise these rights, contact audit@kerget.com.

Service Scope

Short version: We provide independent cybersecurity technical evidence reviews. Our reports are evidence packages for insurance discussions — not guarantees of security and not a substitute for ongoing security management.

These service terms govern your use of Cyber Audit Pro's website and, together with a signed engagement agreement, the delivery of technical evidence review services. By requesting services or submitting a contact form, you agree to these terms.

Cyber Audit Pro provides independent cyber insurance technical evidence review and readiness support. Our services are limited to:

  • Point-in-time review of security controls against common cyber insurance questionnaire categories
  • Collection and organization of evidence supporting those controls
  • Preparation of structured technical evidence packages
  • Remediation recommendations based on identified gaps

This service is a technical evidence review, not a formal audit, compliance certification, underwriting assessment, insurance advice, or legal advice. We do not provide ongoing managed security services, penetration testing, or guarantees of insurance approval, premium reduction, claim payment, regulatory compliance, breach prevention, or premium outcomes.

Engagement Terms

Scoping and fees

All engagements are scoped on a fixed-fee basis following a discovery call. The scope, deliverables, timeline, and fee are confirmed in a written engagement letter before work begins. No fees are charged before scope agreement.

Access requirements

Client agrees to provide read-only access credentials sufficient to conduct the technical evidence review. Cyber Audit Pro will not request, accept, or use credentials with write or administrative privileges beyond those minimally required. All credential handling is documented and credentials are revoked or returned upon engagement completion.

Client responsibilities

  • Provide accurate and complete responses to the pre-audit questionnaire
  • Ensure that persons granting access are authorized to do so
  • Notify Cyber Audit Pro of any access restrictions or sensitive systems that should be excluded
  • Review draft findings and provide feedback within the agreed review window

Cancellation

Either party may cancel the engagement before review work begins without penalty. Cancellation after review work has commenced may result in a partial fee based on work completed. Specific cancellation terms are outlined in the signed engagement letter.

Deliverables

Standard deliverables for each engagement include:

  • Completed 47-item evidence checklist with status and evidence locations documented
  • Executive summary report with an Evidence Coverage Summary — Internal Review Metric and insurance questionnaire-oriented language
  • Findings table with severity ratings and remediation recommendations
  • Evidence appendix (screenshots, policy exports, configuration documentation)
  • One revision pass within 30 days of report delivery, at no additional charge

Deliverables are structured for broker and underwriter discussion. Cyber Audit Pro makes no representation that any insurer will accept, approve, or act upon the report in any particular way. Report use is at the discretion of the relevant underwriting team.

Limitations of Service

Our technical evidence reviews are point-in-time reviews. The report reflects the evidence available during the review period. Changes made after review completion are not reflected in the report unless a new engagement is initiated.

Our reports do not constitute:

  • An insurance approval guarantee, premium reduction guarantee, or claim payment guarantee
  • Legal advice, insurance advice, or a legal opinion on compliance status
  • A penetration test or vulnerability assessment
  • A continuous monitoring service
  • Certification under any regulatory framework (SOC 2, ISO 27001, etc.)

Cyber Audit Pro does not represent that the completion of recommended remediations will prevent security incidents or provide a formal compliance certification. Security is a continuous process, not a one-time certification.

Client-Specific Terms

Client-specific scope, data handling, access controls, retention, confidentiality, and contractual terms are established in the signed engagement agreement.