Privacy Policy

Effective Date: April 20, 2026|Last Updated: July 15, 2026

1.Who We Are

Cyberwrite Inc. ("Cyberwrite," "we," "us," or "our") is a provider of AI-powered cyber insurance analytics, catastrophe modeling, and decision intelligence. We are the data controller responsible for the personal data described in this policy.

Cyberwrite Inc.

1 Liberty Plaza, New York, NY

United States

Data Protection Contact: privacy@cyberwrite.com

If you have questions about this policy or wish to exercise your data protection rights, contact us at privacy@cyberwrite.com.

2.Scope of This Policy

This policy explains how Cyberwrite collects, uses, stores, shares, and protects personal data in connection with:

  • Our website (cyberwrite.com and associated domains)
  • Our platform, including 4SEEN® AI Analytics, Cyberwrite AI, CYBERPROFILE®, and our catastrophe modeling services
  • Our cyber risk intelligence services, including company scanning, credential monitoring, and risk assessment
  • Our sales, marketing, and customer support activities

This policy applies to all individuals whose personal data we process, including website visitors, platform users, employees of client organizations, and individuals whose data may appear in our cyber risk intelligence datasets.

3.Personal Data We Collect

We collect and process the following categories of personal data:

3.1 Data You Provide Directly

When you request a demo, create an account, contact us, or interact with our services:

  • Name, job title, and company name
  • Business email address and phone number
  • Country and industry
  • Communications you send us
  • Preferences and feedback

3.2 Data Collected Automatically

When you use our website or platform:

  • IP address and approximate location
  • Browser type, device type, and operating system
  • Pages visited, features used, and interaction patterns
  • Referral source and session duration
  • Cookies and similar tracking technologies (see Section 11)

3.3 Data Collected Through Our Cyber Risk Intelligence Services

Cyberwrite operates proprietary scanning infrastructure that continuously assesses companies worldwide for cyber risk. In the course of this activity, we may collect and process:

  • Publicly accessible technical data about company infrastructure, including technology stacks, web server configurations, SSL/TLS certificates, DNS records, open ports, and email security configurations (SPF, DKIM, DMARC)
  • Publicly accessible subdomain and hosting information
  • Exposed credential data obtained from breach databases and dark web monitoring, which may include email addresses and associated metadata
  • Company-level risk indicators derived from the above data

This data is collected from publicly accessible sources and specialized intelligence feeds. It is processed for the purpose of cyber risk assessment and insurance analytics. Where this data includes personal data (such as email addresses in exposed credential datasets), we process it under our legitimate interest in providing cyber risk intelligence services to the insurance industry, subject to appropriate safeguards.

3.4 Data Received From Clients

Our clients (insurers, brokers, reinsurers, MGAs, and MSPs) may submit company names, policy data, or portfolio information through our platform for analysis. Where this data includes personal data, Cyberwrite processes it as a data processor on behalf of the client, governed by our Data Processing Agreement.

4.How We Use Your Data

We use personal data for the following purposes and legal bases:

PurposeLegal Basis (GDPR)
Providing and operating our platform and servicesPerformance of a contract / Legitimate interest
Generating cyber risk assessments, AI-powered analytics, and reportsLegitimate interest (provision of cyber insurance intelligence)
Processing exposed credential data for risk assessmentLegitimate interest (with Legitimate Interest Assessment on file)
AI-powered risk scoring, claim prediction, and underwriting guidance via 4SEEN® and Cyberwrite AILegitimate interest (provision of insurance decision support)
Catastrophe modeling using technology dependency dataLegitimate interest
Communicating with you about our services, including responding to inquiriesPerformance of a contract / Legitimate interest
Sending marketing communicationsConsent (where required) / Legitimate interest
Improving our platform, models, and servicesLegitimate interest
Ensuring security and preventing fraudLegitimate interest / Legal obligation
Complying with legal and regulatory obligationsLegal obligation
Generating aggregated, anonymized analyticsLegitimate interest

Where we rely on legitimate interest as a legal basis, we have conducted assessments to ensure our interests are balanced against the rights and freedoms of the individuals concerned. You may request details of these assessments by contacting privacy@cyberwrite.com.

5.AI and Automated Processing

Cyberwrite uses artificial intelligence and machine learning systems to process data and generate outputs. We are committed to transparency about how these systems work.

5.1 AI Systems We Operate

4SEEN® AI Analytics

Machine learning models trained on proprietary breach, claims, and risk data to predict cyber insurance outcomes, generate risk scores, and estimate financial impact. 4SEEN® outputs include claim probability scores, financial loss estimates, and risk benchmarks.

Cyberwrite AI

A purpose-built large language model trained on proprietary cyber insurance data. Cyberwrite AI generates underwriting recommendations (accept/refer/decline with confidence scores), portfolio risk prioritization, catastrophe exposure narratives, and executive risk summaries.

CYBERPROFILE® Risk Signal Aggregation

A patented system that aggregates and correlates risk signals from multiple proprietary data sources into unified risk assessments.

Catastrophe Model

An event-based model that simulates 80,000+ catastrophic cyber events using actual company technology dependency data.

5.2 How AI Outputs Are Used

Our AI systems generate recommendations and analytics to support human decision-making. They do not make final binding decisions about insurance coverage, pricing, or claims on their own. Underwriters, portfolio managers, and other professionals use Cyberwrite's outputs as one input among several in their decision-making process.

5.3 Explainability

Every AI-generated recommendation includes a citation chain explaining the data inputs, risk factors, and reasoning that contributed to the output. This enables users to understand, verify, and override AI-generated guidance.

5.4 Accuracy and Oversight

Our AI models are continuously validated against real-world outcomes. We monitor model performance, test for bias, and update models as new data becomes available. Human oversight is maintained at every stage where AI outputs inform consequential decisions.

5.5 Your Rights Regarding AI Processing

If our AI processing affects you or your organization, you have the right to:

  • Request information about the logic involved in automated processing
  • Object to automated processing in certain circumstances
  • Request human review of decisions significantly affected by automated processing

Contact privacy@cyberwrite.com to exercise these rights.

6.How We Share Your Data

We do not sell personal data.

We may share personal data with the following categories of recipients:

  • Clients: When our clients submit data for analysis, the resulting reports and analytics are delivered back to those clients. Cyberwrite does not share one client's proprietary data with another client.
  • Service Providers: We use third-party service providers for hosting, infrastructure, analytics, communication, and support. These providers are bound by data processing agreements and process data only on our instructions.
  • Professional Advisors: Legal, accounting, and insurance advisors, subject to professional confidentiality obligations.
  • Legal and Regulatory Requirements: We may disclose data when required by law, regulation, court order, or governmental authority, or when necessary to protect our rights, safety, or property.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity, subject to this policy.

A list of our sub-processors is available upon request by contacting privacy@cyberwrite.com.

7.International Data Transfers

Cyberwrite operates globally and may transfer personal data to countries outside your jurisdiction, including Israel and other countries where our infrastructure or service providers are located.

The United States does not have a general adequacy decision from the European Commission. For transfers from the EEA to the United States, we rely on appropriate safeguards as described below.

For transfers to other countries that have not received an adequacy decision, we implement appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (June 2021 version)
  • Supplementary technical and organizational measures where required
  • Transfer impact assessments for transfers to jurisdictions with surveillance concerns

For more information about the safeguards we use, contact privacy@cyberwrite.com.

8.Data Retention

We retain personal data only as long as necessary for the purposes described in this policy, or as required by law.

Data CategoryRetention Period
Account and contact informationDuration of the business relationship plus 3 years, or as required by applicable law
Platform usage data24 months from collection
Website analytics data14 months from collection
Cyber risk intelligence data (company scans)Continuously updated; historical data retained to support trend analysis and AI model training
Exposed credential dataRetained as part of our risk intelligence database; specific records removed upon verified request
Client-submitted dataAs specified in the applicable Data Processing Agreement; deleted or returned upon contract termination
Marketing communication recordsUntil consent is withdrawn or unsubscribe is processed

When data is no longer needed, it is securely deleted or anonymized in accordance with our data destruction procedures.

9.Data Security

We implement technical and organizational measures to protect personal data against unauthorized access, loss, destruction, or alteration. These measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls and least-privilege principles
  • Regular security assessments and penetration testing
  • Employee security awareness training
  • Incident detection and response procedures
  • Business continuity and disaster recovery plans

Cyberwrite maintains SOC 2 Type II and ISO 27001 certifications. Details of our security practices and certifications are available on our Trust page or upon request.

10.Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

Under GDPR (EEA, UK, and similar jurisdictions):

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your personal data in certain circumstances
  • Restriction: Request that we limit processing of your data in certain circumstances
  • Portability: Request your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interest, including profiling
  • Withdraw Consent: Where processing is based on consent, withdraw it at any time
  • Complaint: Lodge a complaint with your local data protection supervisory authority

Under CCPA/CPRA (California residents):

  • Right to Know: Request disclosure of personal information collected, used, and shared
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: Opt out of the sale or sharing of personal information (note: Cyberwrite does not sell personal information)
  • Right to Limit Use of Sensitive Personal Information: Limit use of sensitive PI to specified purposes
  • Non-Discrimination: We will not discriminate against you for exercising your rights

To exercise any of these rights:

Email privacy@cyberwrite.com with your request. We will verify your identity and respond within 30 days (GDPR) or 45 days (CCPA/CPRA). If we need additional time, we will notify you of the extension and the reasons.

For companies included in our cyber risk intelligence database:

If your company appears in our risk assessment database and you wish to request information about the data we hold, request corrections, or object to processing, contact privacy@cyberwrite.com. We will review and respond to all requests in accordance with applicable law.

11.Cookies and Tracking Technologies

We use cookies and similar technologies on our website. Our Cookie Policy provides detailed information about:

  • The specific cookies we use and their purposes
  • How to manage your cookie preferences
  • Third-party cookies placed on our site

We obtain your consent before placing non-essential cookies through our cookie consent controls. Essential cookies required for site functionality do not require consent.

12.Global Privacy Control

Global Privacy Control (GPC) is a browser-level privacy signal that communicates a user's request to opt out of the sale or sharing of personal information and the use of non-essential tracking technologies. Cyberwrite respects GPC signals when they are enabled in your browser or privacy extension.

  • When GPC is detected, we treat it as an opt-out request equivalent to an explicit rejection of analytics, marketing, advertising and other non-essential tracking.
  • Google Analytics and app-level analytics events are disabled when GPC is enabled, and existing Google Analytics cookies are cleared where technically possible.
  • Server-side form handlers check for the Sec-GPC HTTP header so server-side analytics or tracking can also respect the signal.
  • You can enable GPC through browsers or extensions that support it, including privacy-focused browser settings and extensions such as Privacy Badger or DuckDuckGo Privacy Essentials.

13.Marketing Communications

We may send you marketing communications about our products, services, and events. You can opt out at any time by:

  • Clicking the "unsubscribe" link in any marketing email
  • Contacting privacy@cyberwrite.com
  • Updating your communication preferences in your account settings

Opting out of marketing does not affect service-related communications necessary for the operation of your account.

14.Children's Privacy

Our services are designed for business professionals and are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.

15.Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated via email to registered users or through a prominent notice on our website. The "Last Updated" date at the top of this policy indicates when it was most recently revised.

We encourage you to review this policy periodically.

16.Contact Us

For privacy-related inquiries, data subject requests, or complaints:

Cyberwrite Inc.

Email: privacy@cyberwrite.com

1 Liberty Plaza, New York, NY, United States

For general inquiries: legal@cyberwrite.com

If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with your local data protection supervisory authority.