πŸ”’ Verified Company Β· Live Platform Metrics

The Trust Center

Real company information, real platform metrics pulled live from our database, and a transparent look at how we handle your data and SLAs β€” nothing fabricated, nothing inflated.

πŸ“… Book Free Security Consultation View security.txt
β€”
Total Scans
β€”
CVEs Tracked Live
99.9%
Platform Uptime SLA
<2h
Critical CVE Alert SLA

Verified Company Information

Legal entity details, on the record. No anonymous shell β€” a registered Indian private limited company.

🏒

Legal Entity

CYBERDUDEBIVASH PRIVATE LIMITED

CIN: U74999OR2024PTC049281

GST: 21ARKPN8270G1ZP

Founded 2024 Β· Odisha, India

πŸ‘€

Founder

Bivash β€” Founder & Principal Security Architect

Cybersecurity practitioner specializing in AI-powered threat intelligence, domain security analysis, and enterprise security architecture.

LinkedIn Profile β†’
πŸ“‹

Compliance & Registrations

PAN: ARKPN8270G

MSME Udyam: UDYAM-OD-19-0133456 (NIC 63122)

Startup India (DPIIT): IN-0426-9439SC

Digital Identity: eMudhra Verified Profile

Security Methodology

How scans, AI analysis, and data handling actually work under the hood.

πŸ”

Scan Engine

Deterministic, static analysis β€” not live network reconnaissance. Domain risk scoring runs entirely from domain-string characteristics (TLD reputation, phishing-pattern matching, structural signals); TLS, DNSSEC, HTTP header, port, and email-authentication findings are explicitly flagged as requiring live verification rather than presented as observed. Every scan response carries a machine-readable assessment_mode and live_verification field so this is checkable, not just claimed. See Verified Detection Methodology below.

🧠

AI Analysis

Scan scoring and threat correlation are deterministic. Conversational AI features (copilot, AI verdicts, executive summaries) are processed by external LLM providers disclosed in our Sub-Processor List, with provider selection and fallback controlled by the platform.

πŸ—„οΈ

Data Handling

Scan targets and results are stored under your account for history and reports, encrypted at rest, and permanently erased on account deletion (GDPR/DPDP right to erasure).

Compliance Framework Status

Honestly scoped β€” we mark frameworks "In Progress" or "Planning" rather than implying certifications we don't yet hold.

Verified Detection Methodology

Most AI security vendors report a single "detection accuracy" percentage with no independent audit behind it. Our domain scan engine isn't an ML classifier making claims like that in the first place β€” it's deterministic, documented business logic, so instead of an unverifiable accuracy number we publish something checkable: every documented risk rule, tested in isolation, with the real pass/fail result from the last CI run.

Loading verified results…

Methodology and full rule list: scripts/domain-engine-rule-conformance.mjs in the public repository. Re-run it yourself against workers/src/engine.js β€” same input, same result, every time.

Vulnerability Disclosure

Found a security issue? Here's how to report it responsibly.

πŸ“§

Contact

security@cyberdudebivash.com

⏱️

Response SLA

Critical: 24h, High: 72h, Medium: 7 days

🎯

Bug Bounty

Private program β€” contact for access

Service Level Commitments

What you can hold us to.

πŸ“¨

Report Delivery

Instant (automated) to 4 hours (human review)

πŸ“‹

Assessment Delivery

72 hours standard Β· 48h premium Β· 24h enterprise

🚨

Critical CVE Alert

< 2 hours from NVD publication

πŸ’¬

Support Response

< 4 business hours (email), immediate (WhatsApp)

Enterprise Assessment Process

Five steps, start to finish.

1

Book & Pay

Instant Razorpay checkout. GST-compliant invoice sent immediately.

2

Intake Form

We send a 5-question form to understand your scope and priorities.

3

Analysis

Our analyst runs a comprehensive assessment β€” automated plus manual review.

4

Report Delivery

Full PDF report delivered within 72 hours to your email.

5

Expert Call

30-minute video walkthrough of all findings with Q&A.

Platform Infrastructure

Infrastructure

Cloudflare Workers + D1 (SQLite) + KV Storage. Edge-deployed globally with India-region data preference.

Application Security

JWT authentication, rate limiting, OWASP input validation, and audit logging across all API endpoints.

Threat intel feeds are partially open-source: github.com/cyberdudebivash/cyberdudebivash-ai-security-hub

Sub-Processor Disclosure

Third parties that may process data on our behalf. Enterprise customers receive 30 days advance notice before a new sub-processor is added. Questions: privacy@cyberdudebivash.in

Infrastructure & Payments

  • Cloudflare, Inc. (US) β€” compute, database, storage, CDN. Processes account data, API traffic, scan results.
  • Razorpay Software Pvt Ltd (India) β€” payment processing. Card/UPI credentials are tokenized by Razorpay and never touch our application layer.
  • Google LLC (US) β€” Google Analytics 4 on public marketing pages, with ad personalization signals disabled.

AI / LLM Inference

Conversational AI features (AI Copilot, AI verdicts, executive summaries) send prompt content β€” which may include chat messages, scan targets, and scan findings β€” to one inference provider per request, selected by our provider router with automatic fallback: Groq (US), Cloudflare Workers AI (US/edge), and β€” only where configured β€” DeepSeek (China), OpenRouter (US), Together AI (US), Anthropic (US). Deterministic features (scan scoring, template-based rule generation, CVE ingestion) do not call LLM providers.

Questions about our security posture?

Talk directly to our security team β€” no sales script.

πŸ“… Book a Call βœ‰οΈ Email Us