Institutional Governance & Compliance

Privacy Policy

Data protection, confidentiality, and technical integrity are fundamental to our practice. Effective Date: August 14, 2026.

1. Introduction

Incisive Cyber ("we", "us", "our") respects your privacy. As a strategic cybersecurity advisory firm, data protection, confidentiality, and technical integrity are fundamental to our core operating practice.

This Privacy Policy explains how we collect, use, and protect personal information in compliance with the Australian Privacy Act 1988 (Cth), the 13 Australian Privacy Principles (APPs), applicable NSW privacy standards (PPIPA), and international privacy benchmarks such as the General Data Protection Regulation (GDPR).

2. Information We Collect

We practice strict data minimisation. We only collect information that is strictly essential for delivering high-assurance advisory services and maintaining website security:

  • Inquiry & Contact Data: Name, business email address, job title, organisation name, and specific project details provided when submitting our confidential advisory form.
  • Security & Technical Telemetry: Standard, non-identifying HTTP server logs (IP address, browser user agent string, timestamps) processed at the network edge strictly for security monitoring and Content Security Policy (CSP) enforcement.

Zero-Tracking Commitment

We operate a zero-tracking website. We do not use third-party advertising pixels, cross-site trackers, or behavioural profiling cookies.

3. How We Use Information

We use collected information exclusively to:

  1. Deliver executive security advisory, Virtual CISO, and resilience engineering services.
  2. Respond promptly and confidentially to your consultation requests.
  3. Maintain, protect, and audit the technical security of our digital infrastructure.

Use of Artificial Intelligence (AI) & Data Governance

Incisive Cyber may utilise secure, enterprise-grade AI technologies to assist our advisory team in synthesising research, preparing supporting information, and optimising service delivery.

Strict Non-Training Guarantee: Under no circumstances will personal data, client information, or inquiry submissions provided to Incisive Cyber be used to train, retune, or improve public or commercial AI models. All AI-assisted workflows operate within isolated, enterprise-bounded environments governed by strict zero-retention policies.

Zero Commercial Data Sales: We never sell, rent, trade, or share your personal or business information with third parties for marketing purposes.

4. Security & Zero-Trust Governance

In alignment with our core operating framework (Legal, Ethical, Moral, Secure), all data entrusted to Incisive Cyber is safeguarded by strict zero-trust controls:

  • Technical Safeguards: Modern TLS 1.3 encryption in transit and AES-256 encryption at rest.
  • Automated Pre-Flight Verification: Continuous static analysis (npm run sec-check) ensuring zero unauthorised script execution or data leakage.
  • Restricted Access: Access is limited strictly to authorised advisory partners bound by non-disclosure agreements.

5. Your Rights & Complaints

You have the right to request access to, correction of, or deletion of any personal information we hold about you.