Security White Paper
A comprehensive overview of Cyrigo's security architecture, organisational practices,
and data protection standards.
Last updated
12 November 2024
Table of Contents
1. Introduction
2. Business Security
3. Infrastructure Overview
4. Data Protection
5. Sign-in and security
6. Application Security
7. Systems & Servers
8. Monitoring & Incidents
9. Backup & Recovery
10. Outsourced Operations
12. Staff Security
13. Commitment
1. Introduction and Overview
Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from
NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance,
and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy
management.
Security is a core part of Cyrigo’s mission. We design every part of our platform and operations with security,
privacy, and reliability in mind — from our infrastructure and development processes to how we handle customer
data and access control.
2. Business Security
Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices have
access-controlled and physically secure facilities. As a small and specialised team, we manage very limited
on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities and cloud
environments.
All company devices are managed through Microsoft Intune, ensuring they remain secure and compliant, while
Microsoft Entra ID provides centralised identity and access management with strong authentication. Cyrigo AS
applies a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security
controls.
Cyrigo AS actively aligns with recognized information security frameworks such as ISO 27001 and ISO 27002,
and our primary reference standard is ISO 27005.
3. Application Infrastructure Overview
Our platform is hosted on secure servers located in Scandinavian data centres, ensuring compliance with
European data protection regulations (GDPR).
Separation of Environments
Separate production and test environments to ensure
data integrity.
Constant Uptime
Backup systems and constant monitoring ensure that services
remain completely reliable.
Data Protection
All customer data is stored within the EU/EEA, encrypted
both in transit and at rest.
Dedicated Operations
Proactive monitoring, patching, and incident response via
trusted partners.
4. Data Protection
Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption
standards to protect data both when it is stored and when it is transferred.
Data Separation
We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data
is fully isolated.
Dedicated Servers
For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend
systems.
GDPR Compliance
At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.
5. Authentication and Authorization
Cyrigo offers secure and flexible login options. Users can sign in using a username and password that
follow industry best practices, or through Microsoft Entra ID.
Single Sign-On (SSO) for hassle-free access
Multi-factor authentication (MFA) for extra security
Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary
6. Application Security
Security is built into every part of Cyrigo’s development and operations. We follow recognised secure coding
principles and perform regular code reviews and automatic vulnerability testing.
7. System and Server Security
Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored.
Firewalls with strict rule sets limit incoming traffic.
8. Monitoring and Incident Response
We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to
the Cyrigo operations team for immediate investigation.
9. Backup and Recovery
Local backups are performed several times a day. Offsite backups are completed daily and stored securely in an EU data centre.
All backup data is transferred via encrypted connections.
10. Outsourced Operations and Security
Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best
practices for Linux server security and system hardening.
12. Staff Security
Non-Disclosure Agreements (NDAs)
All personnel sign confidentiality agreements to protect
customer information.
Trusted Partners
We work exclusively with subcontractors located in NATO, EU,
or EEA countries.
Security Awareness
Employees receive regular security training on best practices
and emerging threats.
13. Our Commitment to Continuous Security
Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess,
improve, and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.
Security White Paper
A comprehensive overview of Cyrigo's security architecture, organisational practices,
and data protection standards.
Last updated
12 November 2024
Table of Contents
1. Introduction
2. Business Security
3. Infrastructure Overview
4. Data Protection
5. Sign-in and security
6. Application Security
7. Systems & Servers
8. Monitoring & Incidents
9. Backup & Recovery
10. Outsourced Operations
12. Staff Security
13. Commitment
1. Introduction and Overview
Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance, and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy management.
Security is at the heart of what we do at Cyrigo. Every aspect of our platform and operations is built with security, privacy, and reliability in mind — from our infrastructure and development processes to how we manage customer data and access control.
2. Business Security
Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices feature access-controlled and physically secure facilities. As a small, specialised team, we manage very limited on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities, and cloud environments.
All company devices are managed through Microsoft Intune to keep them secure and compliant, while Microsoft Entra ID provides centralized identity and access management with strong authentication. Cyrigo AS uses a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security controls.
Cyrigo AS actively aligns with recognised information security frameworks such as ISO 27001 and ISO 27002, and we use ISO 27005 as our main reference standard.
3. Application Infrastructure Overview
Our platform is hosted on secure servers in Scandinavian data centres, ensuring we fully comply with European data protection laws (GDPR).
4. Data Protection
Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption standards to protect your data both at rest and in transit.
Data Separation
We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data
is fully isolated.
Dedicated Servers
For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend
systems.
GDPR Compliance
At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.
5. Authentication and Authorization
Cyrigo provides secure and flexible login options. Users can sign in using a username and password that meet industry standards, or via Microsoft Entra ID.
Single Sign-On (SSO) for hassle-free access
Multi-factor authentication (MFA) for extra security
Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary
6. Application Security
Separation of Environments
Separate production and test environments to ensure
data integrity.
Constant Uptime
Backup systems and constant monitoring ensure that services
remain completely reliable.
Data Protection
All customer data is stored within the EU/EEA, encrypted
both in transit and at rest.
Dedicated Operations
Proactive monitoring, patching, and incident response via
trusted partners.
Security is built into every part of Cyrigo’s development and operations. We follow recognized secure coding principles and perform regular code reviews and automatic vulnerability testing.
7. System and Server Security
Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored.
Firewalls with strict rule sets limit incoming traffic.
8. Monitoring and Incident Response
We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to the Cyrigo operations team for immediate investigation.
9. Backup and Recovery
Local backups are carried out several times a day. Offsite backups are completed daily and stored securely in an EU data centre. All backup data is transferred using encrypted connections.
10. Outsourced Operations and Security
Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best practices for Linux server security and system hardening.
12. Staff Security
Non-Disclosure Agreements (NDAs)
All staff sign confidentiality agreements to ensure your business data remains secure.
Trusted Partners
We work exclusively with subcontractors located in NATO, EU,
or EEA countries.
Security Awareness
Employees receive regular security training on best practices
and emerging threats.
13. Our Commitment to Continuous Security
Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess, improve and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.

We provide SaaS solutions designed for compliance, risk management and governance
CONTACT US
Terms and Conditions
Security
© 2024 Cyrigo AS. All rights reserved.
Privacy policy
Terms and Conditions
Regulatory Compliance

We provide SaaS solutions designed for compliance, risk management and governance
CONTACT US
Terms and Conditions
Security
Security White Paper
A comprehensive overview of Cyrigo's security architecture, organisational practices,
and data protection standards.
Last updated
12 November 2024
Table of Contents
1. Introduction
2. Business Security
3. Infrastructure Overview
4. Data Protection
5. Sign-in and security
6. Application Security
7. Systems & Servers
8. Monitoring & Incidents
9. Backup & Recovery
10. Outsourced Operations
12. Staff Security
13. Commitment
Non-Disclosure Agreements (NDAs)
All personnel sign confidentiality agreements to protect
customer information.
Trusted Partners
We work exclusively with subcontractors located in NATO, EU,
or EEA countries.
Security Awareness
Employees receive regular security training on best practices
and emerging threats.
1. Introduction and Overview
Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from
NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance,
and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy
management.
Security is a core part of Cyrigo’s mission. We design every part of our platform and operations with security,
privacy, and reliability in mind — from our infrastructure and development processes to how we handle customer
data and access control.
2. Business Security
Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices have
access-controlled and physically secure facilities. As a small and specialised team, we manage very limited
on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities and cloud
environments.
All company devices are managed through Microsoft Intune, ensuring they remain secure and compliant, while
Microsoft Entra ID provides centralised identity and access management with strong authentication. Cyrigo AS
applies a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security
controls.
Cyrigo AS actively aligns with recognized information security frameworks such as ISO 27001 and ISO 27002,
and our primary reference standard is ISO 27005.
3. Application Infrastructure Overview
Our platform is hosted on secure servers located in Scandinavian data centres, ensuring compliance with
European data protection regulations (GDPR).
Separation of Environments
Separate production and test environments to ensure
data integrity.
Constant Uptime
Backup systems and constant monitoring ensure that services
remain completely reliable.
Dedicated Operations
Proactive monitoring, patching, and incident response via
trusted partners.
Data Protection
All customer data is stored within the EU/EEA, encrypted
both in transit and at rest.
4. Data Protection
Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption
standards to protect data both when it is stored and when it is transferred.
Data Separation
We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data
is fully isolated.
Dedicated Servers
For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend
systems.
GDPR Compliance
At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.
5. Authentication and Authorization
Cyrigo offers secure and flexible login options. Users can sign in using a username and password that
follow industry best practices, or through Microsoft Entra ID.
Single Sign-On (SSO) for hassle-free access
Multi-factor authentication (MFA) for extra security
Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary
6. Application Security
Security is built into every part of Cyrigo’s development and operations. We follow recognised secure coding
principles and perform regular code reviews and automatic vulnerability testing.
7. System and Server Security
Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored.
Firewalls with strict rule sets limit incoming traffic.
8. Monitoring and Incident Response
We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to
the Cyrigo operations team for immediate investigation.
9. Backup and Recovery
Local backups are performed several times a day. Offsite backups are completed daily and stored securely in an EU data centre.
All backup data is transferred via encrypted connections.
10. Outsourced Operations and Security
12. Staff Security
13. Our Commitment to Continuous Security
Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess,
improve, and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.
Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best
practices for Linux server security and system hardening.
Do you have any further questions?
Our security team is ready to provide detailed documentation or discuss
specific compliance requirements for your organisation.
Get in touch!

We provide SaaS solutions designed for compliance, risk management and governance
CONTACT US
Terms and Conditions
Security
© 2024 Cyrigo AS. All rights reserved.
Privacy policy
Terms and Conditions
Regulatory Compliance
Security White Paper
A comprehensive overview of Cyrigo's security architecture, organisational practices,
and data protection standards.
Last updated
12 November 2024
Table of Contents
1. Introduction
2. Business Security
3. Infrastructure Overview
4. Data Protection
5. Sign-in and security
6. Application Security
7. Systems & Servers
8. Monitoring & Incidents
9. Backup & Recovery
10. Outsourced Operations
12. Staff Security
13. Commitment
1. Introduction and Overview
Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from
NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance, and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy
management.
Security is at the heart of what we do at Cyrigo. Every aspect of our platform and operations is built with security, privacy, and reliability in mind — from our infrastructure and development processes to how we manage customer data and access control.
2. Business Security
Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices feature access-controlled and physically secure facilities. As a small, specialised team, we manage very limited on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities, and cloud environments.
All company devices are managed through Microsoft Intune, ensuring they remain secure and compliant, while Microsoft Entra ID provides centralised identity and access management with strong authentication. Cyrigo AS
applies a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security controls.
Cyrigo AS actively aligns with recognised information security frameworks such as ISO 27001 and ISO 27002, and we use ISO 27005 as our main reference standard.
3. Application Infrastructure Overview
Our platform is hosted on secure servers in Scandinavian data centres, ensuring we fully comply with European data protection laws (GDPR).
Separation of Environments
Separate production and test environments to ensure
data integrity.
Constant Uptime
Backup systems and constant monitoring ensure that services
remain completely reliable.
Dedicated Operations
Proactive monitoring, patching, and incident response via
trusted partners.
Data Protection
All customer data is stored within the EU/EEA, encrypted
both in transit and at rest.
4. Data Protection
Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption standards to protect your data both at rest and in transit.
Data Separation
We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data
is fully isolated.
Dedicated Servers
For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend
systems.
GDPR Compliance
At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.
5. Authentication and Authorization
Cyrigo provides secure and flexible login options. Users can sign in using a username and password that meet industry standards, or via Microsoft Entra ID.
Single Sign-On (SSO) for hassle-free access
Multi-factor authentication (MFA) for extra security
Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary
6. Application Security
Security is built into every part of Cyrigo’s development and operations. We follow recognized secure coding principles and perform regular code reviews and automatic vulnerability testing.
7. System and Server Security
Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored. Firewalls with strict rule sets limit incoming traffic.
8. Monitoring and Incident Response
We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to the Cyrigo operations team for immediate investigation.
9. Backup and Recovery
Local backups are carried out several times a day. Offsite backups are completed daily and stored securely in an EU data centre. All backup data is transferred using encrypted connections.
10. Outsourced Operations and Security
11. Staff Security
Non-Disclosure Agreements (NDAs)
All personnel sign confidentiality agreements to protect
customer information.
Trusted Partners
We work exclusively with subcontractors located in NATO, EU,
or EEA countries.
Security Awareness
Employees receive regular security training on best practices
and emerging threats.
12. Commitment to Ongoing Security
Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess,
improve, and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.
Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best
practices for Linux server security and system hardening.

We provide SaaS solutions designed for compliance, risk management and governance
CONTACT US
Terms and Conditions
Security

We provide SaaS solutions designed for compliance, risk management and governance
CONTACT US
Terms and Conditions
Security
Security White Paper
A comprehensive overview of Cyrigo's security architecture, organisational practices,
and data protection standards.
Last updated
12 November 2024
Table of Contents
1. Introduction
2. Business Security
3. Infrastructure Overview
4. Data Protection
5. Sign-in and security
6. Application Security
7. Systems & Servers
8. Monitoring & Incidents
9. Backup & Recovery
10. Outsourced Operations
12. Staff Security
13. Commitment
1. Introduction and Overview
Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from
NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance,
and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy
management.
Security is a core part of Cyrigo’s mission. We design every part of our platform and operations with security,
privacy, and reliability in mind — from our infrastructure and development processes to how we handle customer
data and access control.
2. Business Security
Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices have
access-controlled and physically secure facilities. As a small and specialised team, we manage very limited
on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities and cloud
environments.
All company devices are managed through Microsoft Intune, ensuring they remain secure and compliant, while
Microsoft Entra ID provides centralised identity and access management with strong authentication. Cyrigo AS
applies a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security
controls.
Cyrigo AS actively aligns with recognized information security frameworks such as ISO 27001 and ISO 27002,
and our primary reference standard is ISO 27005.
3. Application Infrastructure Overview
Our platform is hosted on secure servers located in Scandinavian data centres, ensuring compliance with
European data protection regulations (GDPR).
Separation of Environments
Separate production and test environments to ensure
data integrity.
Constant Uptime
Backup systems and constant monitoring ensure that services
remain completely reliable.
Dedicated Operations
Proactive monitoring, patching, and incident response via
trusted partners.
Data Protection
All customer data is stored within the EU/EEA, encrypted
both in transit and at rest.
4. Data Protection
Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption
standards to protect data both when it is stored and when it is transferred.
Data Separation
We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data
is fully isolated.
Dedicated Servers
For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend
systems.
GDPR Compliance
At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.
5. Authentication and Authorization
Cyrigo offers secure and flexible login options. Users can sign in using a username and password that
follow industry best practices, or through Microsoft Entra ID.
Single Sign-On (SSO) for hassle-free access
Multi-factor authentication (MFA) for extra security
Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary
6. Application Security
Security is built into every part of Cyrigo’s development and operations. We follow recognised secure coding
principles and perform regular code reviews and automatic vulnerability testing.
7. System and Server Security
Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored.
Firewalls with strict rule sets limit incoming traffic.
8. Monitoring and Incident Response
We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to
the Cyrigo operations team for immediate investigation.
9. Backup and Recovery
Local backups are performed several times a day. Offsite backups are completed daily and stored securely in an EU data centre.
All backup data is transferred via encrypted connections.
10. Outsourced Operations and Security
Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best
practices for Linux server security and system hardening.
12. Staff Security
Non-Disclosure Agreements (NDAs)
All personnel sign confidentiality agreements to protect
customer information.
Security Awareness
Employees receive regular security training on best practices
and emerging threats.
Trusted Partners
We work exclusively with subcontractors located in NATO, EU,
or EEA countries.
13. Our Commitment to Continuous Security
Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess,
improve, and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.
Security White Paper
A comprehensive overview of Cyrigo's security architecture, organisational practices,
and data protection standards.
Last updated
12 November 2024
Table of Contents
1. Introduction
2. Business Security
3. Infrastructure Overview
4. Data Protection
5. Sign-in and security
6. Application Security
7. Systems & Servers
8. Monitoring & Incidents
9. Backup & Recovery
10. Outsourced Operations
12. Staff Security
13. Commitment
1. Introduction and Overview
Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from
NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance,
and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy
management.
Security is a core part of Cyrigo’s mission. We design every part of our platform and operations with security,
privacy, and reliability in mind — from our infrastructure and development processes to how we handle customer
data and access control.
2. Business Security
Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices have
access-controlled and physically secure facilities. As a small and specialised team, we manage very limited
on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities and cloud
environments.
All company devices are managed through Microsoft Intune, ensuring they remain secure and compliant, while
Microsoft Entra ID provides centralised identity and access management with strong authentication. Cyrigo AS
applies a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security
controls.
Cyrigo AS actively aligns with recognized information security frameworks such as ISO 27001 and ISO 27002,
and our primary reference standard is ISO 27005.
3. Application Infrastructure Overview
Our platform is hosted on secure servers located in Scandinavian data centres, ensuring compliance with
European data protection regulations (GDPR).
Separation of Environments
Separate production and test environments to ensure
data integrity.
Constant Uptime
Backup systems and constant monitoring ensure that services
remain completely reliable.
Dedicated Operations
Proactive monitoring, patching, and incident response via
trusted partners.
Data Protection
All customer data is stored within the EU/EEA, encrypted
both in transit and at rest.
4. Data Protection
Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption
standards to protect data both when it is stored and when it is transferred.
Data Separation
We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data
is fully isolated.
Dedicated Servers
For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend
systems.
GDPR Compliance
At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.
5. Authentication and Authorization
Cyrigo offers secure and flexible login options. Users can sign in using a username and password that
follow industry best practices, or through Microsoft Entra ID.
Single Sign-On (SSO) for hassle-free access
Multi-factor authentication (MFA) for extra security
Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary
6. Application Security
Security is built into every part of Cyrigo’s development and operations. We follow recognised secure coding
principles and perform regular code reviews and automatic vulnerability testing.
7. System and Server Security
Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored.
Firewalls with strict rule sets limit incoming traffic.
8. Monitoring and Incident Response
We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to
the Cyrigo operations team for immediate investigation.
9. Backup and Recovery
Local backups are performed several times a day. Offsite backups are completed daily and stored securely in an EU data centre.
All backup data is transferred via encrypted connections.
10. Outsourced Operations and Security
Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best
practices for Linux server security and system hardening.
12. Staff Security
Non-Disclosure Agreements (NDAs)
All personnel sign confidentiality agreements to protect
customer information.
Security Awareness
Employees receive regular security training on best practices
and emerging threats.
Trusted Partners
We work exclusively with subcontractors located in NATO, EU,
or EEA countries.
13. Our Commitment to Continuous Security
Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess,
improve, and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.

We provide SaaS solutions designed for compliance, risk management and governance
CONTACT US
Terms and Conditions
Security