Security White Paper

A comprehensive overview of Cyrigo's security architecture, organisational practices,

and data protection standards.

Last updated

12 November 2024

Table of Contents

1. Introduction

2. Business Security

3. Infrastructure Overview

4. Data Protection

5. Sign-in and security

6. Application Security

7. Systems & Servers

8. Monitoring & Incidents

9. Backup & Recovery

10. Outsourced Operations

12. Staff Security

13. Commitment

1. Introduction and Overview

Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from

NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance,

and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy

management.

Security is a core part of Cyrigo’s mission. We design every part of our platform and operations with security,

privacy, and reliability in mind — from our infrastructure and development processes to how we handle customer

data and access control.

2. Business Security

Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices have

access-controlled and physically secure facilities. As a small and specialised team, we manage very limited

on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities and cloud

environments.

All company devices are managed through Microsoft Intune, ensuring they remain secure and compliant, while

Microsoft Entra ID provides centralised identity and access management with strong authentication. Cyrigo AS

applies a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security

controls.

Cyrigo AS actively aligns with recognized information security frameworks such as ISO 27001 and ISO 27002,

and our primary reference standard is ISO 27005.

3. Application Infrastructure Overview

Our platform is hosted on secure servers located in Scandinavian data centres, ensuring compliance with

European data protection regulations (GDPR).

Separation of Environments

Separate production and test environments to ensure

data integrity.

Constant Uptime

Backup systems and constant monitoring ensure that services

remain completely reliable.

Data Protection

All customer data is stored within the EU/EEA, encrypted

both in transit and at rest.

Dedicated Operations

Proactive monitoring, patching, and incident response via

trusted partners.

4. Data Protection

Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption

standards to protect data both when it is stored and when it is transferred.

Data Separation

We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data

is fully isolated.

Dedicated Servers

For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend

systems.

GDPR Compliance

At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.

5. Authentication and Authorization

Cyrigo offers secure and flexible login options. Users can sign in using a username and password that

follow industry best practices, or through Microsoft Entra ID.

Single Sign-On (SSO) for hassle-free access

Multi-factor authentication (MFA) for extra security

Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary

6. Application Security

Security is built into every part of Cyrigo’s development and operations. We follow recognised secure coding

principles and perform regular code reviews and automatic vulnerability testing.

7. System and Server Security

Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored.

Firewalls with strict rule sets limit incoming traffic.

8. Monitoring and Incident Response

We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to

the Cyrigo operations team for immediate investigation.

9. Backup and Recovery

Local backups are performed several times a day. Offsite backups are completed daily and stored securely in an EU data centre.

All backup data is transferred via encrypted connections.

10. Outsourced Operations and Security

Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best

practices for Linux server security and system hardening.

12. Staff Security

Non-Disclosure Agreements (NDAs)

All personnel sign confidentiality agreements to protect

customer information.

Trusted Partners

We work exclusively with subcontractors located in NATO, EU,

or EEA countries.

Security Awareness

Employees receive regular security training on best practices

and emerging threats.

13. Our Commitment to Continuous Security

Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess,

improve, and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.

Security White Paper

A comprehensive overview of Cyrigo's security architecture, organisational practices,

and data protection standards.

Last updated

12 November 2024

Table of Contents

1. Introduction

2. Business Security

3. Infrastructure Overview

4. Data Protection

5. Sign-in and security

6. Application Security

7. Systems & Servers

8. Monitoring & Incidents

9. Backup & Recovery

10. Outsourced Operations

12. Staff Security

13. Commitment

1. Introduction and Overview

Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance, and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy management.

Security is at the heart of what we do at Cyrigo. Every aspect of our platform and operations is built with security, privacy, and reliability in mind — from our infrastructure and development processes to how we manage customer data and access control.

2. Business Security

Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices feature access-controlled and physically secure facilities. As a small, specialised team, we manage very limited on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities, and cloud environments.

All company devices are managed through Microsoft Intune to keep them secure and compliant, while Microsoft Entra ID provides centralized identity and access management with strong authentication. Cyrigo AS uses a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security controls.

Cyrigo AS actively aligns with recognised information security frameworks such as ISO 27001 and ISO 27002, and we use ISO 27005 as our main reference standard.

3. Application Infrastructure Overview

Our platform is hosted on secure servers in Scandinavian data centres, ensuring we fully comply with European data protection laws (GDPR).

4. Data Protection

Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption standards to protect your data both at rest and in transit.

Data Separation

We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data

is fully isolated.

Dedicated Servers

For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend

systems.

GDPR Compliance

At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.

5. Authentication and Authorization

Cyrigo provides secure and flexible login options. Users can sign in using a username and password that meet industry standards, or via Microsoft Entra ID.

Single Sign-On (SSO) for hassle-free access

Multi-factor authentication (MFA) for extra security

Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary

6. Application Security

Separation of Environments

Separate production and test environments to ensure

data integrity.

Constant Uptime

Backup systems and constant monitoring ensure that services

remain completely reliable.

Data Protection

All customer data is stored within the EU/EEA, encrypted

both in transit and at rest.

Dedicated Operations

Proactive monitoring, patching, and incident response via

trusted partners.

Security is built into every part of Cyrigo’s development and operations. We follow recognized secure coding principles and perform regular code reviews and automatic vulnerability testing.

7. System and Server Security

Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored.

Firewalls with strict rule sets limit incoming traffic.

8. Monitoring and Incident Response

We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to the Cyrigo operations team for immediate investigation.

9. Backup and Recovery

Local backups are carried out several times a day. Offsite backups are completed daily and stored securely in an EU data centre. All backup data is transferred using encrypted connections.

10. Outsourced Operations and Security

Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best practices for Linux server security and system hardening.

12. Staff Security

Non-Disclosure Agreements (NDAs)

All staff sign confidentiality agreements to ensure your business data remains secure.

Trusted Partners

We work exclusively with subcontractors located in NATO, EU,

or EEA countries.

Security Awareness

Employees receive regular security training on best practices

and emerging threats.

13. Our Commitment to Continuous Security

Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess, improve and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.

We provide SaaS solutions designed for compliance, risk management and governance

© 2024 Cyrigo AS. All rights reserved.

Privacy policy

Terms and Conditions

Regulatory Compliance

We provide SaaS solutions designed for compliance, risk management and governance

Security White Paper

A comprehensive overview of Cyrigo's security architecture, organisational practices,

and data protection standards.

Last updated

12 November 2024

Table of Contents

1. Introduction

2. Business Security

3. Infrastructure Overview

4. Data Protection

5. Sign-in and security

6. Application Security

7. Systems & Servers

8. Monitoring & Incidents

9. Backup & Recovery

10. Outsourced Operations

12. Staff Security

13. Commitment

Non-Disclosure Agreements (NDAs)

All personnel sign confidentiality agreements to protect

customer information.

Trusted Partners

We work exclusively with subcontractors located in NATO, EU,

or EEA countries.

Security Awareness

Employees receive regular security training on best practices

and emerging threats.

1. Introduction and Overview

Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from

NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance,

and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy

management.

Security is a core part of Cyrigo’s mission. We design every part of our platform and operations with security,

privacy, and reliability in mind — from our infrastructure and development processes to how we handle customer

data and access control.

2. Business Security

Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices have

access-controlled and physically secure facilities. As a small and specialised team, we manage very limited

on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities and cloud

environments.

All company devices are managed through Microsoft Intune, ensuring they remain secure and compliant, while

Microsoft Entra ID provides centralised identity and access management with strong authentication. Cyrigo AS

applies a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security

controls.

Cyrigo AS actively aligns with recognized information security frameworks such as ISO 27001 and ISO 27002,

and our primary reference standard is ISO 27005.

3. Application Infrastructure Overview

Our platform is hosted on secure servers located in Scandinavian data centres, ensuring compliance with

European data protection regulations (GDPR).

Separation of Environments

Separate production and test environments to ensure

data integrity.

Constant Uptime

Backup systems and constant monitoring ensure that services

remain completely reliable.

Dedicated Operations

Proactive monitoring, patching, and incident response via

trusted partners.

Data Protection

All customer data is stored within the EU/EEA, encrypted

both in transit and at rest.

4. Data Protection

Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption

standards to protect data both when it is stored and when it is transferred.

Data Separation

We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data

is fully isolated.

Dedicated Servers

For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend

systems.

GDPR Compliance

At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.

5. Authentication and Authorization

Cyrigo offers secure and flexible login options. Users can sign in using a username and password that

follow industry best practices, or through Microsoft Entra ID.

Single Sign-On (SSO) for hassle-free access

Multi-factor authentication (MFA) for extra security

Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary

6. Application Security

Security is built into every part of Cyrigo’s development and operations. We follow recognised secure coding

principles and perform regular code reviews and automatic vulnerability testing.

7. System and Server Security

Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored.

Firewalls with strict rule sets limit incoming traffic.

8. Monitoring and Incident Response

We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to

the Cyrigo operations team for immediate investigation.

9. Backup and Recovery

Local backups are performed several times a day. Offsite backups are completed daily and stored securely in an EU data centre.

All backup data is transferred via encrypted connections.

10. Outsourced Operations and Security

12. Staff Security

13. Our Commitment to Continuous Security

Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess,

improve, and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.

Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best

practices for Linux server security and system hardening.

Do you have any further questions?

Our security team is ready to provide detailed documentation or discuss

specific compliance requirements for your organisation.


Get in touch!

We provide SaaS solutions designed for compliance, risk management and governance

© 2024 Cyrigo AS. All rights reserved.

Privacy policy

Terms and Conditions

Regulatory Compliance

Security White Paper

A comprehensive overview of Cyrigo's security architecture, organisational practices,

and data protection standards.

Last updated

12 November 2024

Table of Contents

1. Introduction

2. Business Security

3. Infrastructure Overview

4. Data Protection

5. Sign-in and security

6. Application Security

7. Systems & Servers

8. Monitoring & Incidents

9. Backup & Recovery

10. Outsourced Operations

12. Staff Security

13. Commitment

1. Introduction and Overview

Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from

NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance, and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy

management.

Security is at the heart of what we do at Cyrigo. Every aspect of our platform and operations is built with security, privacy, and reliability in mind — from our infrastructure and development processes to how we manage customer data and access control.

2. Business Security

Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices feature access-controlled and physically secure facilities. As a small, specialised team, we manage very limited on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities, and cloud environments.

All company devices are managed through Microsoft Intune, ensuring they remain secure and compliant, while Microsoft Entra ID provides centralised identity and access management with strong authentication. Cyrigo AS

applies a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security controls.

Cyrigo AS actively aligns with recognised information security frameworks such as ISO 27001 and ISO 27002, and we use ISO 27005 as our main reference standard.

3. Application Infrastructure Overview

Our platform is hosted on secure servers in Scandinavian data centres, ensuring we fully comply with European data protection laws (GDPR).

Separation of Environments

Separate production and test environments to ensure

data integrity.

Constant Uptime

Backup systems and constant monitoring ensure that services

remain completely reliable.

Dedicated Operations

Proactive monitoring, patching, and incident response via

trusted partners.

Data Protection

All customer data is stored within the EU/EEA, encrypted

both in transit and at rest.

4. Data Protection

Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption standards to protect your data both at rest and in transit.

Data Separation

We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data

is fully isolated.

Dedicated Servers

For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend

systems.

GDPR Compliance

At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.

5. Authentication and Authorization

Cyrigo provides secure and flexible login options. Users can sign in using a username and password that meet industry standards, or via Microsoft Entra ID.

Single Sign-On (SSO) for hassle-free access

Multi-factor authentication (MFA) for extra security

Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary

6. Application Security

Security is built into every part of Cyrigo’s development and operations. We follow recognized secure coding principles and perform regular code reviews and automatic vulnerability testing.

7. System and Server Security

Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored. Firewalls with strict rule sets limit incoming traffic.

8. Monitoring and Incident Response

We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to the Cyrigo operations team for immediate investigation.

9. Backup and Recovery

Local backups are carried out several times a day. Offsite backups are completed daily and stored securely in an EU data centre. All backup data is transferred using encrypted connections.

10. Outsourced Operations and Security

11. Staff Security

Non-Disclosure Agreements (NDAs)

All personnel sign confidentiality agreements to protect

customer information.

Trusted Partners

We work exclusively with subcontractors located in NATO, EU,

or EEA countries.

Security Awareness

Employees receive regular security training on best practices

and emerging threats.

12. Commitment to Ongoing Security

Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess,

improve, and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.

Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best

practices for Linux server security and system hardening.

We provide SaaS solutions designed for compliance, risk management and governance

We provide SaaS solutions designed for compliance, risk management and governance

Security White Paper

A comprehensive overview of Cyrigo's security architecture, organisational practices,

and data protection standards.

Last updated

12 November 2024

Table of Contents

1. Introduction

2. Business Security

3. Infrastructure Overview

4. Data Protection

5. Sign-in and security

6. Application Security

7. Systems & Servers

8. Monitoring & Incidents

9. Backup & Recovery

10. Outsourced Operations

12. Staff Security

13. Commitment

1. Introduction and Overview

Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from

NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance,

and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy

management.

Security is a core part of Cyrigo’s mission. We design every part of our platform and operations with security,

privacy, and reliability in mind — from our infrastructure and development processes to how we handle customer

data and access control.

2. Business Security

Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices have

access-controlled and physically secure facilities. As a small and specialised team, we manage very limited

on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities and cloud

environments.

All company devices are managed through Microsoft Intune, ensuring they remain secure and compliant, while

Microsoft Entra ID provides centralised identity and access management with strong authentication. Cyrigo AS

applies a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security

controls.

Cyrigo AS actively aligns with recognized information security frameworks such as ISO 27001 and ISO 27002,

and our primary reference standard is ISO 27005.

3. Application Infrastructure Overview

Our platform is hosted on secure servers located in Scandinavian data centres, ensuring compliance with

European data protection regulations (GDPR).

Separation of Environments

Separate production and test environments to ensure

data integrity.

Constant Uptime

Backup systems and constant monitoring ensure that services

remain completely reliable.

Dedicated Operations

Proactive monitoring, patching, and incident response via

trusted partners.

Data Protection

All customer data is stored within the EU/EEA, encrypted

both in transit and at rest.

4. Data Protection

Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption

standards to protect data both when it is stored and when it is transferred.

Data Separation

We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data

is fully isolated.

Dedicated Servers

For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend

systems.

GDPR Compliance

At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.

5. Authentication and Authorization

Cyrigo offers secure and flexible login options. Users can sign in using a username and password that

follow industry best practices, or through Microsoft Entra ID.

Single Sign-On (SSO) for hassle-free access

Multi-factor authentication (MFA) for extra security

Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary

6. Application Security

Security is built into every part of Cyrigo’s development and operations. We follow recognised secure coding

principles and perform regular code reviews and automatic vulnerability testing.

7. System and Server Security

Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored.

Firewalls with strict rule sets limit incoming traffic.

8. Monitoring and Incident Response

We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to

the Cyrigo operations team for immediate investigation.

9. Backup and Recovery

Local backups are performed several times a day. Offsite backups are completed daily and stored securely in an EU data centre.

All backup data is transferred via encrypted connections.

10. Outsourced Operations and Security

Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best

practices for Linux server security and system hardening.

12. Staff Security

Non-Disclosure Agreements (NDAs)

All personnel sign confidentiality agreements to protect

customer information.

Security Awareness

Employees receive regular security training on best practices

and emerging threats.

Trusted Partners

We work exclusively with subcontractors located in NATO, EU,

or EEA countries.

13. Our Commitment to Continuous Security

Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess,

improve, and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.

Security White Paper

A comprehensive overview of Cyrigo's security architecture, organisational practices,

and data protection standards.

Last updated

12 November 2024

Table of Contents

1. Introduction

2. Business Security

3. Infrastructure Overview

4. Data Protection

5. Sign-in and security

6. Application Security

7. Systems & Servers

8. Monitoring & Incidents

9. Backup & Recovery

10. Outsourced Operations

12. Staff Security

13. Commitment

1. Introduction and Overview

Cyrigo AS is a growing cybersecurity company with a strong foundation built on research and experience from

NTNU. We offer a cutting-edge SaaS platform designed to help businesses efficiently manage risks, compliance,

and cybersecurity. It provides a complete overview and control of suppliers, information systems, and privacy

management.

Security is a core part of Cyrigo’s mission. We design every part of our platform and operations with security,

privacy, and reliability in mind — from our infrastructure and development processes to how we handle customer

data and access control.

2. Business Security

Cyrigo AS operates from our main offices in Norway, located at Studievegen 16, 2815 Gjøvik. The offices have

access-controlled and physically secure facilities. As a small and specialised team, we manage very limited

on-premises infrastructure, allowing us to focus our security efforts on endpoints, identities and cloud

environments.

All company devices are managed through Microsoft Intune, ensuring they remain secure and compliant, while

Microsoft Entra ID provides centralised identity and access management with strong authentication. Cyrigo AS

applies a risk-based approach, maintaining a clear overview of vendors, IT systems, assets, and security

controls.

Cyrigo AS actively aligns with recognized information security frameworks such as ISO 27001 and ISO 27002,

and our primary reference standard is ISO 27005.

3. Application Infrastructure Overview

Our platform is hosted on secure servers located in Scandinavian data centres, ensuring compliance with

European data protection regulations (GDPR).

Separation of Environments

Separate production and test environments to ensure

data integrity.

Constant Uptime

Backup systems and constant monitoring ensure that services

remain completely reliable.

Dedicated Operations

Proactive monitoring, patching, and incident response via

trusted partners.

Data Protection

All customer data is stored within the EU/EEA, encrypted

both in transit and at rest.

4. Data Protection

Cyrigo AS ensures that all customer data is handled securely and confidentially. We use modern encryption

standards to protect data both when it is stored and when it is transferred.

Data Separation

We ensure strict data segregation within our platform to prevent accidental or unauthorised access. Every customer's data

is fully isolated.

Dedicated Servers

For customers with higher security requirements, we offer a Private Instance of Cyrigo with dedicated versioning and backend

systems.

GDPR Compliance

At Cyrigo AS, we are committed to protecting your data privacy. We act strictly as a Data Processor, handling all data on behalf of our customers.

5. Authentication and Authorization

Cyrigo offers secure and flexible login options. Users can sign in using a username and password that

follow industry best practices, or through Microsoft Entra ID.

Single Sign-On (SSO) for hassle-free access

Multi-factor authentication (MFA) for extra security

Role-Based Access Control (RBAC) to ensure users only have the minimum access necessary

6. Application Security

Security is built into every part of Cyrigo’s development and operations. We follow recognised secure coding

principles and perform regular code reviews and automatic vulnerability testing.

7. System and Server Security

Our systems are hosted in Scandinavian data centres, where servers are continuously updated and monitored.

Firewalls with strict rule sets limit incoming traffic.

8. Monitoring and Incident Response

We combine local monitoring with external uptime services. If any disruption occurs, automated alerts are sent to

the Cyrigo operations team for immediate investigation.

9. Backup and Recovery

Local backups are performed several times a day. Offsite backups are completed daily and stored securely in an EU data centre.

All backup data is transferred via encrypted connections.

10. Outsourced Operations and Security

Cyrigo partners with OffCenit AS for managed hosting and security operations. OffCenit follows established best

practices for Linux server security and system hardening.

12. Staff Security

Non-Disclosure Agreements (NDAs)

All personnel sign confidentiality agreements to protect

customer information.

Security Awareness

Employees receive regular security training on best practices

and emerging threats.

Trusted Partners

We work exclusively with subcontractors located in NATO, EU,

or EEA countries.

13. Our Commitment to Continuous Security

Cyrigo AS is committed to maintaining a strong and transparent security posture. We continuously assess,

improve, and document our practices to ensure our customers can rely on Cyrigo as a trusted partner.

We provide SaaS solutions designed for compliance, risk management and governance