Privacy Policy

CyOp Security LLC (“CyOp,” “we,” “us,” or “our”) operates cyopsecuritas.com (the “website”) to provide information about its professional services and business activities. This Privacy Policy explains how we collect, use, disclose, and retain personal information when you visit the website or contact us about a potential engagement.

This policy applies to the public website and general business inquiries. Information processed during a client engagement is governed by the applicable contract, statement of work, confidentiality agreement, data-protection agreement, or other written instructions, which control over this policy to the extent of any conflict.

This policy is a notice, not a contract. It does not create, and shall not be construed to create, any contractual or other legal right, duty, or obligation on the part of CyOp beyond those imposed by applicable law.

1. No Engagement, Duty, or Confidential Relationship

Visiting the website or sending an unsolicited communication does not create a client relationship, engagement, fiduciary duty, or duty of confidentiality. Do not send confidential, proprietary, or sensitive information until an engagement has been established in writing and an appropriate transmission method has been agreed. Unsolicited information is received without any obligation of confidentiality or non-use, except as required by applicable law.

2. Information We Collect

Information you provide

If you email us, we may receive your name, email address, organization, job title, telephone number if you include it, message content, attachments, and related email metadata. We may also receive information you provide during follow-up communications concerning a potential or existing business relationship.

The website currently does not provide visitor accounts, a contact form, public comments, online payment, appointment scheduling, or newsletter registration.

Information collected automatically

Our website host, WordPress installation, and supporting security systems may automatically process ordinary technical data needed to deliver, maintain, troubleshoot, and protect the website. This may include:

  • Internet Protocol address and general location inferred from it;
  • browser type, device type, operating system, and language;
  • referring page, requested pages or files, request date and time, and response status;
  • diagnostic, performance, cache, error, and security-event data; and
  • information associated with suspected abuse, malicious traffic, or attempted unauthorized access.

We receive this information from your browser or device and from service providers that operate or protect the website.

Deidentified and aggregated information

We may create or use deidentified or aggregated information that does not identify you. We maintain and use such information only in deidentified form and do not attempt to reidentify it, except as permitted by law to test the effectiveness of deidentification.

Sensitive information

The public website is not designed to collect sensitive personal information. Do not send passwords, authentication secrets, government identification numbers, payment-card or banking information, protected health information, vulnerability evidence, exploit code, confidential system details, client data, or other sensitive records in an unsolicited communication. If sensitive information is necessary for an authorized engagement, we will arrange an appropriate transmission method and handling terms. If you send sensitive information without such arrangements, we may delete it without notice and without review.

Third-party information and vulnerability reports

Do not send us personal information about another person, or information concerning suspected vulnerabilities in systems that you do not own or lack written authorization to test, unless the law requires or permits you to do so. CyOp does not solicit, authorize, direct, or condone unauthorized access to any system. Receipt of any such information does not constitute acceptance, engagement, endorsement, or authorization by CyOp. We reserve the right to preserve such communications and to report suspected unlawful activity to appropriate authorities.

If you wish to report a suspected security issue affecting the website itself, email aaron@cyopsecuritas.com with a description only. Do not include exploit code, extracted data, or evidence obtained through unauthorized access. CyOp does not operate a bug-bounty program and does not offer compensation, safe harbor, or authorization for testing of its systems.

3. Cookies, Analytics, and Tracking

CyOp does not currently use visitor analytics, advertising technology, tracking pixels, behavioral profiling, external font services, or third-party media embeds on this website. The current CyOp theme adds no cookies or third-party JavaScript.

WordPress, the hosting environment, or security infrastructure may use cookies or similar technologies that are strictly necessary to provide, secure, cache, or administer the website. Administrative login cookies apply to authorized site administrators and are not used to advertise to public visitors. Blocking necessary cookies may affect site operation.

CyOp has not enabled any third party to collect personal information through this website for cross-site behavioral advertising or to track visitors over time across unrelated websites. If our practices change, we will update this policy and provide any notices or choices required by applicable law before the change takes effect.

4. How We Use Information

We may use personal information to:

  • provide, operate, maintain, troubleshoot, and secure the website;
  • respond to inquiries and communicate with you;
  • evaluate, plan, establish, administer, or perform a business relationship;
  • prepare requested proposals, agreements, or service information;
  • screen inquiries for legitimacy, conflicts of interest, sanctions or export restrictions, and lawful-purpose verification before accepting an engagement;
  • prevent, detect, investigate, respond to, and document fraud, abuse, security incidents, or unlawful activity, including preserving evidence and cooperating with law enforcement;
  • maintain appropriate business, contractual, tax, insurance, audit, licensing, and compliance records, including records required of a licensed Texas security services contractor and licensed private investigator;
  • establish, exercise, or defend legal rights and claims; and
  • comply with applicable law, legal process, and enforceable governmental requests.

We do not use website or inquiry information to make automated decisions that produce legal or similarly significant effects.

5. How We Disclose Information

We may disclose personal information only as reasonably necessary for the purposes described above:

  • Service providers. Website technical data is processed by Namecheap, Inc. through its EasyWP hosting service and may be processed by providers supporting domain services, email, information technology, security, backup, or records management. Direct email content and metadata are processed by the applicable email providers. These providers receive only the information needed to perform their services and process information under their own terms and privacy obligations.
  • Professional advisers. Information may be disclosed to attorneys, accountants, auditors, insurers, or other professional advisers when reasonably necessary.
  • Legal, safety, and security purposes. Information may be disclosed to courts, regulators, licensing authorities, law-enforcement agencies, or other appropriate parties when required by law, when reasonably necessary to protect the rights, safety, property, systems, or users of CyOp or others, or to investigate, prevent, or take action regarding suspected fraud, abuse, or unlawful activity. We reserve the right to fully cooperate with lawful investigations.
  • Business transaction. Information may be transferred as part of an actual or proposed merger, acquisition, financing, reorganization, sale of assets, dissolution, or similar transaction, subject to appropriate confidentiality and use restrictions.
  • At your direction. We may disclose information when you request or authorize us to do so.

CyOp does not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or offer financial incentives in exchange for it. CyOp has not done so during the preceding 12 months.

6. Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected. Retention depends on the nature of the information and may include the duration of an inquiry or business relationship, reasonable follow-up, applicable contractual or client-record requirements, regulatory and licensing record-keeping requirements, tax and accounting requirements, limitation periods, dispute resolution, security needs, and legal obligations.

Technical logs are retained according to operational and security needs and the hosting provider’s retention practices. Information relevant to a security incident, dispute, legal hold, or investigation may be retained for as long as reasonably necessary for that purpose, notwithstanding any other retention period stated or implied in this policy. Residual copies may remain in protected backups until those backups expire under the applicable rotation. When information is no longer needed, we delete it, deidentify it, or allow it to expire through established retention processes.

7. Security

We use reasonable administrative and technical measures appropriate to the nature of the information to protect it from unauthorized access, use, alteration, loss, or disclosure. No website, email system, storage system, or Internet transmission can be guaranteed completely secure, and we cannot warrant the security of information you transmit to us. You transmit information at your own risk. Please use an agreed secure method rather than ordinary email when transmitting sensitive engagement information.

Email authenticity. CyOp will never ask you to provide passwords, authentication codes, or payment information by unsolicited email. If you receive a suspicious message claiming to be from CyOp, do not respond to it; instead, contact us directly at the address in Section 14.

8. Your Privacy Rights

Depending on where you reside and subject to applicable law, its thresholds, and its exemptions, you may have the right to:

  • confirm whether we process your personal information and access it;
  • correct inaccurate personal information;
  • request deletion of personal information;
  • obtain a portable copy of personal information you provided;
  • opt out of a sale, targeted advertising, or certain profiling; and
  • appeal a decision concerning a privacy request.

CyOp does not currently sell personal information, use it for targeted advertising, or conduct profiling that produces legal or similarly significant effects. Some privacy laws apply only to businesses that meet certain size, revenue, or data-volume thresholds, and CyOp may be exempt from some or all of them. Where a law does not grant you a particular right, we may nevertheless honor a reasonable request as a courtesy, in our discretion, without waiving any exemption or creating any obligation to honor future requests.

To submit a request, email aaron@cyopsecuritas.com with the subject Privacy Request and describe the right you wish to exercise. Include your name, the email address you used to contact us, your state or country of residence, and enough information to identify the relevant interaction. Do not send sensitive identity documents unless we specifically request them through an appropriate method.

We may request information reasonably necessary to verify your identity and authority, and we may deny a request that we cannot verify or that is manifestly unfounded, excessive, repetitive, or exempt under applicable law. An authorized agent may submit a request when permitted by law, but we may require proof of authorization and verification of the consumer’s identity. We may retain records of privacy requests and our responses as required or permitted by law. We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.

Deletion requests are subject to lawful exceptions, including retention needed to complete a transaction, detect and protect against security incidents or fraud, comply with legal obligations, exercise or defend legal claims, and other purposes permitted by applicable law.

If we deny a request, you may appeal by replying to our decision with the subject Privacy Appeal and explaining why you believe the decision should be reconsidered. If an appeal is denied and applicable law provides a regulator-complaint process, our response will provide the appropriate information.

9. Browser Privacy Signals

Because CyOp does not conduct cross-site behavioral tracking, a browser “Do Not Track” signal does not change the website’s current operation. Where applicable law requires recognition of an opt-out preference signal, such as Global Privacy Control, we treat the signal as a request to opt out of sale or targeted-advertising uses associated with that browser or device. CyOp does not currently engage in either practice.

10. Children’s Privacy

This website is intended for business and professional audiences and is not directed to children. We do not knowingly collect personal information online from children under 13, and we do not knowingly sell or share the personal information of anyone under 18. If we learn that personal information of a child under 13 was collected through the website, we will take reasonable steps to delete it.

11. Processing in the United States

CyOp is based in San Antonio, Texas. The website and related business communications are operated and processed in the United States. If you access the website from another country, you do so on your own initiative, and your information may be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction. The website is directed to audiences in the United States and is not intended to target residents of other jurisdictions.

12. External Links

The website may link to websites or services operated by others. CyOp does not control and is not responsible for their content, security, or privacy practices. Review the privacy notice of any external service you choose to use.

13. Governing Law; Severability; Changes

This policy and any dispute arising out of or relating to it or the website’s privacy practices are governed by the laws of the State of Texas and applicable United States federal law, without regard to conflict-of-law principles, except where the law of your jurisdiction mandatorily applies. Exclusive venue for any such dispute lies in the state or federal courts located in Bexar County, Texas, to the extent permitted by applicable law.

If any provision of this policy is held invalid or unenforceable, the remaining provisions remain in full force and effect. Our failure to enforce any provision is not a waiver of it.

We may revise this policy at any time to reflect changes in the website, our practices, service providers, or applicable law. We will post the revised policy on this page and update the “Last updated” date, and the revised policy applies from that date. If a change materially affects how we use information already collected, we will provide additional notice when required by law. Your continued use of the website after a revision takes effect constitutes acceptance of the revised policy to the extent permitted by law.

14. Contact

For privacy questions, requests, or appeals, contact:

CyOp Security LLC
San Antonio, Texas
aaron@cyopsecuritas.com

15. Publication Dates

Effective date: July 25, 2026
Last updated: July 25, 2026