1. Introduction#
CyberCube Services Private Limited, referred to as “CyberCube,” “DhanushGuard,” “we,” “us,” or “our,” provides DhanushGuard, a cloud-security, cloud-compliance, configuration-assessment, evidence-collection and audit-automation platform.
DhanushGuard may allow authorised organisations to connect supported cloud accounts, select approved security or compliance operations, assess cloud-resource configurations, collect evidence and manage findings.
This Privacy Policy explains how we process personal data and other information when an organisation or individual:
- visits a DhanushGuard website;
- creates or administers an account;
- connects a cloud environment;
- executes an approved assessment;
- reviews a finding or report;
- uses a predefined query or compliance workflow;
- integrates DhanushGuard with another service; or
- communicates with our personnel.
2. Scope#
This Privacy Policy applies to usage of:
- DhanushGuard websites and portals;
- customer and administrator accounts;
- cloud-account integrations;
- approved cloud-security and compliance assessments;
- predefined domain-query workflows;
- APIs and connectors;
- evidence and finding management;
- dashboards and reports;
- implementation and support services; and
- related DhanushGuard functionality.
It does not govern a third-party cloud provider’s independent processing.
3. Roles and Responsibilities#
3.1 CyberCube as data fiduciary or controller
CyberCube generally determines the purposes and means of processing for:
- account information;
- customer contact information;
- billing records;
- product telemetry;
- security logs;
- support communications;
- website analytics;
- service administration; and
- CyberCube’s own legal and operational requirements.
3.2 CyberCube as processor
When DhanushGuard accesses and assesses a customer-authorised cloud environment, the customer normally determines:
- which cloud accounts are connected;
- which resources are assessed;
- which checks are executed;
- which evidence is retained;
- which users may view findings; and
- how the findings are used.
For this processing, the customer normally acts as controller, data fiduciary or equivalent responsible party, and CyberCube acts as processor or service provider.
4. Information We Process#
4.1 Organisation and account information
We may process:
- organisation name;
- business address;
- business contact information;
- industry;
- company size;
- administrator details;
- authorised-user details;
- usernames;
- user identifiers;
- roles and permissions;
- Contact personal information (example: name, email id, mobile number, social media account etc.)
- authentication records;
- license and subscription information;
- communication preferences; and
- billing and support contacts.
4.2 Cloud-account and integration information
When a customer connects a cloud environment, we may process information such as:
- cloud provider;
- account identifier;
- tenant or organisation identifier;
- subscription or project identifier;
- region;
- resource identifiers;
- integration status;
- assumed-role information;
- service-principal information;
- API endpoint information;
- authorisation scope;
- token metadata;
- credential status;
- connection-test results;
- API-call metadata;
- error information; and
- last successful connection time.
Customers should use temporary, role-based and least-privilege access wherever supported.
4.3 Cloud-resource configuration
DhanushGuard may process configuration and metadata relating to:
- identity and access management;
- users, roles, policies and groups;
- compute resources;
- virtual networks;
- security groups;
- firewall rules;
- storage;
- databases;
- encryption configuration;
- keys and certificates;
- logging and monitoring;
- backup settings;
- vulnerability-related configuration;
- serverless services;
- containers;
- public-access settings;
- resource tags;
- regions;
- service configuration;
- account-level security settings; and
- other supported cloud services.
DhanushGuard is intended primarily to process configuration, metadata and security evidence. Customers should not intentionally expose workload payloads, application secrets or business-record content unless required and authorised for a documented function.
4.4 Security, compliance and audit findings
DhanushGuard may generate or store:
- control identifiers;
- compliance-framework mappings;
- resource identifiers;
- configuration observations;
- pass, fail, warning or not-applicable status;
- evidence;
- severity;
- risk rating;
- remediation guidance;
- assigned owner;
- due date;
- exception status;
- comments;
- acceptance decisions;
- timestamps;
- scan history;
- change history; and
- report content.
Findings may indirectly contain personal data, such as a cloud username, business email address, resource owner, account identifier or activity-log entry, details shared by users to perform the said tasks.
4.5 Query and orchestration information
DhanushGuard may process:
- predefined query identifier;
- approved query text;
- user-selected control;
- mapped cloud operation;
- requested resource scope;
- orchestration status;
- model or rule output;
- structured operation parameters;
- API response metadata;
- validation output;
- normalised result; and
- execution logs.
DhanushGuard is designed around controlled, predefined workflows. It is not intended to provide unrestricted autonomous access to a customer’s cloud environment.
4.6 Authentication and security information
We may process:
- login events;
- authentication factors;
- failed attempts;
- IP addresses;
- session identifiers;
- device and browser information;
- role changes;
- privilege changes;
- integration changes;
- query execution;
- report export;
- evidence modification;
- administrative actions;
- suspicious events; and
- audit trails.
4.7 Support and commercial information
We may process:
- sales enquiries;
- demonstrations;
- proposals;
- licences;
- contracts;
- implementation records;
- support tickets;
- troubleshooting information;
- correspondence;
- customer feedback; and
- meeting notes.
5. Credential and Secret Handling#
DhanushGuard may require customer-authorised credentials, roles, tokens or service identities to access cloud APIs.
Depending on the deployment, DhanushGuard may:
- use an assumed role;
- use temporary credentials;
- use a service principal;
- retrieve a secret from an approved secret-management system;
- use an encrypted credential reference; or
- receive a customer-managed token.
Customers should not provide root-user credentials, unrestricted administrator credentials or long-lived secrets unless expressly required and approved for a documented deployment.
CyberCube will process credential information only as required to operate the authorised integration and according to applicable security controls and contractual commitments.
6. Sources of Information#
Information may be obtained:
- directly from users;
- from customer administrators;
- from customer-authorised cloud APIs;
- from identity providers;
- from integrations;
- from predefined assessment workflows;
- from generated logs;
- from support interactions;
- from implementation partners; and
- automatically through product telemetry and cookies.
7. Purposes of Processing#
We process information to:
- create and manage accounts;
- authenticate users;
- connect authorised cloud environments;
- execute customer-selected checks;
- retrieve and normalise cloud configuration;
- evaluate security and compliance controls;
- generate evidence and findings;
- map findings to frameworks;
- provide remediation guidance;
- produce dashboards and reports;
- track risk acceptance and remediation;
- maintain audit trails;
- protect accounts and integrations;
- troubleshoot API or configuration issues;
- manage licences and subscriptions;
- provide support and implementation;
- comply with legal and contractual requirements;
- prevent unauthorised use;
- improve reliability and usability; and
- establish or defend legal claims.
Customer cloud information will not be used for unrelated advertising.
8. Legal Grounds#
Where required, processing is based on:
- performance of a contract;
- documented customer instructions;
- consent;
- compliance with law;
- legitimate or permitted business use;
- security protection;
- legal claims; or
- another lawful basis recognised by applicable law.
The customer is responsible for establishing the lawful basis for cloud-account information and personal data it instructs DhanushGuard to process.
9. Artificial Intelligence and Governed Automated Processing#
DhanushGuard may use natural-language processing, language models, rule engines or other automated methods to:
- interpret an approved predefined query;
- map the query to an authorised cloud operation;
- structure an API request;
- normalise a cloud-provider response;
- summarise a finding;
- map evidence to a control; or
- generate remediation guidance.
DhanushGuard is not intended to act as an unrestricted autonomous agent. User actions should correspond to approved operations and authorised permissions.
Automated output may be inaccurate, incomplete or outdated. Material findings and remediation actions must be reviewed by qualified personnel.
Customer cloud information will not be used to train general-purpose AI models unless such use is:
- expressly agreed in writing;
- clearly disclosed;
- lawfully permitted; and
- subject to appropriate contractual and technical safeguards.
10. Cloud Provider Information#
When DhanushGuard connects to a cloud provider:
- the cloud provider continues to process information under its own agreement with the customer;
- CyberCube does not control the cloud provider’s independent processing;
- customer API usage may be subject to cloud-provider charges, quotas and rate limits; and
- cloud-provider logs may record DhanushGuard’s access.
The customer is responsible for configuring its cloud account and reviewing cloud-provider terms.
11. Sharing and Disclosure#
We may disclose information to:
- hosting and infrastructure providers;
- approved subprocessors;
- authentication providers;
- monitoring and support providers;
- professional advisers;
- customer-authorised users;
- customer administrators;
- implementation partners;
- government or regulatory authorities where legally required; and
- parties involved in a legitimate corporate transaction.
Information may also be disclosed where reasonably necessary to:
- protect the Services;
- investigate misuse;
- respond to a security incident;
- enforce a contract;
- prevent harm; or
- comply with lawful process.
We do not sell customer cloud-configuration information as a data-broker activity.
12. International Processing#
Information may be processed in countries where CyberCube or its approved providers operate.
Where required, CyberCube will apply appropriate mechanisms, which may include:
- data-processing agreements;
- contractual safeguards;
- access controls;
- transfer assessments;
- encryption;
- regional hosting;
- localisation requirements; and
- transfer restrictions required by law.
The selected hosting region may be stated in the Order Form.
13. Security Measures#
CyberCube maintains reasonable measures designed to protect information processed through DhanushGuard.
Measures may include:
- least-privilege cloud access;
- role assumption;
- temporary credentials;
- encryption in transit;
- encryption at rest where supported;
- secret-management controls;
- role-based user access;
- multi-factor authentication;
- audit logging;
- environment separation;
- secure development;
- vulnerability management;
- monitoring;
- backup and recovery;
- incident response;
- change control; and
- employee confidentiality obligations.
The exact measures may vary by deployment model and contractual plan.
Customers remain responsible for the security of their cloud environments, identity providers, permissions, credentials and remediation actions.
14. Incident Management#
Where CyberCube confirms a personal-data breach affecting customer-controlled information, CyberCube will notify the affected customer according to applicable law and contract.
CyberCube may also preserve and disclose logs where required for incident investigation, legal compliance or protection of the Services.
The customer remains responsible for its own cloud-provider notifications and regulatory determinations unless otherwise agreed.
15. Retention#
Information is retained according to:
- customer configuration;
- the Subscription Term;
- contractual requirements;
- legal obligations;
- security needs;
- audit requirements; and
- backup lifecycles.
Possible retention categories include:
- account records;
- integration records;
- findings;
- evidence;
- reports;
- audit logs;
- security logs;
- support records;
- billing records; and
- backups.
Where available, customer administrators may configure finding or evidence retention.
After deletion from active systems, information may remain temporarily in protected backups until the applicable backup expires or is overwritten.
16. Individual Rights#
Depending on applicable law, individuals may request:
- access;
- correction;
- completion;
- updating;
- deletion;
- withdrawal of consent;
- information about processing;
- grievance redressal;
- nomination;
- restriction or objection where applicable; and
- complaint to a competent authority.
Where the information is controlled by a DhanushGuard customer, the request should normally be submitted to that customer. CyberCube will provide reasonable assistance as required.
17. Children#
DhanushGuard is an enterprise cloud-security product and is not directed to children.
Customers must not create accounts for children or intentionally use DhanushGuard to process children’s personal data without appropriate legal authority and safeguards.
18. Cookies#
DhanushGuard portals may use essential, session, authentication, security, preference and limited analytics cookies.
Optional cookies will be handled according to applicable consent requirements.
19. Customer Responsibilities#
The customer is responsible for:
- having authority over connected cloud accounts;
- selecting appropriate access permissions;
- providing notices to personnel;
- establishing a lawful basis;
- managing user permissions;
- configuring identity-provider controls;
- validating findings;
- approving remediation actions;
- responding to data-subject requests;
- revoking credentials when no longer required; and
- complying with laws governing its cloud environment.
20. Changes to This Policy#
We may revise this Privacy Policy to reflect legal, operational, security or product changes.
The updated policy will state the new effective date. Additional notice will be provided where required.
21. Contact and Grievance Redressal#
CyberCube Services Private Limited
Address:
Third Floor, Plot No - 880, Udyog Vihar Phase V Rd, Sector 19, Gurugram, Haryana 122016
Privacy Email: info@cybercube.co
Grievance Officer: Shailesh Kumar
Grievance Email: Shailesh.kumar@cybercube.co
Response Period: 1-2 business days.