Privacy Policy
Last updated: August 2026
StrikeCyber Pty Ltd (ACN 677 052 041) ("StrikeCyber", "we", "us", "our") is an Australian offensive cyber security firm. Protecting information is our profession, and it is central to how we run our own business. This Privacy Policy explains how we collect, use, secure, disclose and retain personal information, and the rights you have in relation to it.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy applies to our website at strikecyber.au, our client portal and platform, and the delivery of our services. It does not override any separate written agreement, statement of work or rules of engagement, which govern how we handle data within a specific engagement.
What personal information we collect
We collect only the information we need. Depending on how you interact with us, this may include:
- Contact and business details — your name, organisation, role, email address and phone number, provided when you submit a form, request a consultation or contact us.
- Enquiry details — the information you choose to include in a message, such as the systems, environments, timeframes and compliance drivers relevant to your enquiry.
- Engagement information — details provided when you scope or receive a service, including the assets, environments, objectives and rules of engagement in scope.
- Client portal account information — where you are granted access to our portal, including your credentials and activity and access logs.
- Technical information — collected automatically when you visit our website, such as your IP address, device and browser type, referring page and pages viewed, used for analytics, performance and security.
We do not seek to collect sensitive information (as defined in the Privacy Act) through our website. Where an engagement requires us to handle sensitive, regulated or confidential data, that handling is governed by a separate written agreement.
How we use your information
We use personal information to:
- Respond to enquiries and provide consultations, quotes and proposals.
- Scope, deliver, manage and report on the services you engage us to perform.
- Operate, maintain and secure our website, client portal and platform.
- Communicate with you about your enquiry or engagement, and send updates you have asked to receive. You can opt out of optional communications at any time.
- Meet our legal, regulatory, contractual and record-keeping obligations.
- Detect, investigate and prevent fraud, misuse and security threats.
We will only use your information for a purpose you would reasonably expect, a purpose you have consented to, or a purpose otherwise permitted under the APPs.
AI-assisted processing
We deliver our services using an AI-augmented offensive security platform. AI-assisted tooling supports reconnaissance, analysis, correlation and the drafting of reports, and every finding is reviewed and validated by a StrikeCyber operator before it reaches you.
Where AI systems process information as part of an engagement, they operate within controlled environments that we own or control. We do not feed client data into public or third-party AI models in ways that would expose it, and your information is not used to train models outside your engagement. We do not use AI to make decisions that produce legal or similarly significant effects about you without human review.
How we protect and isolate your data
We apply technical and organisational security measures appropriate to the sensitivity of the information we hold, including access controls, encryption in transit, logging and the principle of least privilege. Engagement data and findings are isolated to your organisation and handled in access-limited environments on infrastructure we control. Your data is not pooled with other clients' data, and it is not sold.
Disclosure and sub-processors
We do not sell your personal information. We disclose it only where necessary to operate our business and deliver our services, and always subject to confidentiality obligations. This includes trusted service providers who help us run our website and communications, for example:
- Hosting and content delivery — our website and platform are hosted on Vercel's infrastructure.
- Analytics — we use Google Analytics (via Google Tag Manager) to understand website usage.
- Email delivery — enquiry notifications and confirmations are sent using a transactional email provider.
We may also disclose personal information where required or authorised by law, to protect our rights or safety or those of others, or as part of a business restructure. We require our providers to protect personal information consistently with this policy and the APPs.
Overseas disclosure
Some of our service providers may store or process data outside Australia. Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the APPs, or we rely on an exception permitted under the Privacy Act.
Cookies and analytics
Our website uses cookies and similar technologies to operate the site, remember your preferences, measure usage and improve performance and security. You can control or block cookies through your browser settings; some parts of the site may not function as intended if you do. Where analytics or advertising cookies are used, they help us understand aggregate usage and are not used to identify you personally without your consent.
Retention
We keep personal information only for as long as necessary to fulfil the purposes described in this policy, or to meet our legal, contractual and record-keeping obligations. When it is no longer required, we securely delete or de-identify it.
Notifiable data breaches
We maintain processes to detect, assess and respond to data breaches. If a breach involving your personal information is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act.
Access, correction and complaints
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date or incomplete. Contact us using the details below and we will respond within a reasonable period. There is generally no charge for a request, though a reasonable cost may apply for more complex requests.
If you have a concern about how we have handled your personal information, please contact us first so we can try to resolve it. If you are not satisfied with our response, you may lodge a complaint with the OAIC at oaic.gov.au.
Third-party links
Our website may link to third-party sites. We are not responsible for the privacy practices or content of those sites, and we encourage you to review their privacy policies.
Children
Our website and services are directed at organisations and professionals, not children, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time to reflect changes in our practices or the law. The current version is always available on this page, and the "last updated" date above shows when it last changed.
Contact
To exercise your rights, ask a question or raise a privacy concern, contact us at info@strikecyber.au or 1300 654 898.
