Security is an important part of the design, deployment, and operation of Cybergate products and services.
This page provides an overview of the security practices, access controls, development processes, infrastructure protections, and operational responsibilities associated with Cybergate solutions.
Important
Security controls and available features may vary depending on the product, customer environment, deployment model, and subscribed services.
Security is a shared responsibility between Cybergate and its customers.
The exact division of responsibilities depends on whether the service is operated by Cybergate, deployed within customer infrastructure, or provided through a hybrid deployment.
Depending on the service and deployment model, Cybergate responsibilities can include:
Customers are normally responsible for areas including:
Security Recommendation
Administrator accounts should only be provided to personnel who require administrative privileges to perform their duties.
Cybergate continuously reviews security controls associated with its products, infrastructure, and operational processes.
Security validation may include activities such as:
Use the following table to document verified Cybergate assessments.
| Security Area | Status | Details |
|---|---|---|
| Vulnerability Assessment | [Update] | [Assessment frequency / provider] |
| Penetration Testing | [Update] | [Last assessment / scope] |
| Source Code Security Review | [Update] | [Process / tools] |
| Dependency Security Scanning | [Update] | [Process / tools] |
| Infrastructure Security Review | [Update] | [Process / frequency] |
| ISO/IEC 27001 | [Update] | [Certified / In Progress / Not Claimed] |
| SOC 2 | [Update] | [Certified / In Progress / Not Claimed] |
Important
Only publish certifications, audit results, penetration-test results, or compliance claims that have been formally verified and approved by Cybergate management or the responsible security team.
Detailed security assessment reports may contain sensitive information and therefore may only be provided to authorized customers or partners under appropriate confidentiality arrangements.
Cybergate products should follow secure software development practices throughout the development lifecycle.
The secure development lifecycle can include:
Changes to production applications should undergo appropriate technical review before release.
Review activities can include:
Third-party libraries and application dependencies should be monitored for known security vulnerabilities.
Where applicable, vulnerable packages should be:
Security testing may include:
Security testing should consider common application security risks, including relevant OWASP guidance.
Cybergate platforms should provide appropriate mechanisms for protecting user and administrator access.
Exact authentication functionality may differ between products.
Authentication controls may include:
Users should create strong passwords and avoid reusing passwords across unrelated services.
Recommended organizational password policies should consider:
Passwords must never be shared between users.
Security Recommendation
Use unique administrator accounts instead of shared administrator credentials wherever possible.
Multi-factor authentication provides additional protection by requiring another authentication factor in addition to a password.
Where MFA is supported, it should be enabled especially for:
Refer to the relevant product authentication documentation for supported MFA methods.
Administrative privileges should follow the principle of least privilege.
Users should only receive permissions required for their responsibilities.
Typical roles may include:
| Role | Typical Access |
|---|---|
| User | Standard end-user functions |
| Supervisor | Team or contact-center management |
| Administrator | Customer-level administration |
| Support Administrator | Technical support functions |
| Platform Administrator | Platform-level administration |
Actual roles vary depending on the Cybergate product.
Administrator permissions should be reviewed periodically.
Organizations should maintain an appropriate account lifecycle.
New accounts should only be created after appropriate authorization.
When an employee changes responsibilities:
When a user leaves the organization:
Account removal should form part of the organization's employee offboarding process.
Cybergate products may process customer communication, account, configuration, and operational information depending on the service being used.
Appropriate controls should protect sensitive information throughout its lifecycle.
Security controls can include:
Communication between users, browsers, APIs, applications, and platform services should use encrypted protocols wherever supported.
Typical technologies can include:
Unencrypted administrative protocols should be avoided whenever secure alternatives are available.
API integrations should be treated as privileged access.
Organizations using Cybergate APIs should:
Warning
Never include real passwords, API keys, authentication tokens, private keys, or customer credentials in screenshots or public documentation.
Infrastructure security depends on the deployment model.
For Cybergate-managed infrastructure, appropriate controls can include:
For customer-hosted deployments, infrastructure security controls must be coordinated with the customer's infrastructure and security teams.
Security vulnerabilities should be handled through a defined lifecycle.
A typical process includes:
Discovery
↓
Validation
↓
Risk Assessment
↓
Prioritization
↓
Remediation
↓
Testing
↓
Deployment
↓
Verification
Vulnerabilities may be identified through:
Critical security issues should receive priority according to organizational vulnerability-management procedures.
Customers should maintain supported versions of Cybergate products and associated infrastructure components.
Security updates may include:
Customers operating self-managed environments should ensure that underlying infrastructure remains appropriately patched and supported.
Security monitoring can help identify abnormal activity and support incident investigation.
Depending on the product and deployment, relevant logs may include:
Access to security logs should be restricted to authorized personnel.
Logs should be retained according to organizational, contractual, and regulatory requirements.
Appropriate backup procedures should be maintained for critical systems and data.
Backup controls should consider:
Organizations should periodically test restoration procedures rather than relying solely on successful backup-job status.
Potential security vulnerabilities or suspected security incidents related to Cybergate products should be reported through approved Cybergate support or security channels.
When reporting a potential security issue, provide:
Important
Never send production passwords, private keys, authentication tokens, or other sensitive credentials through standard support requests.
Additional security-related documentation can be found in:
For product-security inquiries, vulnerability reporting, security questionnaires, assessment information, or other security-related requests, contact:
Cybergate Services (Pvt) Ltd.
Security / Support Contact: [Insert approved email address]
Support Portal: [Insert approved support portal if applicable]
For urgent production incidents, follow the established Cybergate support escalation procedure.
This documentation provides general security guidance. Specific controls and capabilities can vary between products, deployment models, versions, and customer configurations.