What we hold, where it runs, and what we have not answered yet
This page is for whoever has to fill in the vendor questionnaire. It states what can be verified and marks what cannot, because a gap you can price is easier to work with than a subject a website avoids.
Everything below is answered. Where an answer is a gap — no ISO 27001, no insurance, a draft not yet through a lawyer — it says that, because a gap you can price is easier to work with than a subject a website avoids. Email hello@cyberdefense.co.th and it will be answered by a person.
Almost nothing, and it is short because of that
This page loads no analytics, no tag manager, no advertising pixels and no third-party scripts of any kind. The only outside origins your browser contacts are Google Fonts. There are no accounts and no forms to submit.
The one cookie
cd-locale-dismissed — Remembers that you closed the Thai-language suggestion, so it is not shown again. (Until you clear it)
Two of our services do not run inside your tenant, and that matters
Managed Exposure and Managed Leak Detection are marked “no access needed” because they run on our platform rather than yours. That is the reason a partner can start in a week — and it is also the reason we hold data about your customer on our side. Leak Detection in particular processes personal data: exposed credentials belong to named people. We store the account identifier and the fact of exposure, never the password value. All three facts are true and all three belong here.
Publicly observable attack surface: domains, hostnames, IP addresses, open ports, TLS certificates. No credentials issued, nothing installed.
- No personal data
- —
- Hosted in
- Thailand
- Retained for
- 12 months rolling. Deleted within 30 days of a partner leaving.
Credentials and personal identifiers already published on leak sites and in combolists, plus brand terms and executive names supplied by the partner. This is personal data and is treated as such. We store the account identifier and the fact that it was exposed — never the password value itself, in any form.
- Processes personal data
- ●
- Hosted in
- Thailand
- Retained for
- 90 days from the date the finding is reported, then deleted.
Security telemetry inside the partner’s own tenant, under accounts the partner issues and can revoke without asking us. The telemetry and the case history stay in that tenant, and its retention is set there. Where the tenant runs on the zcr platform, that platform is ours — so this is your data in your tenant on our infrastructure, and we keep no separate copy outside it. The one thing we do hold separately is the case correspondence: the email between our analysts and the partner about a case.
- Processes personal data
- ●
- Hosted in
- The partner’s own tenant
- Retained for
- Set by the partner’s own platform
Because the free scan and the 60-day pilot are both Managed Exposure, this processing can begin before a contract exists. Ask us for the data-processing agreement first if that ordering does not work for you.
How long any of it stays
Ninety days from delivery, then deleted. That covers the penetration test report and its evidence, the working copy of a reviewed repository, samples supplied for detection engineering, the onboarding handover pack, learner data we hold for awareness training, and a reported leak-detection finding.
Three that are not ninety days
The three a reviewer asks first
Standards, key management and the precise scope of each are answered in your own security questionnaire rather than published here, because a reviewer needs them in their format and against their control set. Send yours and a person completes it.
Subprocessors
zcr.ai is a brand of Cyber Defense Co., Ltd. rather than a separate company, so it is not a subprocessor in the legal sense — there is one counterparty on a contract, not two. It is listed because a reviewer will look for it, and an explanation is more useful than a gap.
Platform infrastructure Split: our own hardware in a Thai data centre (Benchachinda), plus AWS in the Thailand region. Both are in Thailand, which is why the hosting line above says what it says.
Response and notification
The second one is the obligation you have to flow down into your own customer contract. If it is not stated below, it is not stated yet.
What is held, and what is not
Thai standard for computer traffic data retention systems under the Computer Crime Act. A product certification of the log retention system — not a management-system certification of the company.
Neither is held today and no date is announced. For an MSSP whose own certification scope carries a subservice-organization control, this is a real blocker and will not get smaller by being left unsaid.
Who you would be signing with
Documents available on request
Email hello@cyberdefense.co.th and say which of these you need. Where the answer below is a limit rather than a document — the agreement is drafted but not yet through a lawyer — it says so before you ask, not after you have read it.
- Data processing agreement (DPA) A draft exists and we send it on request. It has not been through a lawyer yet — we would rather say so than have your counsel be the one to notice. It carries standard contractual clauses for partners exporting from the EEA, the UK or Switzerland.
- Partner agreement template Yes, under NDA — before any call, not after one.
- Liability cap Twelve months of fees paid under the agreement.
- Insurance cover None held today. No professional indemnity and no cyber liability cover, so the cap above is the practical limit of recovery.
- Governing law Thai law, courts of Bangkok. Negotiable on larger engagements — ask.