Privacy Policy

Last updated: August 21, 2026

IYA Cyber Security (“IYA Sec”, “we”, “us”) is a boutique cybersecurity consulting firm. This policy explains what information iyasec.io collects when you visit, how that information is used, and what choices you have. It also describes how we handle information you send us when you contact us about an engagement.

We work in security for a living, so we try to hold this site to the standard we would ask of a client: collect as little as possible, be specific about what is collected, and avoid third-party code that we do not need.

The Short Version

  • iyasec.io is a static website. There are no accounts, logins, forms, comment sections, or shopping carts.
  • Google Analytics is the only third-party service that runs in your browser on this site.
  • We serve no advertising, and we do not sell, rent, or trade personal information.
  • Fonts and images are served from our own domain, so simply reading a page does not report your visit to a third-party CDN.

Information You Give Us

The only way to contact us through this site is to email info@iyasec.io. When you write to us we receive your email address, any name or company you choose to include, and the contents of your message. We use that information to respond to you and, if we go on to work together, to carry out the engagement. We do not add correspondents to a marketing list.

Information Collected Automatically

Our hosting and content delivery provider records standard server log data for requests to the site. That typically includes the requesting IP address, the date and time, the page or file requested, the referring page, and the browser user agent string. This data is used to keep the site available, to investigate errors and abuse, and to produce aggregate traffic counts.

Analytics and Cookies

We use Google Analytics (measurement ID G-8TMHT031BS) to understand which articles and pages people find useful. Google Analytics sets cookies in your browser and collects information such as the pages you view, how long you spend on them, an approximate geographic region derived from your IP address, your device and browser type, and the site that referred you. We look at this information in aggregate. We do not use it to identify individual visitors, and we do not combine it with any information you send us by email.

This data is processed by Google on our behalf and is subject to Google’s own privacy terms. You can prevent it from being collected in any of the following ways, none of which affect how the site works:

  • Block or delete cookies for this site in your browser settings.
  • Install Google’s Analytics opt-out browser add-on.
  • Enable your browser’s tracking protection, or use an extension that blocks analytics scripts.

This site sets one cookie of its own, cookie_policy_accepted. It records that you have dismissed the cookie notice at the bottom of the page, so that the notice is not shown to you again for a year. It holds nothing else — no identifier, and nothing that says who you are — and it is never sent anywhere but back to this site.

Those are the only cookies this site sets: Google Analytics’ and that one. We do not use advertising cookies, cross-site tracking pixels, social media trackers, session replay, or fingerprinting scripts.

How We Use Information

  • To respond to inquiries and to deliver consulting services that you engage us for.
  • To operate, secure, troubleshoot, and maintain this website.
  • To understand in aggregate which content is worth writing more of.
  • To meet legal, regulatory, and contractual obligations.

We do not sell, rent, or share personal information with third parties for their own marketing, and we do not use website data for automated decision-making or profiling.

Client and Engagement Confidentiality

Our consulting work regularly involves sensitive material: system architecture, threat models, audit findings, incident timelines, and unremediated vulnerabilities. We treat everything a client shares with us as confidential and handle it under the terms of the applicable engagement agreement or non-disclosure agreement, which take precedence over this policy where they differ.

We do not name clients as references, publish engagement material, or discuss findings attributable to a client without written permission. Deliverables and findings produced during an engagement belong to the client. General lessons learned may inform what we write publicly, but our articles do not identify clients and do not describe a specific unremediated vulnerability in an identifiable system.

Sending Us Sensitive Information

This site is served over HTTPS, and we apply reasonable technical and organizational measures to protect information in our possession. No method of transmission or storage is completely secure, and ordinary email is not a confidential channel.

Please do not send credentials, private keys, security reports, incident details, or other sensitive material in an unencrypted email. Contact us first and we will arrange an appropriately protected channel.

Links to Other Sites

Articles on this site link to external resources, and most of them are also published on Medium. Reading an article here does not notify Medium or any other third party, but once you follow a link you are subject to that site’s own privacy practices, which we do not control.

Data Retention

Email correspondence is retained for as long as needed for the business or legal purpose it relates to. Server logs are retained for a limited period as configured by our hosting provider. Analytics data is retained according to the retention period configured in Google Analytics.

Your Rights

Depending on where you live, you may have the right to request access to the personal information we hold about you, to have it corrected or deleted, to restrict or object to certain processing, or to receive a copy in portable form. Residents of the European Economic Area and the United Kingdom have these rights under the GDPR; residents of California have comparable rights under the CCPA/CPRA, including the right to opt out of the sale or sharing of personal information, which we do not do.

To make a request, email info@iyasec.io. We may need to verify your identity before acting, and we will respond within the time frame required by applicable law. Requests concerning information we process on behalf of a client are referred to that client, who is the controller of that data.

Children’s Privacy

This site is intended for a professional audience. It is not directed to children, and we do not knowingly collect personal information from anyone under 16.

Changes to This Policy

We may update this policy as the site or our practices change. The date at the top reflects the most recent revision, and material changes will be described here.

Contact

Questions about this policy can be sent to info@iyasec.io.