Legal

Privacy Policy

Defense Cybersecurity Group, Inc. ("DCG," "we," "us") operates this website at cybersecgru.com. This policy explains what we collect from visitors, why, who we share it with, and the rights you have over it. It covers this website only — it does not cover the Midwatch enclave or any service we run under a signed client agreement, which are governed by that agreement.

Please do not send Controlled Unclassified Information (CUI), export-controlled technical data, or other sensitive material through this website or by unencrypted email. If you need to share something sensitive while evaluating our services, contact us first and we will arrange an appropriate channel.

Your tracking choices

There are exactly two choices to make, and you can change either of them at any time, from any page on this site, using the Privacy choices control in the footer. It is also here:

Analytics covers understanding how the site is used — which pages are read, how far people scroll, and which campaign or referral brought a visit. Today that means the first-party campaign record described under “What we store in your browser” below.

Advertising covers measuring and targeting advertising, and identifying visiting organisations. Apollo is currently disabled. If we begin running paid search advertising it would also cover Google Ads measurement, and we will update this page in the same change that switches it on.

Both are on by default. This is our current US opt-out setting; it does not mean you have clicked an acceptance button. We do not put an interstitial banner in front of the site. Turning either choice off takes one click and takes effect immediately — the same single click it takes to turn it back on. We do not make opting out harder than opting in.

If your browser blocks access to site storage or refuses to save changes, we still honour any valid saved choice we can read. If none can be read, both choices start off. You can change them for the current page using Privacy choices, but a change that cannot be saved will not carry over to another page; an earlier saved choice may apply there again. The control tells you when changes cannot be remembered.

We honour Global Privacy Control. If your browser or an extension sends a Global Privacy Control signal, both choices are switched off and locked for as long as that signal is present, whatever you may have chosen here before. The footer control tells you when that is happening.

When you turn a choice off, four things happen at once: the corresponding Google consent signals are set to denied; our own browser record for that choice is deleted; the cookies and browser storage that choice's tools had set on this site are cleared, including the anonymous identifier they use to recognise a returning browser; and nothing further is loaded for it.

Two honest limits. A third-party script that has already started running on the page you are looking at cannot be recalled by us — no website can do that — so it stops at your next page load; reload the page if you want it gone immediately. And we can only clear what a tool stored under this site's name; anything it holds on its own systems is covered by its own privacy policy, linked below.

These choices are stored in your own browser, not in an account, so they are per-browser and per-device. Clearing your browser storage clears them, and the defaults above apply again.

Where measurement runs at all

Measurement is switched on for exactly three hostnames: cybersecgru.com, staging.cybersecgru.com, and midwatch.security. On any other hostname — including www. variants, preview builds, and local copies — the measurement script loads no analytics or advertising tool, records no campaign information, and stores nothing in your browser. Adding a hostname to that list is a reviewed change to this site's source code, not a setting someone can flip.

What we store in your browser

This site sets no cookie of its own. It uses first-party browser storage, and it stores exactly four things:

WhatWhyKept for
Your two tracking choices, and the date you made them So we can honour them, and so we can tell a deliberate choice from a default 12 months
Campaign record: the page you first landed on, the hostname of the site that referred you, and the five standard utm_ campaign values — requires Analytics So we can tell which article, search, or referral led to an enquiry 90 days
Google advertising click identifiers (gclid, gbraid, wbraid) — requires Advertising So a lead can be matched back to the advertisement that produced it 90 days
A random enquiry reference, created only when you actually send us something So a message sent twice does not become two records 24 hours

We keep the first landing page and the most recent campaign; a later direct visit does not overwrite the first one we saw. We do not store the rest of the address you arrived on: the full query string is discarded, and only the five utm_ values and the three Google click identifiers are read out of it. From a referring site we keep only the hostname — www.linkedin.com, not the page you were reading there.

Our reports separate three things: the first campaign or referral that ever brought you here, the most recent one, and the one that applies to the page you are reading right now. Only the first two are stored for 90 days. The third is held in the page's memory for as long as that page is open and is never written to your browser's storage — and if you arrive directly, with no campaign and no external referral, there is no current campaign value at all. A stored earlier campaign is never presented as the current one.

What we never put into analytics

Our measurement code can only send a fixed list of events, each with a fixed list of parameters, and each parameter is checked against a strict pattern before it is sent. Names, email addresses, telephone numbers, company names, message text, CUI markings, and full web addresses with query strings are rejected by that check rather than filtered afterwards. Nothing you type into this site is sent to an analytics or advertising provider.

Consent

By using this website you consent to this policy. If you do not agree with it, please do not use the site. Your tracking choices are separate and are described above.

Information we collect

Information you give us. The contact form on this site sends what you typed to our own request handler at /api/consult, over HTTPS, and that handler emails it to us. If that handler cannot be reached, or replies that it cannot accept the message — an error response, a refusal, or a reply we cannot read — the form falls back to opening a pre-addressed message in your own email application so your enquiry is not lost. Either way we receive an ordinary email containing what you chose to write — typically your name, email address, company, role, and a description of what you need help with. We also receive whatever you tell us by emailing or calling us directly, or when you request access to our CMMC self-assessment tool.

Information collected automatically. Standard technical information about each request: IP address, browser type and version, operating system, referring page, which pages you viewed, and the date and time.

How we use your information

  • To respond to your enquiry, and to deliver the work if it becomes an engagement
  • To operate, maintain and diagnose faults on the website
  • To understand which content is useful, so we can improve it
  • To identify organisations researching CMMC compliance, so our team can follow up

We do not sell personal information. We do not currently run paid advertising, and this site loads no ad network or ad server. Google Analytics 4 and Google Tag Manager are configured on this site as of 2026-09-22 and are covered by the consent controls described above; Google Ads conversion tracking remains not configured and no ad destination is contacted.

Log files

This site follows the standard practice of using log files. These record visits, and the technical details listed above. The information is not linked to anything personally identifiable; it is used to analyse trends, administer the site, and gather demographic information in aggregate.

Analytics and site improvement

Covered by the Analytics choice above. If Analytics is off, Hotjar is never requested. Hotjar's site identifier is registered for cybersecgru.com only, so it is not loaded on staging.cybersecgru.com or midwatch.security at all.

Hotjar runs only on cybersecgru.com, and only when Analytics is permitted. Hotjar reads the address of the page and of the page you came from directly from your browser, so before loading it the site checks both addresses, and Hotjar is not loaded on that page if the page address contains login details, any query string (the single exception is Hotjar's own fixed installation check, ?hjVerifyInstall=6757165, which carries nothing about you), or a fragment after # that is not the id of an element we wrote into that page (such as #process); or if the page you came from was a page on another site (a bare site address such as https://www.google.com/ is fine), or its address carried a query string, fragment or login details. This check happens when each page loads. It helps us understand how visitors use this site — which sections get read, how far down a page people scroll, and where they lose interest. Hotjar does this with aggregated heatmaps and, in some cases, anonymised recordings of on-page activity such as mouse movement, scrolling and clicks. Recordings are configured to suppress the contents of form fields, and we do not use Hotjar to identify individual visitors. You can opt out of Hotjar across every site that uses it at hotjar.com/policies/do-not-track.

Business identification

Covered by the Advertising choice above, not by Analytics. It is not measurement of how the site is used; it discloses your IP address to a data vendor so that our sales team can follow up, which is the activity the United States opt-out laws are about. If Advertising is off, Apollo is never requested.

Apollo is currently disabled on every hostname pending review of the URLs it can collect. When enabled, it can match visitor IP addresses against a database of publicly registered corporate networks. Where there is a match, this tells us that an organisation visited the site — for example, that a defense contractor in Ohio read an article about CUI scoping. It resolves only a portion of traffic. We use it so our team can follow up with organisations researching CMMC compliance.

Apollo's service is also capable of identifying individual visitors within the United States. We have not enabled person-level identification, and we will update this page before we do.

Cookies and similar technologies

The four first-party items this site stores itself are listed under “What we store in your browser” above. In addition, any third-party tool that is running under a choice you have left on may set its own cookie or browser storage to recognise a returning browser and avoid double-counting the same visit. We do not use cookies to build advertising profiles.

You can block or delete cookies and site storage in your browser settings, and most browsers let you refuse them entirely. The site is built to work normally without them, and so is the Privacy choices control: if storage is blocked, your choice applies to the page you are on and cannot be remembered, and the control tells you so.

Blocking this site’s measurement script outright — with an ad blocker, a strict privacy mode, or by disabling JavaScript — also works, and the site remains fully usable. Nothing on this site’s navigation, content, or contact details depends on it.

Fonts

This site loads its typefaces from Google Fonts. Because those files are served from Google's servers rather than ours, your browser makes a request to Google on each page load, and Google receives your IP address as part of that request. Google states that it does not use these requests to build advertising profiles. If you would rather this did not happen, blocking fonts.googleapis.com and fonts.gstatic.com in your browser will stop it — the site remains fully readable, in a fallback typeface.

Third-party privacy policies

This policy does not cover the practices of the third parties named above. Theirs are here:

We share information with these providers only to the extent they need it to provide their service, and with our hosting provider. We do not share your enquiry with anyone outside DCG. We may disclose information where legally required, or where necessary to protect our rights, our clients, or the security of our systems.

How long we keep it

Enquiries and correspondence are retained for as long as we have an active or prospective relationship with you, and afterwards where we need to for legal, contractual, or record-keeping reasons. Analytics data held by a vendor is retained according to that vendor's standard retention period. What we store in your own browser is limited to the four items and the periods in the table above, and each expires on its own.

Security

We apply the same practices to our own systems that we build for clients. That said, no method of transmitting information over the internet is completely secure, and email in particular is not. See the note at the top of this page about sensitive material.

Your CCPA privacy rights

If you are a California resident, you have the right to request:

  • What categories of personal information we hold about you, and the specific pieces
  • What categories of personal information we have disclosed, and to whom
  • That we delete personal information we hold about you
  • That we not sell your personal information — though note we do not sell personal information to anyone

We will not discriminate against you for exercising any of these rights. Make a request using the contact details below and we will respond within one month.

You do not need to write to us to opt out of targeted advertising or the sharing of your information for it: use the Privacy choices control in the footer of any page, or send a Global Privacy Control signal from your browser, and we will honour both. Deletion, access, and correction requests for anything we hold outside your own browser go to the contact details below.

Your GDPR data protection rights

If you are in the United Kingdom or the European Economic Area, you have the right to:

  • Access — ask for copies of the personal data we hold about you
  • Rectification — ask us to correct anything inaccurate, or complete anything incomplete
  • Erasure — ask us to delete your personal data
  • Restrict processing — ask us to limit how we use it
  • Object to processing — object to our use of it
  • Data portability — ask us to transfer it to you or to another organisation

Make a request using the contact details below and we will respond within one month. There is no charge.

Children's information

This site is aimed at businesses in the Defense Industrial Base. It is not directed at children, we do not knowingly collect information from anyone under 13, and we have never knowingly done so. If you believe your child has provided information through this site, contact us and we will delete it promptly.

Changes to this policy

If we add or remove a tool that collects visitor information, we will update this page and change the date at the top. Material changes will be noted here rather than made silently.

Contact us

Questions about this policy, or a request under any of the rights above:

Defense Cybersecurity Group, Inc.
7901 4th St. N., STE 300
St. Petersburg, FL 33702
[email protected]
(727) 316-5720