Privacy Policy, Training Use, and Compliance Statement

Cyber Nomad Inc. (“Cyber Nomad,” “we,” “us,” or “our”) is a hybrid organization delivering nonprofit programs and for-profit cybersecurity training and services. We are committed to protecting your information while maintaining high standards of legal compliance, ethical cybersecurity practice, and workforce development integrity.


1. Information We Collect

We may collect:

  • Personal Information (e.g., name, email, contact details, payment or donation data)
  • Student & Program Data (e.g., enrollment, progress, certifications, participation)
  • Technical Data (e.g., IP address, device type, usage analytics, activity within training systems)


2. How We Use Information

We use information to:

  • Deliver cybersecurity training, education, and contracted services
  • Process payments, donations, and grants in compliance with IRS and funding requirements
  • Track program outcomes for workforce, audit, and grant reporting
  • Maintain secure, monitored training environments
  • Improve services, platform performance, and user experience
  • Comply with federal, state (Alaska), and contractual obligations


3. Student Data & FERPA-Aligned Practices

Cyber Nomad applies FERPA-informed principles to protect participant data:

  • Limit collection to what is necessary
  • Restrict access to authorized personnel and approved partners
  • Maintain confidentiality of student records and performance data
  • Use de-identified or aggregated data for reporting whenever possible


4. Cybersecurity Training & Acceptable UseAuthorized Use

Participants may only access assigned systems and perform activities within defined training environments.

Prohibited Use

Participants may not:

  • Access unauthorized systems or external networks
  • Use training tools or skills for illegal or unethical purposes
  • Attempt to evade monitoring, controls, or safeguards
Monitoring

All training environments may be logged, monitored, and audited to ensure safety, compliance, and instructional integrity.


5. Assumption of Risk & Liability (Alaska-Aligned)

By participating in Cyber Nomad programs, you acknowledge:

  • Cybersecurity training may involve simulated attacks, defensive operations, and controlled system interaction
  • There are inherent risks in technical environments, including system errors or unintended disruptions within authorized labs

To the fullest extent permitted by Alaska and federal law:

  • You assume all risks associated with participation
  • You release and hold harmless Cyber Nomad Inc. and its affiliates from claims arising from participation, except in cases of gross negligence or willful misconduct
  • Cyber Nomad is not liable for indirect, incidental, or consequential damages, including misuse of skills learned outside program scope

You accept full responsibility for how you apply cybersecurity knowledge beyond authorized training environments.


6. Ethical Use & Legal Compliance

Participants agree to:

  • Comply with all applicable U.S. laws, including the Computer Fraud and Abuse Act (CFAA)
  • Follow responsible disclosure practices
  • Maintain confidentiality of systems, labs, and participant data
  • Uphold professional cybersecurity and workforce ethics


7. DoD / NIST-Aligned Security Practices

Cyber Nomad training and operations are informed by:

  • NIST cybersecurity principles (risk management, least privilege, audit logging)
  • DoD-aligned ethical training standards

We implement safeguards including:

  • Role-based access control
  • Activity monitoring and audit logging
  • Risk-based security practices


8. Data Sharing

We do not sell personal data. We may share information with:

  • Trusted service providers (e.g., platforms, payment processors)
  • Grantors, auditors, and workforce partners
  • Government entities or authorities when legally required


9. Grant & Regulatory Compliance (CFR / OMB)

Cyber Nomad aligns with:

  • 2 CFR Part 200 (Uniform Guidance)
  • Federal and Alaska audit, reporting, and compliance requirements

We ensure:

  • Data minimization for program delivery and reporting
  • Secure record retention aligned with grant and IRS rules
  • Internal controls to prevent fraud, waste, and abuse
  • Responsible management of subrecipients and vendors

Data may be disclosed in aggregated or de-identified form for reporting and public impact.


10. Data Security

We apply administrative, technical, and organizational safeguards consistent with industry cybersecurity best practices.
No system can guarantee absolute security.


11. Your Rights

You may:

  • Opt out of communications
  • Request access, correction, or deletion of your data
  • Ask how your data is used in programs, services, or reporting


12. External Links

We are not responsible for third-party privacy practices.


13. Updates

This policy may be updated to reflect legal, regulatory, or operational changes. Updates will be posted with an effective date.


14. Contact

anna.london@cyber-nomad.com

Get In Touch About Our Terms

Reach out with any questions about our policies or services.
Email: anna.london@cyber-nomad.com
Phone: 907-203-5733
Address: 7400 N. McCarrey Street, Palmer, Alaska 99645

Frequently Asked Questions about Our Terms and Policies

Get clarity on cybersecurity services in Alaska
What is the process for starting a cybersecurity risk assessment?

To initiate a risk assessment, simply click on the 'Start Your 2-Minute Risk Check' button on our website. You'll receive a series of questions that help us evaluate your current cybersecurity posture and identify potential vulnerabilities.

How much do your cybersecurity services cost?

Pricing for our services varies based on the complexity and scope of the assessment. After your initial risk check, we'll provide a detailed quote tailored to your specific needs.

Do you guarantee complete security against cyber threats?

While we don’t guarantee absolute protection against all cyber incidents, our aim is to significantly reduce your risk through thorough assessments and strategic planning.

What kind of ongoing support do you offer after the assessment?

After completing your assessment, we offer continued support through incident response planning and ongoing cybersecurity training to ensure your operations stay protected over time.

Are your services compliant with Alaskan regulations?

Yes, our services align with local regulatory requirements. We will help you navigate any specific compliance needs specific to your organization or industry.

How does your team handle sensitive information?

We prioritize client confidentiality and employ strict protocols to handle and protect all sensitive data, ensuring it remains secure throughout the engagement.

What if I need help with a cyber incident now?

If you're facing a cyber incident, contact us directly so we can mobilize our incident response team to assist you promptly.

Can you help families with cybersecurity issues, too?

Absolutely. Our non-profit arm, Cyber Nomad Inc., is dedicated to providing resources and support for families facing issues like cyberbullying and online safety.