We don't sell, rent, or share client data.
Briefing intake, newsletter sign-ups, and service operational data are used only to deliver the work you hired us for. Our revenue is service fees and channel partnerships — not data.
Trust & transparency
Security work only means something if the security company is honest about itself. This page reflects what is true and active today. If something isn't in place yet, it isn't listed here — and if you ever find a gap between what we say and what we do, tell us and we'll fix it.
Who we are
Principal: Kfir Yair, CISSP. We provide direct communication and accountable delivery.
Contact: security@obsidianridge.io · 964 High House Rd, PMB 2086, Cary, NC 27513 · (984) 999-7785
How we deliver security
Partner posture
Obsidian Ridge is a Huntress MDR Partner. That means we operate the Huntress Managed EDR, Managed ITDR, Managed Security Awareness Training, and Managed SIEM platforms end-to-end for covered organizations:
Huntress operates the 24/7 SOC behind the detection platforms; we add the practitioner program that turns the platform into an outcome.

Partner posture
Obsidian Ridge is a Fortinet Engage Advocate Partner.

Sub-processors
Published in full because clients with privacy obligations (HIPAA, GDPR, CCPA) need to list every party that handles their data. Anything not on this list does not see your data. Changes here trigger a 30-day notice to clients before activation.
| Sub-processor | Purpose | Data handled |
|---|---|---|
| Vercel | Website hosting | Site content, form submissions in transit |
| Supabase | Application database | Contact, assessment, and calculator submissions |
| Resend | Email delivery | Email address, message content |
| Cloudflare | Bot protection (Turnstile) | Connection metadata |
| Namecheap | Domain registration and DNS | Domain records only, no customer data |
| Plausible | Cookieless site analytics | Aggregate page-view and event counts |
| Proton | Business email | Correspondence with us |
We review this list on a regular basis.
Cross-border note: where a US-hosted sub-processor handles personal data of an EU or UK data subject, the EU / UK Standard Contractual Clauses are incorporated by reference via the relevant DPA.
Where a sub-processor is added or replaced, existing clients receive written notice at least 30 days before activation.
Plausible, our active analytics processor, is EU-based and EU-hosted, keeping visitor analytics within EU jurisdiction and outside the US CLOUD Act's reach.
Payments & contracting
Engagements are governed by a written agreement and, where applicable, a Business Associate Agreement or Data Processing Addendum.
Data residency
Application data (briefing requests, assessment responses, newsletter subscribers) is stored in the United States at Supabase (US East). Email delivery uses US-region Resend.
Where a US-hosted sub-processor handles personal data of an EU or UK data subject, the EU / UK Standard Contractual Clauses are incorporated by reference through the relevant DPA. No client data is transferred to a jurisdiction without an approved transfer mechanism in place.
Vulnerability disclosure
We publish an RFC 9116 security.txt at /.well-known/security.txt, and its Policy field points here. Send coordinated vulnerability reports to Obsidian Ridge LLC at security@obsidianridge.io — encrypted over PGP on request. Please give us a reasonable chance to fix an issue before disclosing it publicly.
In scope: this website — obsidianridge.io and its subdomains — and its forms and API endpoints.
Out of scope: any client environment or system we manage on a client's behalf; the third-party platforms we use as sub-processors (report those to the vendor — we'll help coordinate); denial-of-service or volumetric testing; physical attacks; and social engineering of the operator, clients, or vendors.
What to expect: we acknowledge a report within 2 business days, give an initial assessment within 5, keep you updated through resolution, and — with your permission — credit you once the issue is fixed.
Safe harbor: if you make a good-faith effort to follow this policy, we will treat your research as authorized, we will not pursue or support legal action against you for it, and we will work with you to resolve the issue quickly.
We link the sources behind our security and compliance content.
Founder credentials
Obsidian Ridge is led by a CISSP-certified security practitioner with a decade of cybersecurity experience spanning:
Today he architects security for a large enterprise. Work spans individual protection, small business security, and enterprise environments.
CISSP • CCFH (CrowdStrike) • ZDTA (Zscaler) • CySA+ (CompTIA) • Security+ (CompTIA) • Network+ (CompTIA) • CC (ISC²)
Each credential is verifiable through its issuing body on request. The full bio, employment history, and engagement scope live on the About page.
Operating principles
Sales-driven security firms tend to communicate what they do. We find it more useful to tell you what is off the table — in writing, on a page you can link to and hold us against.
Briefing intake, newsletter sign-ups, and service operational data are used only to deliver the work you hired us for. Our revenue is service fees and channel partnerships — not data.
Ridge Core is month-to-month. Ridge Plus and Ridge Reserve run on annual terms with an explicit renewal opt-in, not silent auto-renew. You see the renewal date before it happens, every time.
Affiliate and reseller relationships are disclosed at the link, on the privacy page, and at the routing layer (/go/<vendor>). If a payout would change our honest recommendation, we walk away from the deal — not from the recommendation.
Every case study is real and either named with written consent or anonymized at the client's request. Every credential listed below has a verification path on request. No stock-photo founders, no AI-generated reviews, no inflated headcount.
No Meta Pixel, no Google Ads remarketing, no X tracking. Site analytics run on Plausible — cookieless, no cross-site tracking, no personal data sold. No third-party advertising trackers reading your visit.
Ridge Core $25, Ridge Plus $50, Ridge Reserve $70, each per person per month, and Ridge Log at $8 per data source per month: all listed on /pricing along with fixed onboarding fees and Sprint pricing. No 'call for pricing' gating, no hidden minimums. What's on the page is what the proposal will show.
Obsidian Ridge is a CISSP-led practice with one senior practitioner on every engagement. We don't claim a 30-person SOC we don't have — Huntress operates the 24/7 SOC behind the detection platforms, and that relationship is named openly on every page that depends on it.
Briefings are free, 30 minutes, and we tell you when you don't need us. No urgency timers, no fake renewal pressure, no fear-driven upgrade emails. If the fit isn't there, we'll point you to something simpler — no hard feelings.
If you see us doing any of the above, email security@obsidianridge.io and call it out. We'll confirm, fix, or explain — in writing — within two business days.
A note on our published research
Our KEV tracker, advisories, and industry pages are informational and reflect the best available public sources at the time of writing. Each links to primary sources. Nothing on this site is legal or compliance advice.
Related policies
How we handle data, what we collect, the affiliate and reseller relationships behind our revenue, and how we're paid in plain English.
Read the policy →The terms that govern the website, the assessment tool, the blog, and the briefing intake — including the DMCA procedure and export-controls notice.
Read the terms →How refunds, cancellations, and pro-rations work across Ridge Core, Ridge Plus, and Ridge Reserve, plus the policy for fixed-fee sprints and incident response blocks.
Read the policy →Our WCAG 2.2 AA target, known limitations, and how to request an accessible alternative or report a barrier — with a two-business-day response commitment.
Read the statement →Next step
The briefing is free, 30 minutes, and we tell you when you don't need us. Where an engagement calls for a written agreement, BAA, or DPA, we share the executable version during the briefing.
Not ready to talk? Score yourself first →