We don't sell, rent, or share client data.
Briefing intake, newsletter sign-ups, and service operational data are used only to deliver the work you hired us for. Our revenue is service fees and channel partnerships — not data.
Trust & transparency
Security work only means something if the security company is honest about itself. This page reflects what is true and active today. If something isn't in place yet, it isn't listed here — and if you ever find a gap between what we say and what we do, tell us and we'll fix it.
Last reviewed: August 13, 2026. Reviewed by: Kfir Yair, Founder.
Who we are
Principal:Kfir Yair, CISSP. You work directly with the person who does the work — not an account manager or a call center.
Contact: security@obsidianridge.io· 964 High House Rd, PMB 2086, Cary, NC 27513 · (984) 999-7785
How we deliver security
Partner posture
Obsidian Ridge is a Huntress MDR Partner. That means we operate the Huntress Managed EDR, Managed ITDR, Managed Security Awareness Training, and Managed SIEM platforms end-to-end for covered organizations — deployment, alert triage, escalation handling, incident response coordination, and compliance evidence packaging. Huntress operates the 24/7 SOC behind the detection platforms; we add the practitioner program that turns the platform into an outcome.

Partner posture
Obsidian Ridge is a Fortinet partner. Fortinet's security platform underpins parts of our managed stack, operated and monitored by us.

Sub-processors
Published in full because clients with privacy obligations (HIPAA, GDPR, CCPA) need to list every party that handles their data. Anything not on this list does not see your data. Changes here trigger a 30-day notice to clients before activation.
| Sub-processor | Purpose | Data handled |
|---|---|---|
| Vercel | Website hosting | Site content, form submissions in transit |
| Supabase | Application database | Contact, assessment, and calculator submissions |
| Resend | Email delivery | Email address, message content |
| Cloudflare | DNS and bot protection (Turnstile) | Connection metadata |
| Plausible | Cookieless site analytics | Aggregate page-view and event counts |
| Proton | Business email | Correspondence with us |
We review this list on a regular basis. Last reviewed: August 13, 2026.
Cross-border note: where a US-hosted sub-processor handles personal data of an EU or UK data subject, the EU / UK Standard Contractual Clauses are incorporated by reference via the relevant DPA. Where a sub-processor is added or replaced, existing clients receive written notice at least 30 days before activation. Plausible, our active analytics processor, is EU-based and EU-hosted, keeping visitor analytics within EU jurisdiction and outside the US CLOUD Act's reach.
Payments & contracting
Engagements are governed by a written agreement and, where applicable, a Business Associate Agreement or Data Processing Addendum.
Data residency
Application data (briefing requests, assessment responses, newsletter subscribers) is stored in the United States at Supabase (US East). Email delivery uses US-region Resend. Where a US-hosted sub-processor handles personal data of an EU or UK data subject, the EU / UK Standard Contractual Clauses are incorporated by reference through the relevant DPA. No client data is transferred to a jurisdiction without an approved transfer mechanism in place.
Vulnerability disclosure
We publish an RFC 9116 security.txt at /.well-known/security.txt, and its Policy field points here. Send coordinated vulnerability reports to Obsidian Ridge LLC at security@obsidianridge.io — encrypted over PGP on request. Please give us a reasonable chance to fix an issue before disclosing it publicly.
In scope: this website — obsidianridge.ioand its subdomains — and its forms and API endpoints.
Out of scope:any client environment or system we manage on a client's behalf; the third-party platforms we use as sub-processors (report those to the vendor — we'll help coordinate); denial-of-service or volumetric testing; physical attacks; and social engineering of the operator, clients, or vendors.
What to expect:we acknowledge a report within 2 business days, give an initial assessment within 5, keep you updated through resolution, and — with your permission — credit you once the issue is fixed.
Safe harbor: if you make a good-faith effort to follow this policy, we will treat your research as authorized, we will not pursue or support legal action against you for it, and we will work with you to resolve the issue quickly.
We publish last-reviewed dates and sources on our security and compliance content.
Founder credentials
Obsidian Ridge is led by a CISSP-certified security practitioner with 10+ years of cybersecurity experience spanning the IDF, the Israeli Government Tax Authority as Production Technical Lead, Deloitte in Digital Forensics & Risk Analytics, Varonis as a Cyber Security Architect, Cypress Creek Renewables as a Cloud Security Analyst, and TEKRiSQ as Director of Security Solutions — currently leading Zero Trust Island Browser deployment for a Fortune 500 airline. Work spans individual protection, small business security, and enterprise environments.
CISSP • CCFH (CrowdStrike) • ZDTA (Zscaler) • CySA+ (CompTIA) • Security+ (CompTIA) • Network+ (CompTIA) • CC (ISC²)
Each credential is verifiable through its issuing body on request. The full bio, employment history, and engagement scope live on the About page.
Operating principles
Sales-driven security firms tend to communicate what they do. We find it more useful to tell you what is off the table — in writing, on a page you can link to and hold us against.
Briefing intake, newsletter sign-ups, and service operational data are used only to deliver the work you hired us for. Our revenue is service fees and channel partnerships — not data.
Foundation is month-to-month. Protected and Complete run on annual terms with an explicit renewal opt-in, not silent auto-renew. You see the renewal date before it happens, every time.
Affiliate and reseller relationships are disclosed at the link, on the privacy page, and at the routing layer (/go/<vendor>). If a payout would change our honest recommendation, we walk away from the deal — not from the recommendation.
Every case study is real and either named with written consent or anonymized at the client's request. Every credential listed below has a verification path on request. No stock-photo founders, no AI-generated reviews, no inflated headcount.
No Meta Pixel, no Google Ads remarketing, no X tracking. Site analytics run on Plausible — cookieless, no cross-site tracking, no personal data sold. No third-party advertising trackers reading your visit.
Foundation $15/agent, Protected $32/user, Complete from $55/user — all listed on /pricing along with fixed onboarding fees and Sprint pricing. No 'call for pricing' gating, no hidden minimums. What's on the page is what the proposal will show.
Obsidian Ridge is a CISSP-led practice with one senior practitioner on every engagement. We don't claim a 30-person SOC we don't have — Huntress operates the 24/7 SOC behind the detection platforms, and that relationship is named openly on every page that depends on it.
Briefings are free, 30 minutes, and we tell you when you don't need us. No urgency timers, no fake renewal pressure, no fear-driven upgrade emails. If the fit isn't there, we'll point you to something simpler — no hard feelings.
If you see us doing any of the above, email security@obsidianridge.ioand call it out. We'll confirm, fix, or explain — in writing — within two business days.
A note on our published research
Our KEV tracker, advisories, and industry pages are informational and reflect the best available public sources at the time of review. Each carries a last-reviewed date and links to primary sources. Nothing on this site is legal or compliance advice.
Related policies
How we handle data, what we collect, the affiliate and reseller relationships behind our revenue, and how we're paid in plain English.
Read the policy →The terms that govern the website, the assessment tool, the blog, and the briefing intake — including the DMCA procedure and export-controls notice.
Read the terms →How refunds, cancellations, and pro-rations work across Foundation, Protected, and Complete — plus the policy for fixed-fee sprints and incident response blocks.
Read the policy →Our WCAG 2.2 AA target, known limitations, and how to request an accessible alternative or report a barrier — with a two-business-day response commitment.
Read the statement →Next step
The briefing is free, 30 minutes, and we tell you when you don't need us. Where an engagement calls for a written agreement, BAA, or DPA, we share the executable version during the briefing.
Not ready to talk? Score yourself first →