Cerberus is a closed-beta anti-cheat engine. This page lays out our security posture, our disclosure process, and exactly what data the SDK does and doesn't touch โ no marketing gloss.
We're an early-stage beta product, so we'd rather under-claim than over-claim. Here's exactly where each piece of our security posture stands today.
The Cerberus kernel driver ships with an Extended Validation (EV) code-signing certificate on every release. WHQL certification is in progress and not yet complete.
WHQL PENDINGKernel Integrity (Layer 1) uses hypervisor-assisted memory isolation to detect syscall tampering, PTE manipulation, and BYOVD attempts before they can touch protected memory regions.
ACTIVE IN BETAThe Cerberus SDK does not install a persistent background service. It loads with the protected game process and unloads fully when the game closes โ nothing keeps running afterward.
BY DESIGNWe've scoped a SOC 2 Type II audit and engaged an auditor, but as a closed-beta company we don't have a completed report yet. We'll publish the report here the day it's final โ not before.
SCHEDULEDDetection events and session metadata are encrypted in transit (TLS 1.3) and at rest (AES-256) across all three regions. No detection data is ever transmitted unencrypted.
ACTIVEWe run internal red-team exercises against the kernel driver and API each release cycle. A third-party penetration test is planned once we exit closed beta.
PLANNEDWe run an open responsible-disclosure program. Full policy details are published at our /.well-known/security.txt.
If you've found a vulnerability in the Cerberus kernel driver, detection engine, partner API, SDK, or this website, we want to hear from you before anyone else does. We respond to all reports within 48 hours.
We don't currently offer a paid bug bounty โ we're a small closed-beta team. What we do offer: public recognition (with your permission) on our acknowledgments page, and early access to new detection features for researchers who report valid findings.
The Cerberus SDK's job is anti-cheat detection, not surveillance. Here's the plain-language version โ the full legal text lives in our Privacy Policy.
| We Collect | We Never Collect |
|---|---|
| Detection signal data (aimbot, injection, DMA confidence scores) | Gameplay recordings or screenshots |
| Session integrity metadata (game ID, region, SDK version, session duration) | Chat or voice content of any kind |
| Hashed hardware fingerprints, used solely for ban-evasion detection | Browsing history or activity outside the game |
| Kernel-level memory permission & module integrity checks | Anything outside the anti-cheat scan scope |
Zero telemetry when the game isn't running. The Cerberus SDK is not a background service โ it loads with the protected process and collects nothing when the game is closed. No idle pings, no always-on data collection.
We keep our vendor footprint small on purpose. Categories below are described generically โ detailed vendor names are available to partner studios under NDA.
Hosts detection backend and databases across our three regions (US-East, EU-West, AP-Southeast).
Distributes signature updates and static assets with regional edge caching.
Aggregates crash reports and performance traces from the API and dashboard โ no gameplay data included.
Sends partner account notifications, security alerts, and status subscription updates.
We publish our uptime, incidents, and every signature/security change we ship โ including the ones we'd rather not talk about.
Full 30-day and monthly uptime history, per-region service health, and incident postmortems โ updated in real time.
View status โEvery signature update and security fix is logged publicly, tagged "security" so partners can audit exactly what changed and when.
View changelog โFor partner studios who need these for procurement or legal review.
Our uptime commitment, service credit schedule, and incident response targets โ set at or below what we already deliver, not above it.
View SLA โWhat data we process on your behalf, our sub-processors, and data subject rights โ for GDPR-relevant studios.
View DPA โ