How Cerberus is built to be trusted

We're an early-stage beta product, so we'd rather under-claim than over-claim. Here's exactly where each piece of our security posture stands today.

๐Ÿ”

EV Code-Signed Driver

The Cerberus kernel driver ships with an Extended Validation (EV) code-signing certificate on every release. WHQL certification is in progress and not yet complete.

WHQL PENDING
๐Ÿงฑ

Hypervisor-Assisted Isolation

Kernel Integrity (Layer 1) uses hypervisor-assisted memory isolation to detect syscall tampering, PTE manipulation, and BYOVD attempts before they can touch protected memory regions.

ACTIVE IN BETA
๐Ÿ’ค

Zero Persistent Background Process

The Cerberus SDK does not install a persistent background service. It loads with the protected game process and unloads fully when the game closes โ€” nothing keeps running afterward.

BY DESIGN
๐Ÿ“‹

SOC 2 Type II

We've scoped a SOC 2 Type II audit and engaged an auditor, but as a closed-beta company we don't have a completed report yet. We'll publish the report here the day it's final โ€” not before.

SCHEDULED
๐Ÿ”‘

Encryption in Transit & at Rest

Detection events and session metadata are encrypted in transit (TLS 1.3) and at rest (AES-256) across all three regions. No detection data is ever transmitted unencrypted.

ACTIVE
๐Ÿงช

Independent Penetration Testing

We run internal red-team exercises against the kernel driver and API each release cycle. A third-party penetration test is planned once we exit closed beta.

PLANNED

Found a security issue? Tell us first.

We run an open responsible-disclosure program. Full policy details are published at our /.well-known/security.txt.

Responsible Disclosure Program

View security.txt โ†’

If you've found a vulnerability in the Cerberus kernel driver, detection engine, partner API, SDK, or this website, we want to hear from you before anyone else does. We respond to all reports within 48 hours.

In Scope

  • Kernel driver & usermode components
  • Detection engine & signature database
  • Partner API and SDK
  • This website (cerberusac.dev)

Out of Scope

  • Social engineering of team members
  • Denial-of-service attacks
  • Automated scanning without prior approval

We don't currently offer a paid bug bounty โ€” we're a small closed-beta team. What we do offer: public recognition (with your permission) on our acknowledgments page, and early access to new detection features for researchers who report valid findings.

๐Ÿ“ง Report to security@arsenalrx.dev  ยท  PGP key and full policy linked from security.txt

What we collect. What we never do.

The Cerberus SDK's job is anti-cheat detection, not surveillance. Here's the plain-language version โ€” the full legal text lives in our Privacy Policy.

We CollectWe Never Collect
Detection signal data (aimbot, injection, DMA confidence scores)Gameplay recordings or screenshots
Session integrity metadata (game ID, region, SDK version, session duration)Chat or voice content of any kind
Hashed hardware fingerprints, used solely for ban-evasion detectionBrowsing history or activity outside the game
Kernel-level memory permission & module integrity checksAnything outside the anti-cheat scan scope
๐Ÿ›‘

Zero telemetry when the game isn't running. The Cerberus SDK is not a background service โ€” it loads with the protected process and collects nothing when the game is closed. No idle pings, no always-on data collection.

Who touches our infrastructure

We keep our vendor footprint small on purpose. Categories below are described generically โ€” detailed vendor names are available to partner studios under NDA.

โ˜๏ธ

Multi-Region Cloud Infrastructure Provider

Hosts detection backend and databases across our three regions (US-East, EU-West, AP-Southeast).

๐ŸŒ

CDN / Edge Network Provider

Distributes signature updates and static assets with regional edge caching.

๐Ÿž

Error Monitoring & Observability Provider

Aggregates crash reports and performance traces from the API and dashboard โ€” no gameplay data included.

โœ‰๏ธ

Transactional Email Provider

Sends partner account notifications, security alerts, and status subscription updates.

Nothing hidden behind a status page

We publish our uptime, incidents, and every signature/security change we ship โ€” including the ones we'd rather not talk about.

SLA and data processing terms

For partner studios who need these for procurement or legal review.