ChimeraScope is operated by Gexiro Global Enterprises Ltd. We hold our own security posture to the same rigour we apply to client assessments — documented transparently, with no overstated claims.
Security posture & responsible disclosure
Enforced Content-Security-Policy, HSTS (1-year, includeSubDomains), X-Frame-Options DENY, X-Content-Type-Options nosniff, and a set of modern HTTP security headers.
Anti-abuse controls are applied to public contact endpoints.
We welcome responsible disclosure — see security.txt and our Vulnerability Disclosure Policy below.
CSA STAR Level 1 (self-assessment)
ChimeraScope (Gexiro Global Enterprises Ltd) is listed in the Cloud Security Alliance STAR Registry at Level 1, based on the CAIQ/CCM self-assessment. This is a self-assessment, not a third-party certification.
Application security
OWASP ASVS v5.0 Level 1 — internal self-verification completed. OWASP does not certify; this is a self-verification.
CIS Controls v8 (IG1 self-assessment)
Self-assessed against the CIS Controls v8, Implementation Group 1 (IG1) using the CIS Controls Self Assessment Tool (CSAT). This is a self-assessment, not a third-party certification or audit.
DNSSEC & internet-standards hardening
DNSSEC enabled and validating on chimerascope.com and chimerascope.fyi (verified via public validating resolvers).
Hardened in line with modern internet standards, including TLS 1.3, HSTS, modern security headers, IPv6, and RPKI at the network edge.
Independently rated SSL Labs A+ for TLS configuration across our domains (external Qualys SSL Labs assessment).
Staff cybersecurity awareness training
Staff cybersecurity awareness training completed through the Global Cyber Alliance Learning Portal, covering cyber risk awareness, technology asset inventory, strong passwords and two-factor authentication, software update hygiene, email spoofing and phishing awareness, DMARC basics, phishing and malware prevention, ransomware recovery awareness, and business backup hygiene. Training certificates of completion are maintained internally. These certificates support staff awareness evidence and are not a third-party audit or company-level certification.
Additional business cybersecurity, cloud, network operations, and storage infrastructure awareness training has been completed through EC-Council CodeRed. Topics include cyber risk and minimum security practices, cloud service and deployment models, router/firewall administration concepts, DHCP, NAT/PAT, IP and DNS fundamentals, SAN/NAS storage, storage protocols, object storage, converged infrastructure, HCI, and NetApp ONTAP lab fundamentals. Course completion evidence is maintained internally. These records are not vendor certifications, third-party audits, or company-level certifications.
Continuing professional development in cybersecurity has been completed through Linux Foundation training (certificate of completion). Completion records are maintained internally. These are course completions, not vendor or professional certifications.
Secure disclosure
A published /.well-known/security.txt (RFC 9116) with a PGP key for encrypted reports.
A public Vulnerability Disclosure Policy and Security Advisories page. Security contact: [email protected].
Data protection
ISO/IEC 27001:2022 readiness self-assessment completed (internal; certification is not claimed).
GDPR / DSGVO data-protection and technical & organizational measures (TOM) review completed. No third-party trackers or analytics. Records of processing and subprocessors are documented.
Operational security
TLS is enforced throughout the public surface, with internal secret-management, backup, review, and rollback-safe deployment practices.
Servers run auto-updating anti-malware with scheduled, estate-wide scanning, host file-integrity monitoring, and rootkit/backdoor detection; security events are centrally alerted to operations and systems receive automated security patching.
End-user devices use full-disk encryption; backup recovery is periodically tested.
This page describes internal self-assessments and readiness reviews, not third-party certifications. To verify or reach our security team, see security.txt or contact us.
See it in action
Submit a target URL and receive a complimentary intelligence assessment within 24 hours.