Skip to content

Contact

Start a conversation

Tell us what you're up against. It starts with half an hour on what you actually run — a real person replies, and we won't oversell you.

Reply time
≤ 2 working days
Incidents
Hours, CET
Direct
hello@cryvanta.io
Active incident?

If you're under attack right now

Tell us in three fields below. The report goes to our incident inbox and, after delivery, a separate content-free alert is queued for our phones. We aim to respond within a few hours during CET business hours, and we'll be straight with you: we are not a staffed 24/7 SOC. If you need round-the-clock response this minute, your national CERT/CSIRT (in Sweden, CERT-SE) can mobilise immediately.

Sends the report to our incident inbox and queues a content-free phone alert.

What you write reaches our team by email. The alert to our phones deliberately carries no details — just that a report has arrived. Please keep this to who you are, how to reach you, and the shape of the problem; names of staff or customers, credentials and log extracts are better handled on the call than typed into a web form. Retention is reviewed manually against the criteria in our privacy notice. How we handle it.

Belt and braces: you can also email hello@cryvanta.io with URGENT in the subject.

Goes straight to the team — no newsletter, no CRM sequence. Retention is reviewed manually against the criteria in our privacy notice. How we handle it.

What to tell us

None of this is required, and a single sentence is enough to start. But the more of it you bring, the less of the first call is spent establishing facts — and the more of it is spent on what to actually do.

  • What the business doesAnd what would hurt most if it stopped — delivery, payments, a customer-facing service.
  • How many peopleRough headcount, and roughly how many of them are technical.
  • Where you operateCountries, and whether you sell into a regulated market or a demanding supply chain.
  • What you runCloud, on-premise or both. Microsoft 365 or Google. Anything internet-facing you build yourself.
  • Who looks after IT todayAn in-house team, a managed provider, or nobody formally yet.
  • What prompted thisA customer security questionnaire, an audit, an incident, a launch, or a board asking questions.
  • Any date you're working toA deadline changes what we would suggest doing first.

Or reach us directly

Region
Nordic · European Union
Security reports
Use responsible disclosure rather than this form.

What you send reaches the team and nothing else. No newsletter list, no CRM sequence, and no third-party form host — the form posts to our own server. The email it produces is delivered by our mail provider, which is named in the privacy notice.

What happens next

No funnel, no pressure

We're a small team and we like it that way — it means your first reply comes from someone who actually builds the thing.

01

A person reads it

Not a ticketing bot. One of us reads your message and replies — usually within two working days.

02

Then we talk

Half an hour on what you run and what is worrying you — no scope, no deck. If we are not the right fit, or what you need is still on our roadmap, we say so then rather than string you along.

03

You stay in control

Nothing is touched, tested or deployed without a written scope you've agreed to first.