Skip to content

Trust and security

What we do with your data, stated plainly.

This page exists to shorten your security review. Where the honest answer is “depends on your configuration”, it says so rather than claiming something cleaner.

Certifications

What we can and cannot claim today.

We do not display certification badges we have not been issued. If a framework matters to your procurement process, ask us directly on the call and we will tell you exactly where we are in that process, including if the answer is “not started”.

The platform's Assess and Comply agents produce control evidence against NIST CSF 2.0, CIS Controls v8, SOC 2 criteria, ISO 42001, and the OWASP LLM Top 10. That is a capability we ship, not a certification we hold, and the distinction matters.

Posture

Twelve properties, enforced by the platform.

Each of these is a construction guarantee rather than a process commitment, which is why we're willing to write them on a public page.

    • Immutable audit trail

      Every action, every approval, every rejection, written once and never edited.

    • Analyst gates on destructive actions

      Purging mail, disabling an account, or touching production always waits for a person.

    • Role-based access

      Admin, Analyst, and Viewer, enforced at the route rather than hidden in the interface.

    • Your credentials, your vault

      Connector secrets live in your own key vault. We never store them in our database.

    • Reversible by design

      Actions that can be undone record how to undo them, before they run.

    • Tenant isolation

      One tenant's data is never queried in another tenant's context.

Data handling

What we process, and for how long.

CategoryWhat it containsRetention
Security telemetryAlerts, incidents, sign-in events, findings, and the entities inside them.Retained per your configured policy. Deleted on tenant termination.
Connector credentialsNever stored. Read from your own key vault at runtime, held in memory only.Not applicable. Nothing is persisted.
Prompt and content samplesWhere AI Guardian inspects content, the detection result is stored; the payload is stored only if you enable it.Configurable, defaults to detection results only.
User accountsName, work email, role, and authentication state for your platform users.For the life of the account, then deleted.
Audit recordsEvery action, approval, rejection, and configuration change, with its actor.Append only. Retained for the contracted period, then exported and deleted.

Subprocessors

Who else touches it.

Cloud hosting

Your chosen region, or your own tenant if you self-host.

Model inference

Your own model deployment where configured, otherwise the provider you nominate.

Email delivery

Transactional email for invitations and notifications only.

A current, named subprocessor list is available under NDA and is provided as part of any security review.

Disclosure

Reporting a vulnerability.

If you have found something in our platform or on this site, we want to hear about it before anyone else does.

How to reach us

Email security@cyforte.com with enough detail to reproduce. We acknowledge within two business days and will keep you updated until it's resolved.

We will not pursue action against good-faith research that avoids privacy violations, service degradation, and data destruction. Please do not test against a customer tenant.

Bring your security reviewer to the first call.

We would rather answer the hard questions early than discover them at contract stage.

Book a technical review →

Book a demo

Ask us the hard questions.