Trust and security
What we do with your data, stated plainly.
This page exists to shorten your security review. Where the honest answer is “depends on your configuration”, it says so rather than claiming something cleaner.
Certifications
What we can and cannot claim today.
We do not display certification badges we have not been issued. If a framework matters to your procurement process, ask us directly on the call and we will tell you exactly where we are in that process, including if the answer is “not started”.
The platform's Assess and Comply agents produce control evidence against NIST CSF 2.0, CIS Controls v8, SOC 2 criteria, ISO 42001, and the OWASP LLM Top 10. That is a capability we ship, not a certification we hold, and the distinction matters.
Posture
Twelve properties, enforced by the platform.
Each of these is a construction guarantee rather than a process commitment, which is why we're willing to write them on a public page.
Immutable audit trail
Every action, every approval, every rejection, written once and never edited.
Analyst gates on destructive actions
Purging mail, disabling an account, or touching production always waits for a person.
Role-based access
Admin, Analyst, and Viewer, enforced at the route rather than hidden in the interface.
Your credentials, your vault
Connector secrets live in your own key vault. We never store them in our database.
Reversible by design
Actions that can be undone record how to undo them, before they run.
Tenant isolation
One tenant's data is never queried in another tenant's context.
Data handling
What we process, and for how long.
| Category | What it contains | Retention |
|---|---|---|
| Security telemetry | Alerts, incidents, sign-in events, findings, and the entities inside them. | Retained per your configured policy. Deleted on tenant termination. |
| Connector credentials | Never stored. Read from your own key vault at runtime, held in memory only. | Not applicable. Nothing is persisted. |
| Prompt and content samples | Where AI Guardian inspects content, the detection result is stored; the payload is stored only if you enable it. | Configurable, defaults to detection results only. |
| User accounts | Name, work email, role, and authentication state for your platform users. | For the life of the account, then deleted. |
| Audit records | Every action, approval, rejection, and configuration change, with its actor. | Append only. Retained for the contracted period, then exported and deleted. |
Subprocessors
Who else touches it.
Cloud hosting
Your chosen region, or your own tenant if you self-host.
Model inference
Your own model deployment where configured, otherwise the provider you nominate.
Email delivery
Transactional email for invitations and notifications only.
A current, named subprocessor list is available under NDA and is provided as part of any security review.
Disclosure
Reporting a vulnerability.
If you have found something in our platform or on this site, we want to hear about it before anyone else does.
How to reach us
Email security@cyforte.com with enough detail to reproduce. We acknowledge within two business days and will keep you updated until it's resolved.
We will not pursue action against good-faith research that avoids privacy violations, service degradation, and data destruction. Please do not test against a customer tenant.
Bring your security reviewer to the first call.
We would rather answer the hard questions early than discover them at contract stage.
