Trust Centre
How CydraLabs protects your agents' data and decisions
Security, privacy and data-handling information for enterprise evaluation. Statements describe the current platform design; where something is not yet in place, we say so.
Security
Security design
- Tenant isolation
- PostgreSQL row-level security on every tenant table, enforced for a non-owner application role. Cross-tenant lookups return not found.
- Authentication
- OpenID Connect sign-in through a backend-for-frontend session with an HttpOnly cookie and CSRF protection. Agents use signed, short-lived workload tokens.
- Least-privilege roles
- Nine roles from one permission matrix, enforced by the API. Policy authors cannot publish their own policies.
- Fail-closed enforcement
- Policy engine or detector errors deny high-risk actions.
- Tamper-evident evidence
- Evidence records hash their predecessor and are signed with Ed25519. The application role cannot update or delete evidence.
- Encryption
- TLS for data in transit. In the AWS reference deployment, the database, cache and object storage are encrypted at rest with customer-managed KMS keys, and cache traffic requires TLS.
Privacy and data handling
Privacy and data handling
- Agent payloads are stored as content hashes plus redacted previews by default, not raw prompts or secrets.
- Structured logs redact secrets and personal data.
- Evidence can be written to object storage with S3 Object Lock in the AWS reference deployment.
- Website enquiries and quotation requests are kept for up to 12 months.
Subprocessors
Subprocessors
A formal subprocessor list will be published before general availability of the CydraLabs-managed service.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting of this website and the demonstration environment | Ireland (eu-west-1) |
| Amazon Web Services (Simple Email Service) | Sending request notifications, acknowledgements and account emails | Ireland (eu-west-1) |
| Plausible Analytics | Cookieless website and app usage statistics (no personal data) | European Union |
| Cloudflare (Turnstile) | Protecting website forms from automated abuse | Global network |
Deployment regions
Where the platform runs
The CydraLabs-managed pilot runs in AWS Ireland (eu-west-1). Customer-cloud deployments run in the account and region you choose.
CydraLabs-managed SaaS
Pilot programmeHosted and operated by CydraLabs.
Customer cloud or private VPC
Pilot programmeDeployed into your own cloud account with the CydraLabs reference deployment.
On-premises or sovereign deployment
RoadmapPlanned for environments that cannot use cloud services.
Assurance status
Assurance status
CydraLabs does not yet hold third-party certifications or attestations. We will publish changes to our assurance status on this page.
- The architecture, data model and threat model are documented and available to design partners.
- Automated checks run on every change: unit and integration tests, static analysis, dependency and container scanning, and secret scanning.
- Every capability on this site carries an Available, Beta, Preview or Roadmap label.
Contact routes
Contact routes
Security reports
Report a vulnerability in a CydraLabs service or this website.
Report an issueSecurity questionnaires
Request a security review or questionnaire response as part of an evaluation.
Contact usPrivacy requests
Ask about or exercise your rights over personal data we hold.
Contact us