SOC 2 Type II
Not yet held. In progress.
Trust Center
We enforce policy at the point of action, record every decision in a tamper evident audit trail, and publish everything you need to evaluate us.
Cyphrex is compliance infrastructure for AI agents. We enforce policy at the point of action, record every decision in a tamper evident audit trail, and produce signed evidence packages that a third party can verify independently.
Because our customers rely on us for their own compliance evidence, we hold ourselves to the standard we help them meet. This page documents our security posture, our subprocessors, and our data handling, and it states plainly what we have completed and what we have not.
Not yet held. In progress.
Not yet held.
DPA available. Metadata only architecture.
We do not market frameworks we have not completed. When these change, this page changes.
Every Cyphrex evidence package is signed with Ed25519. Anchored events carry a per-event proof of inclusion in the hourly on-chain root — membership of a closed leaf, not completeness of the tree. You do not need a Cyphrex account, our permission, or our cooperation to check one. Paste a report ID or upload the source JSON and verify it yourself.
For how this evidence layer sits next to an agent security platform, see Cyphrex vs Zenity. Other comparisons are on Compare.
These controls describe how Cyphrex operates today. They have not yet been examined by an independent auditor.
How authentication, isolation, keys, and transport work today. These are described controls, not an auditor opinion.
Action metadata can itself be sensitive. A resource reference plus a timestamp may constitute protected health information in healthcare, or reveal privileged matter patterns in legal. We therefore treat our audit store as regulated data, sign BAAs and DPAs accordingly, and publish our subprocessors. We do not claim to hold nothing sensitive. We claim to hold no content.
Data is stored in the United States. Regional residency is available on Enterprise agreements.
| Name | Purpose | Data location | Website |
|---|---|---|---|
| Supabase Inc. | Database and authentication | USA (AWS us-east-1) | supabase.com |
| Railway Corp. | Application hosting | USA (us-west-2) | railway.app |
| Resend Inc. | Transactional email delivery | USA | resend.com |
| Sentry (Functional Software, Inc.) | Error monitoring and performance tracking | USA | sentry.io |
| BetterStack | Uptime monitoring | EU | betterstack.com |
| Solana Foundation | Public blockchain anchoring of audit Merkle roots | Decentralized (global validators) | solana.org |
Only Merkle root hashes are written on chain. No customer content, payload data, or personal data is published to the blockchain.
We provide 30 days notice before engaging a new subprocessor. Customers may object on reasonable data protection grounds.
SOC 2 Type II report and penetration test results will be published here once complete.
Security questions and vulnerability reports: hello@cyphrex.io