Trust Center

Security you can check yourself.

We enforce policy at the point of action, record every decision in a tamper evident audit trail, and publish everything you need to evaluate us.

Cyphrex is compliance infrastructure for AI agents. We enforce policy at the point of action, record every decision in a tamper evident audit trail, and produce signed evidence packages that a third party can verify independently.

Because our customers rely on us for their own compliance evidence, we hold ourselves to the standard we help them meet. This page documents our security posture, our subprocessors, and our data handling, and it states plainly what we have completed and what we have not.

SOC 2 Type II

Not yet held. In progress.

ISO 27001

Not yet held.

GDPR

DPA available. Metadata only architecture.

We do not market frameworks we have not completed. When these change, this page changes.

Verify us without trusting us

Every Cyphrex evidence package is signed with Ed25519 and its Merkle root is anchored to a public blockchain. You do not need a Cyphrex account, our permission, or our cooperation to check one. Paste a report ID or upload the source JSON and verify it yourself.

Public key registry
/keys
Independent verification
/verify
Anchoring network
Solana

Controls

These controls describe how Cyphrex operates today. They have not yet been examined by an independent auditor.

Infrastructure security

  • Role based access controlLeast privilege provisioning and periodic review.
  • Multi factor authenticationRequired for administrative access.
  • Unique credentialsNo shared accounts.
  • Production accessRestricted to authorized personnel with a business need.
  • Account scoped accessEnforced in the API layer. A customer may access only their own account data.

Data protection

  • Encryption in transitIndustry standard TLS.
  • Encryption at restProvided by the underlying infrastructure provider.
  • Metadata only by defaultAction payloads are not retained.
  • Configurable retentionWindows set per customer.
  • Deletion after terminationCustomer data deleted following the retention period after termination.

Record integrity

  • Merkle treesAction records hashed and batched into Merkle trees.
  • Ed25519 anchoringMerkle roots signed with Ed25519 and anchored to a public blockchain.
  • Signing key controlSigning keys held under controlled access.
  • Public keysPublished to enable independent verification.
  • Tamper detectionAlteration of an anchored record is cryptographically detectable.

Monitoring and response

  • Application error monitoringProduction errors are captured and reviewed.
  • Uptime monitoringPublic status page at status.cyphrex.io.
  • Administrative audit loggingAdministrative actions are logged.
  • Incident responseDocumented incident response process.
  • Incident notificationSecurity incident notification within 72 hours.

Development and change management

  • Version controlInfrastructure and schema migrations are version controlled.
  • Dependency monitoringDependencies are monitored, with timely security patching.
  • Code reviewCode review before production deployment.

Platform security

How authentication, isolation, keys, and transport work today. These are described controls, not an auditor opinion.

  • InfrastructureRailway for compute, Supabase for database and auth, Solana for blockchain anchoring. All data is stored in the United States.
  • AuthenticationEmail and password, and GitHub OAuth. Passwords are handled by Supabase Auth and are never stored by Cyphrex in plaintext. JWTs are validated server-side. Insecure algorithms are rejected at the API layer.
  • API keysHashed with SHA-256 before storage. Shown once at generation. Compared in constant time. Rotate from the dashboard.
  • Tenant isolationEnforced in the API layer. Every route is account-scoped and ownership is checked before any resource is returned. The API uses the service role key and bypasses row-level security. RLS policies are enabled on customer tables as an additional control, not as the isolation boundary.
  • TransportHTTPS with HSTS. X-Frame-Options, X-Content-Type-Options, Content-Security-Policy, and Referrer-Policy on all responses.
  • Incident responseCustomer notification of a confirmed breach within 72 hours. Full incident report within 7 days of resolution. Full policy.

What we store, and what we do not

What Cyphrex records

  • Agent identity
  • Action type
  • Resource reference
  • Timestamp
  • Policy decision, allowed or blocked
  • Rule matched and violation details

What Cyphrex does not retain

  • The content of what an agent read, wrote, or said
  • Prompt or response payloads, except where a customer explicitly enables per agent capture
  • Any customer data on the blockchain, only cryptographic hashes

Action metadata can itself be sensitive. A resource reference plus a timestamp may constitute protected health information in healthcare, or reveal privileged matter patterns in legal. We therefore treat our audit store as regulated data, sign BAAs and DPAs accordingly, and publish our subprocessors. We do not claim to hold nothing sensitive. We claim to hold no content.

Data is stored in the United States. Regional residency is available on Enterprise agreements.

Subprocessors

NamePurposeData locationWebsite
Supabase Inc.Database & AuthenticationUSA (AWS us-east-1)supabase.com
Railway Corp.Application HostingUSA (us-west-2)railway.app
Resend Inc.Email DeliveryUSAresend.com
Sentry (Functional Software, Inc.)Error monitoring & performance trackingUSAsentry.io
BetterStackUptime monitoringEUbetterstack.com

We provide 30 days notice before engaging a new subprocessor. Customers may object on reasonable data protection grounds.

Documents

Available on request

  • Security overview
  • Data flow description
  • Business Associate Agreement template
  • Incident response summary

SOC 2 Type II report and penetration test results will be published here once complete.

Contact

Security questions and vulnerability reports: hello@cyphrex.io

Message the founder