CYPHERYN Privacy Policy
Information CYPHERYN processes
CYPHERYN processes identity information supplied by the configured authentication provider, such as an account subject and email address; organization memberships; investigation targets and authorization records; provider configuration state; scan requests and results; entities, relationships, findings, reports, evidence, audit events, operational logs, notification settings, and legal acceptance records.
Why it is processed
This information is used to authenticate users, enforce tenant and authorization boundaries, perform requested analysis, preserve evidence and provenance, generate reports, monitor operation, investigate abuse, and maintain security and reliability.
Providers and processors
Authentication, hosting, threat-intelligence, notification, storage, and other configured services may receive the minimum information needed for their function. Queries sent to intelligence providers can reveal a target or indicator. Those services operate under their own terms and privacy practices. Operators choose which integrations to enable.
AI processing
CYPHERYN may send bounded evidence summaries to the AI service configured by the operator. A local model can keep that processing within operator-controlled infrastructure; a remotely configured model may process data under that provider's terms. AI output can be inaccurate and is retained as analysis, not established fact.
Cookies and authentication
The production service uses an authentication provider and a secure session proxy. They use cookies required to establish and maintain a signed-in session. CYPHERYN does not claim that these essential authentication records are anonymous.
Retention and deletion
Investigation data, evidence, audit history, and acceptance records persist according to the operator's retention, backup, integrity, and legal requirements. Deleting an account or investigation may not immediately remove protected backups, required audit evidence, or records that must be retained. Contact the deployment operator to request access, correction, export, or deletion where applicable.
Security and limits
CYPHERYN uses technical controls intended to protect stored data, but no service can guarantee absolute security. Do not submit data you lack authority to process, and never place API keys or secrets into investigation targets or notes.
Policy contact
For this open-source project, use the repository's issue tracker for non-sensitive policy questions. Use private security reporting for vulnerabilities.