← CYPHERYNLegal & responsible use

CYPHERYN Privacy Policy

Version
1.0
Effective
September 3, 2026
Last updated
September 3, 2026

Information CYPHERYN processes

CYPHERYN processes identity information supplied by the configured authentication provider, such as an account subject and email address; organization memberships; investigation targets and authorization records; provider configuration state; scan requests and results; entities, relationships, findings, reports, evidence, audit events, operational logs, notification settings, and legal acceptance records.

Why it is processed

This information is used to authenticate users, enforce tenant and authorization boundaries, perform requested analysis, preserve evidence and provenance, generate reports, monitor operation, investigate abuse, and maintain security and reliability.

Providers and processors

Authentication, hosting, threat-intelligence, notification, storage, and other configured services may receive the minimum information needed for their function. Queries sent to intelligence providers can reveal a target or indicator. Those services operate under their own terms and privacy practices. Operators choose which integrations to enable.

AI processing

CYPHERYN may send bounded evidence summaries to the AI service configured by the operator. A local model can keep that processing within operator-controlled infrastructure; a remotely configured model may process data under that provider's terms. AI output can be inaccurate and is retained as analysis, not established fact.

Cookies and authentication

The production service uses an authentication provider and a secure session proxy. They use cookies required to establish and maintain a signed-in session. CYPHERYN does not claim that these essential authentication records are anonymous.

Retention and deletion

Investigation data, evidence, audit history, and acceptance records persist according to the operator's retention, backup, integrity, and legal requirements. Deleting an account or investigation may not immediately remove protected backups, required audit evidence, or records that must be retained. Contact the deployment operator to request access, correction, export, or deletion where applicable.

Security and limits

CYPHERYN uses technical controls intended to protect stored data, but no service can guarantee absolute security. Do not submit data you lack authority to process, and never place API keys or secrets into investigation targets or notes.

Policy contact

For this open-source project, use the repository's issue tracker for non-sensitive policy questions. Use private security reporting for vulnerabilities.

© 2026 CYPHERYN
TermsResponsible UsePrivacySecurityContact