Our commitment: As a cybersecurity company, we hold ourselves to the highest standards of data protection. This page details our security practices, compliance framework, and how we safeguard your business data.
1. Security Architecture Overview
Encryption
All data is encrypted in transit using TLS 1.2+. Sensitive credentials are hashed using bcrypt with adaptive cost factors.
Authentication
JWT-based authentication with configurable expiry. OAuth 2.0 for email integrations — we never handle your email provider passwords.
Access Control
Role-based access control with company-level data isolation. Each customer's data is logically separated and inaccessible to others.
Audit Logging
Comprehensive audit logs track all significant actions — logins, email connections, threat detections, and configuration changes.
2. Data Processing Details
Data Type
Purpose
Storage
Retention
Account info (name, email)
Authentication & communication
Encrypted DB
Until account deletion + 30 days
Passwords
Authentication
Bcrypt hashed
Until account deletion
OAuth tokens
Email provider access
Encrypted DB
Until account disconnected
Email content
Real-time threat scanning
In-memory only
Not stored — processed in real-time
Email metadata (sender, subject)
Threat detection & reporting
Encrypted DB
12 months
Network threat logs
Attack detection & analytics
Encrypted DB
12 months
Vulnerability scan results
Security assessments
Encrypted DB
Until account deletion
Payment data
Subscription billing
Paystack (PCI-DSS)
As required by law
3. Compliance Framework
3.1 POPIA (South Africa)
As a South African company, we comply with the Protection of Personal Information Act (POPIA):
Lawful processing: We only process personal information with your consent or as necessary to provide the Service
Purpose limitation: Data is collected for specific, defined purposes and not used beyond those purposes
Minimality: We collect only the minimum data necessary to provide the Service
Information Officer: Contact us at ciphrai.sec@gmail.com for POPIA-related inquiries
Right to complain: You may lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za
3.2 GDPR (European Union)
For users in the European Economic Area, we adhere to GDPR principles:
Legal basis: We process data based on contractual necessity and legitimate interest
Data subject rights: Access, rectification, erasure, portability, and objection rights are fully supported
Data Protection Impact Assessments: Conducted for high-risk processing activities
Breach notification: We will notify affected users and relevant authorities within 72 hours of a confirmed data breach
3.3 General Data Protection Practices
Regardless of your jurisdiction, we apply these standards globally:
Privacy by design and by default
Regular security assessments and code reviews
Principle of least privilege for internal access
Secure software development practices
4. Infrastructure Security
4.1 Hosting
Application hosted on enterprise-grade cloud infrastructure with automatic scaling
HTTPS enforced on all connections
DDoS protection at the infrastructure level
Automatic deployments with zero-downtime updates
4.2 Database Security
Production database uses managed database services with automatic backups
Data-at-rest encryption provided by the database service
Database credentials rotated regularly and never stored in code
Parameterized queries used throughout to prevent SQL injection
4.3 Application Security
Input validation: All user inputs are sanitized and validated server-side
Rate limiting: Applied to all API endpoints to prevent abuse
Include your registered email address and company name
We will process your request within 30 days
You will receive confirmation once deletion is complete
Note: After deletion, some anonymized, aggregated data may be retained for statistical purposes. This data cannot be traced back to you or your organization.
9. Contact Us
For questions about our data practices, compliance, or security: