Our commitment: As a cybersecurity company, we hold ourselves to the highest standards of data protection. This page details our security practices, compliance framework, and how we safeguard your business data.
1. Security Architecture Overview
Encryption
All data is encrypted in transit using TLS 1.2+. Sensitive credentials are hashed using bcrypt with adaptive cost factors.
Authentication
JWT-based authentication with configurable expiry. OAuth 2.0 for email integrations — we never handle your email provider passwords.
Access Control
Role-based access control with company-level data isolation. Each customer's data is logically separated and inaccessible to others.
Audit Logging
Comprehensive audit logs track all significant actions — logins, email connections, threat detections, and configuration changes.
2. Data Processing Details
Data Type
Purpose
Storage
Retention
Account info (name, email)
Authentication & communication
Encrypted DB
Until account deletion (erased immediately)
Passwords
Authentication
Bcrypt hashed
Until account deletion
OAuth tokens
Email provider access
AES-256-GCM Encrypted
Until account disconnected or deleted
Email content
Real-time threat scanning
In-memory only
Not stored — processed in real-time
Email metadata (sender, subject)
Threat detection & reporting
Encrypted DB
Duration of active subscription
Network threat logs
Attack detection & analytics
Encrypted DB
Duration of active subscription
Vulnerability scan results
Security assessments
Encrypted DB
Until account deletion
Payment data
Subscription billing
Dodo Payments (PCI-DSS)
As required by law
3. Compliance Framework
3.1 POPIA (South Africa)
As a South African company, we comply with the Protection of Personal Information Act (POPIA):
Lawful processing: We only process personal information with your consent or as necessary to provide the Service
Purpose limitation: Data is collected for specific, defined purposes and not used beyond those purposes
Minimality: We collect only the minimum data necessary to provide the Service
Information Officer: Contact us at ciphrai.sec@gmail.com for POPIA-related inquiries
Right to complain: You may lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za
3.2 GDPR (European Union)
For users in the European Economic Area, we adhere to GDPR principles:
Legal basis: We process data based on contractual necessity and legitimate interest
Data subject rights: Access, rectification, erasure, portability, and objection rights are fully supported
Data Protection Impact Assessments: Conducted for high-risk processing activities
Breach notification: We will notify affected users and relevant authorities within 72 hours of a confirmed data breach
3.3 General Data Protection Practices
Regardless of your jurisdiction, we apply these standards globally:
Privacy by design and by default
Regular security assessments and code reviews
Principle of least privilege for internal access
Secure software development practices
4. Infrastructure Security
4.1 Hosting
Application hosted on enterprise-grade cloud infrastructure with automatic scaling
HTTPS enforced on all connections
DDoS protection at the infrastructure level
Automatic deployments with zero-downtime updates
4.2 Database Security
Production database uses managed database services with automatic backups
Data-at-rest encryption provided by the database service
Database credentials rotated regularly and never stored in code
Parameterized queries used throughout to prevent SQL injection
4.3 Application Security
Input validation: All user inputs are sanitized and validated server-side
Rate limiting: Applied to all API endpoints to prevent abuse
Detection: Continuous monitoring for anomalous activity
Containment: Immediate isolation of affected systems
Notification: Affected customers notified within 72 hours
Investigation: Full root cause analysis conducted
Remediation: Fixes deployed and security measures strengthened
Reporting: Post-incident report provided to affected parties
7. Your Responsibilities
As a user of Ciphrai Security, you are responsible for:
Maintaining strong, unique passwords for your account
Keeping your email OAuth connections up to date
Reviewing security alerts and acting on recommendations
Only scanning websites and domains you own or are authorized to test
Reporting any suspected security issues to us promptly
8. Data Deletion Requests
You have full control over your data and can delete it at any time:
Instant In-App Deletion: Go to Settings → Delete Account in your dashboard. Confirm with your password and phrase to immediately and permanently erase all company data across all tables.
Manual Request: Alternatively, email ciphrai.sec@gmail.com with the subject "Data Deletion Request" and we will process it promptly.
Note: After deletion, an anonymized cryptographic SHA-256 hash of your email is retained solely to verify free trial eligibility upon re-registration, with no personal identifiers preserved.
9. Contact Us
For questions about our data practices, compliance, or security: