As a startup handling sensitive documents, we take security seriously. We're implementing enterprise-grade protections from day one, with transparency about our journey.
These are the security measures we have actively implemented and maintain.
All data is encrypted at rest using AES-256 and in transit via TLS 1.3. Encryption keys are managed through AWS KMS with regular rotation.
Role-based access control (RBAC) with principle of least privilege. Multi-factor authentication required for all internal systems.
Hosted on AWS with VPC isolation, private subnets, security groups, and automated vulnerability scanning of all instances.
All code undergoes peer review and automated security scanning. Dependencies are checked for vulnerabilities in every build.
24/7 automated monitoring for anomalies, with alerting through PagerDuty. Log retention for 1 year with tamper-proof storage.
We only store what's necessary. Optional zero-retention mode where documents are processed but never stored on our servers.
We're building toward enterprise compliance standards. Here's where we are and where we're headed.
AWS infrastructure with VPC isolation, encryption at rest and in transit, automated backups, and MFA for all access.
Secure development lifecycle, automated vulnerability scanning, dependency checking, and peer code reviews.
Currently documenting controls and preparing for our first SOC 2 Type I audit. Expected completion Q2 2026.
First third-party penetration test by an accredited security firm to validate our security posture.
Full SOC 2 Type II certification demonstrating sustained security practices over a 6-month observation period.
International information security management certification for global enterprise customers.
We believe you deserve to know exactly how we handle your information.
We provide detailed information about our security practices to prospective customers.
Clear policies on what we collect, how long we keep it, and when we delete it.
Strict limits on who at Ciryana can access customer data and under what circumstances.
Our plan for handling security incidents quickly and transparently.
We'd love to discuss our security practices with you. Reach out for our security whitepaper or to schedule a call with our team.