◆ Security

The boring version of security.

Client work belongs to the agency that built it. We encrypt it, log access to it, and commit to never training on it. Here’s exactly how that’s wired up today — and what’s shipping next.

◆ SOC 2 Type II · target Q3 2026◆ US-East · EU on requestRequest the trust packet ↓
security/posture.md
$ cat security/posture.md

# zyan.ai security posture last_updated: 2026-04-27

 soc_2_type_ii         : in_progress · target Q3 2026
 hipaa_baa             : on_request · Enterprise
 gdpr                  : supported
 ccpa                  : supported
 sso_saml              : Agency+
 scim_provisioning     : Enterprise
 encryption_at_rest    : AES-256 · per-tenant keys
 encryption_in_transit : TLS 1.3
 default_region        : us-east-1
 eu_region             : on_request · Enterprise
 audit_log_retention   : 30d · 1y · custom
 pentest               : annual · last 2026-02
 vuln_disclosure       : security@heckofawebsite.com

$ 
◆ Policies

Six commitments. Plainly stated.

Boring, auditable, boring. That’s the job. Each of these is practiced, not aspirational — a link to our trust packet below spells out the details your compliance team will want.

Data protection

Your client work is encrypted at rest with per-tenant keys and in transit with TLS 1.3. Backups are encrypted, immutable, and retained for 30 days.

  • AES-256 at rest
  • TLS 1.3 in transit
  • Daily backups, 30d retention

Access & identity

SSO on Agency+ with Okta, Azure AD, Google Workspace, OneLogin, and JumpCloud. SCIM provisioning and role-based access on Enterprise.

  • SSO / SAML · Agency+
  • SCIM · Enterprise
  • Role-based workspace scopes

Infrastructure

Compute runs in isolated containers on AWS US-East by default. Enterprise customers can pin workloads to a dedicated region with single-tenant pools.

  • AWS US-East default
  • Dedicated regions on Enterprise
  • Container-level isolation

Vendors & subprocessors

We use a small, audited set of subprocessors. Each is DPA-bound and reviewed annually. A full list and purpose is below.

  • Documented subprocessor list
  • Annual vendor reviews
  • DPA on file for each

Incident response

Our on-call rotation is always paged on P0 / P1 events. Customers are notified within 72 hours of any incident affecting their data, as the GDPR asks.

  • 24/7 on-call rotation
  • 72-hour breach notification
  • Post-incident review published

Privacy

We only process the data you put in your workspace. No training, no selling, no advertising. Delete your workspace and your data is purged within 30 days.

  • No model training on your code
  • 30-day deletion on request
  • DPA on file for every customer
◆ Roadmap

Compliance on a calendar, not a wish list.

Here’s what’s shipping, when. If a milestone slips, this page updates — nowhere else.

  1. Q1 2026
    SOC 2 Type I
    Report available on request. Scope: workspace compute + billing.
  2. Q2 2026
    Public launch
    June 1st · SSO hardened, SCIM beta, EU region opt-in.
  3. Q3 2026
    SOC 2 Type II
    Full Type II report with 12 months of evidence. Target August 2026.
  4. Q4 2026
    ISO 27001 roadmap
    Gap analysis starts Q4. HIPAA BAA available on request in parallel.
◆ Subprocessors

Who we pay to help run zyan.

Each subprocessor is on a current DPA, reviewed annually, and scoped to the purpose below. Want the full trust packet including a sub-SLA table? Request it below.

SubprocessorPurposeRegion
Amazon Web ServicesCompute, storage, networkingus-east-1 (EU on request)
CloudflareCDN, DDoS protection, WAFGlobal edge
VercelMarketing site hostingUS / EU
ResendTransactional emailUS
StripeBilling & subscription managementUS
Anthropic · OpenAI · GoogleAI model providers (opt-in per workspace)US
SentryError monitoring (scrubbed)US
BetterStackUptime monitoring & status pageEU
◆ Trust packet

Want the long form?

The trust packet covers pen-test results, DPA templates, incident-response playbooks, and the full subprocessor SLA matrix. Share it with your security team and they’ll be quicker to green-light the pilot.

  • Latest pen-test executive summary
  • DPA + SCCs ready for signature
  • Incident-response runbook
  • Answered security questionnaires (CAIQ / SIG-lite)
We’ll reply from security@heckofawebsite.com.