Data Protection
Your client work is encrypted at rest and in transit, and isolated per tenant with row-level security on every table. Backups are encrypted and retained for 30 days.
- AES-256 at rest
- TLS in transit
- Daily backups, 30d retention
The boring version of security: client work belongs to the agency that built it. We encrypt it, log access to it, and commit to never training on it. Here’s exactly how that’s wired up today — and what’s shipping next.
$ cat security/posture.md
# zyan.ai security posture
● tenant_isolation : row-level security · every table
● permission_grid : 38 keys · per member
● realtime_channels : private · tenant-scoped only
● secrets : managed vault · never plaintext
● encryption_at_rest : AES-256
● encryption_in_transit : TLS 1.2+
● custom_domains : DNS-verified · fail-closed
● hosting : US · managed cloud
● activity_ledger : 30d · 1y · custom
● gdpr_ccpa : supported
◐ soc_2_type_ii : roadmap · audit not yet started
○ vuln_disclosure : team@zyan.ai
$ Boring, auditable, boring. That’s the job. Each of these is practiced, not aspirational — a link to our trust packet below spells out the details your compliance team will want.
Your client work is encrypted at rest and in transit, and isolated per tenant with row-level security on every table. Backups are encrypted and retained for 30 days.
Sign-in runs through a hardened auth layer with magic links and seat invites. Every member’s access is governed by a granular permission grid, and client seats only ever see their own portal.
Every workspace is isolated at the database layer with row-level security, realtime channels are private to your tenant, and integration secrets live in a managed vault — never in plaintext.
The operational subprocessor summary below identifies providers and their purposes. Contact us for the current contractual and processing details.
Our on-call rotation is always paged on P0 / P1 events. Customers are notified within 72 hours of any incident affecting their data, as the GDPR asks.
We only process the data you put in your workspace. No training, no selling, no advertising. Delete your workspace and your data is purged within 30 days.
Here’s what’s shipping, when. If a milestone slips, this page updates — nowhere else.
Commits, prompts, seat changes, and credential rotations land in one tenant-scoped ledger your admins can read in the workspace — retained for 30 days by default, a year or longer on contract.
This summary lists the services used for the purposes below. Contact us for the current subprocessor record, contractual details, and processing locations.
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Database, auth, storage, functions | US |
| Vercel | Web hosting & delivery | US |
| Stripe | Billing & payments | US |
| Anthropic | AI model provider (Claude) | US |
| OpenAI | Selected AI model features, where enabled | Provider-managed |
| Moonshot AI | AI model provider (Kimi · opt-in) | US endpoint |
| Gmail, Calendar/Meet, Drive/Sheets, analytics and Ads (authorized connections) | US | |
| DataForSEO | Search & keyword data for SEO tools | US |
The trust packet covers the security architecture, DPA templates, incident-response playbooks, and the full subprocessor table. Share it with your security team and they’ll be quicker to green-light the pilot.