◆ Security

Agency Client Data, Isolated and Encrypted.

The boring version of security: client work belongs to the agency that built it. We encrypt it, log access to it, and commit to never training on it. Here’s exactly how that’s wired up today — and what’s shipping next.

◆ Row-level tenant isolation◆ US-hosted◆ No training on your data
security/posture.md
$ cat security/posture.md

# zyan.ai security posture last_updated: 2026-09-23

 tenant_isolation      : row-level security · every table
 permission_grid       : 38 keys · per member
 realtime_channels     : private · tenant-scoped only
 secrets               : managed vault · never plaintext
 encryption_at_rest    : AES-256
 encryption_in_transit : TLS 1.2+
 custom_domains        : DNS-verified · fail-closed
 hosting               : US · managed cloud
 activity_ledger       : 30d · 1y · custom
 gdpr_ccpa             : supported
 soc_2_type_ii         : roadmap · audit not yet started
 vuln_disclosure       : team@zyan.ai

$ 
◆ Policies

Six Commitments. Plainly Stated.

Boring, auditable, boring. That’s the job. Each of these is practiced, not aspirational — a link to our trust packet below spells out the details your compliance team will want.

Data Protection

Your client work is encrypted at rest and in transit, and isolated per tenant with row-level security on every table. Backups are encrypted and retained for 30 days.

  • AES-256 at rest
  • TLS in transit
  • Daily backups, 30d retention

Access & Identity

Sign-in runs through a hardened auth layer with magic links and seat invites. Every member’s access is governed by a granular permission grid, and client seats only ever see their own portal.

  • 38-key permission grid per member
  • Seat invites + magic links
  • Client seats scoped to their portal

Infrastructure

Every workspace is isolated at the database layer with row-level security, realtime channels are private to your tenant, and integration secrets live in a managed vault — never in plaintext.

  • Row-level security, every table
  • Private tenant realtime channels
  • Secrets in a managed vault

Vendors & Subprocessors

The operational subprocessor summary below identifies providers and their purposes. Contact us for the current contractual and processing details.

  • Documented provider purposes
  • Workspace-controlled integrations
  • Contract details on request

Incident Response

Our on-call rotation is always paged on P0 / P1 events. Customers are notified within 72 hours of any incident affecting their data, as the GDPR asks.

  • 24/7 on-call rotation
  • 72-hour breach notification
  • Post-incident review published

Privacy

We only process the data you put in your workspace. No training, no selling, no advertising. Delete your workspace and your data is purged within 30 days.

  • No model training on your code
  • 30-day deletion on request
  • DPA on file for every customer
◆ Roadmap

Compliance on a Calendar, Not a Wish List.

Here’s what’s shipping, when. If a milestone slips, this page updates — nowhere else.

  1. Shipped
    Tenant isolation & permission grid
    Row-level security on every table, a 38-key member permission grid, and private tenant-scoped realtime channels.
  2. Shipped
    Fail-closed domains & vaulted secrets
    Client-portal custom domains attach only after DNS verification; integration credentials live in a managed vault, never plaintext.
  3. Now
    Trust packet & subprocessor transparency
    Operational subprocessors documented on this page; the detailed trust packet is available on request below.
  4. Next
    SOC 2 readiness, then audit
    Controls are being mapped to SOC 2; a formal Type I / Type II audit engagement is on the roadmap — this page updates when it starts.
◆ Activity ledger

Every Action, on the Record.

Commits, prompts, seat changes, and credential rotations land in one tenant-scoped ledger your admins can read in the workspace — retained for 30 days by default, a year or longer on contract.

  • Agent prompts are logged with the file they touched, not just a timestamp
  • Client seats appear in the ledger but never read it
  • Export on request for your own SIEM or audit file
◆ Subprocessors

Who We Pay to Help Run Zyan.

This summary lists the services used for the purposes below. Contact us for the current subprocessor record, contractual details, and processing locations.

SubprocessorPurposeRegion
SupabaseDatabase, auth, storage, functionsUS
VercelWeb hosting & deliveryUS
StripeBilling & paymentsUS
AnthropicAI model provider (Claude)US
OpenAISelected AI model features, where enabledProvider-managed
Moonshot AIAI model provider (Kimi · opt-in)US endpoint
GoogleGmail, Calendar/Meet, Drive/Sheets, analytics and Ads (authorized connections)US
DataForSEOSearch & keyword data for SEO toolsUS
◆ Trust packet

Want the Long Form?

The trust packet covers the security architecture, DPA templates, incident-response playbooks, and the full subprocessor table. Share it with your security team and they’ll be quicker to green-light the pilot.

  • Security architecture overview (isolation, permissions, secrets)
  • DPA ready for signature
  • Incident-response runbook
  • Security questionnaires answered on request
We’ll reply from team@zyan.ai.