Trust & Security

Security is the product — and the practice

Kyro9 is a security company, so we hold ourselves to the standard we help customers meet. Here's how we handle your data, our compliance posture, and how to report an issue.

Data handling

How we protect your data

Self-hostable by design

Run the entire Kyro9 console — and the AI model — inside your own cloud, so security data never leaves your control. The strongest possible answer to a data-residency requirement.

Least-privilege access

Kyro9 connects to your cloud read-only by default. We ask for the minimum permissions needed and never require write access for core scanning.

Isolation between customers

In our hosted option, every customer runs in a fully isolated environment — not a shared multi-tenant database.

Encryption & secrets

Data is encrypted in transit and at rest; secrets are handled with dedicated protection and never logged.

Compliance

Certifications & posture

We state our status honestly — including what's in progress.

SOC 2 Type II

In progress — report available under NDA on request.

ISO 27001

In progress.

GDPR

Compliant — DPA and sub-processor list available.

Data residency

Self-hosted deployment keeps all data in your own environment.

See our sub-processors, privacy policy and data-processing addendum (available on request).

Report an issue

Responsible disclosure

We welcome reports from security researchers. If you believe you've found a vulnerability in Kyro9, please email [email protected]. Full guidelines are on our responsible disclosure page.

Have a security or compliance question?

Book a call — our team will walk through architecture, data handling and self-hosting in detail.

Book a live demoTalk to us