Security & Trust

Zero-trust security and enterprise resilience.

How Zyfrr architects and enforces zero-trust cloud infrastructure, deterministic enterprise AI guardrails, and cryptographic protections across every digital product we ship.

01Infrastructure & Cloud

Encryption & Network Isolation

All data is encrypted in transit (TLS 1.3) and at rest (AES-256), deployed inside isolated VPC topologies with least-privilege IAM policies.

02AI & Data Boundaries

Private Enterprise AI Guardrails

Proprietary client datasets used in RAG or agentic workflows are strictly isolated and never used to train public foundation models.

03SDLC Governance

Automated SAST, DAST & Audit Trails

Every pull request undergoes automated dependency auditing, static code analysis, peer review and immutable deployment logging.

EFFECTIVE · LAST UPDATED OCTOBER 2026
The Short Version · Executive Summary
  • Zero-trust architecture with end-to-end encryption in transit (TLS 1.3) and at rest (AES-256).
  • Proprietary client datasets used in AI workflows are strictly air-gapped and never used to train public foundation models.
  • Automated CI/CD security gating with SAST, DAST, dependency vulnerability scanning, and signed commits.
  • Responsible vulnerability disclosure program with dedicated security contact and /.well-known/security.txt.

This executive summary provides a high-level overview. The numbered clauses below constitute the formal, legally binding instrument.

1. Zero-trust architectural philosophy

At Zyfrr, security is not a compliance checkbox appended at release; it is the foundational constraint that dictates our software architectures from day one.

We operate on the zero-trust paradigm: "Never trust, always verify." Every service boundary, inter-process communication, API request, and database query must be explicitly authenticated, authorized, and logged regardless of whether it originates within or outside the private network perimeter.

2. Cryptographic standards and data encryption

We enforce industry-standard cryptographic algorithms across all data lifecycles:

  • Data in Transit: All public and internal API endpoints mandate TLS 1.3 with forward secrecy. Deprecated protocols (TLS 1.0, 1.1) and insecure cipher suites are disabled at the edge. We enforce HTTP Strict Transport Security (HSTS) with long-term max-age headers
  • Data at Rest: All production databases, cache layers, message queues, and persistent storage volumes utilize AES-256 encryption. Encryption keys are managed via hardware-isolated Key Management Services (AWS KMS, Google Cloud KMS, or HashiCorp Vault) with automated rotation
  • Deterministic Password Hashing: User credentials utilize Argon2id or bcrypt with high work factors and per-user unique salting

3. Enterprise AI boundaries and LLM data guardrails

When architecting generative AI agents, retrieval-augmented generation (RAG) pipelines, and intelligent workflow automation, we institute strict data privacy boundaries:

  • Zero Training on Customer Data: We utilize enterprise commercial AI agreements (Anthropic Claude Enterprise, Google Cloud Vertex AI, OpenAI Enterprise, and AWS Bedrock) that contractually prohibit the use of client prompt data, documents, or queries for training foundational or public models
  • Vector Store Isolation: Enterprise knowledge bases and vector embeddings (Pinecone, Qdrant, pgvector) are deployed in dedicated tenant namespaces or isolated VPC clusters with row-level security (RLS)
  • Prompt Injection & Egress Filtering: Automated input sanitizers and semantic guardrails prevent prompt injection, unauthorized privilege escalation, and unintended PII leakage in model responses

4. Secure Software Development Lifecycle (SSDLC)

Security governance is integrated directly into our developers’ daily workflows:

  • Branch Protection: Direct pushes to production branches are blocked. All code changes require peer review from senior architects and passing CI test suites
  • Automated SAST & Secret Scanning: Automated static code analysis scans for OWASP Top 10 vulnerabilities, while secret scanners prevent accidental commits of API tokens or credentials
  • Dependency Hygiene: Automated dependency vulnerability scanning (Dependabot and pnpm audit) runs on every build, flagging CVEs before code reaches staging
  • Immutable Audit Logging: All production deployments, infrastructure modifications, and database schema migrations produce immutable audit logs with developer attribution

5. Cloud infrastructure and network topology

Zyfrr deploys production systems across certified tier-one cloud providers (AWS, Google Cloud, Vercel Enterprise) leveraging isolated topologies:

  • Virtual Private Clouds (VPC): Production workloads run inside private subnets without public IP addresses, accessible only through hardened reverse proxies and NAT gateways
  • Web Application Firewall (WAF): Edge layers inspect traffic for SQL injection, cross-site scripting (XSS), rate abuse, and malicious bot activity
  • Least-Privilege Identity & Access Management (IAM): Access to cloud consoles and production clusters mandates multi-factor authentication (MFA) and is restricted to essential engineering personnel

6. High availability, backups, and disaster recovery

We engineer systems to withstand infrastructure failures with zero unrecoverable data loss:

  • Automated Backups: Production databases perform point-in-time recovery (PITR) with continuous transactional logging and geo-redundant snapshot replication
  • Disaster Recovery SLAs: Our target Recovery Point Objective (RPO) is under 15 minutes, with a Recovery Time Objective (RTO) under 2 hours for critical service restoration
  • Weekly Resilience Testing: Backup restores and failover procedures are validated routinely to ensure rapid recovery capabilities

7. Responsible vulnerability disclosure program

We recognize the vital role the independent security research community plays in securing the modern internet. If you discover a potential security vulnerability in any Zyfrr application, we encourage you to report it responsibly:

Security File: Full reporting details and security key definitions are published at https://zyfrr.com/.well-known/security.txt

Email: Write directly to security@zyfrr.com or contact@zyfrr.com with technical details, steps to reproduce, and proof-of-concept payloads

Our Commitment: We acknowledge receipt of verified security reports within 24 hours, provide regular status updates, and pledge not to initiate legal action against researchers acting in good faith who avoid data exfiltration or service disruption

Have questions about this document or want to exercise your rights under the Digital Personal Data Protection Act 2023? Reach our legal and compliance desk at contact@zyfrr.com. A person reads and responds to every request.