1. Proprietary Source Code Ownership
At Cyfendo, we understand that your source code represents your organization's most critical intellectual property. You retain 100% ownership and all intellectual property rights in and to any source code, configuration files, repository metadata, or software artifacts uploaded to or scanned by the Cyfendo platform.
Cyfendo processes customer source code exclusively for the operational purpose of executing security scans, detecting vulnerabilities, and generating suggested remediation patches requested by your account.
2. Zero Model Training & Zero Data Retention (ZDR)
Your code is never used to train, retrain, fine-tune, or improve any public or shared AI/ML foundation models.
- No Foundation Model Ingestion: Customer proprietary code snippets and AST data sent through our agentic reasoning pipeline are governed by enterprise zero-data-retention (ZDR) agreements with upstream AI infrastructure providers.
- Isolated Inference: AI inference calls are stateless and ephemeral. No prompts or source code representations are cached by model providers post-inference.
- No Cross-Customer Contamination: Tenant scan data and AST graphs are strictly partitioned in dedicated tenant namespaces.
3. Ephemeral Sandbox Isolation
To validate potential vulnerabilities without risking your production infrastructure, Cyfendo utilizes isolated, lightweight sandboxes (such as gVisor / microVMs) for dynamic validation where applicable:
- Ephemeral Lifecycle: Analysis sandboxes are created on-demand for the duration of a scan task and immediately destroyed upon task completion.
- Network Isolation: Sandboxes operate in restricted network egress namespaces, preventing unauthorized external data exfiltration.
- Storage Scrubbing: Local scratch disks and ephemeral volume mounts are wiped automatically after scan artifact extraction.
4. Enterprise-Grade Encryption Standards
Cyfendo enforces robust cryptographic protocols to secure data across transit and storage tiers:
- Encryption in Transit: All data transmitted between your development environment, CI/CD runners, browser, and Cyfendo APIs is encrypted using TLS 1.3 (with TLS 1.2 minimum fallback) using strong cipher suites with Perfect Forward Secrecy (PFS).
- Encryption at Rest: Stored findings, vulnerability reports, and cached database records are encrypted at rest using AES-256 with envelope encryption and automated key rotation.
5. Cloud Infrastructure & Sub-processors
Cyfendo operates on enterprise cloud infrastructure (including Google Cloud Platform and AWS) hosted in SOC 2 Type II and ISO 27001 certified data centers. All sub-processors undergo rigorous security vendor risk assessments and are bound by Data Processing Addendums (DPAs) consistent with GDPR, CCPA/CPRA, and industry best practices.
6. Account Data & Operational Telemetry
We collect minimal operational data necessary to deliver and secure the service:
- Account Details: Name, work email address, and organization name for authentication and billing.
- Operational Metrics: Scanned Lines of Code (LOC), scan duration, timestamp, and high-level vulnerability count aggregates for usage billing and capacity planning.
- Security Audit Logs: User sign-in events, API token usage, and scan initiation records for compliance and tenant security auditing.
7. Vulnerability Disclosure Policy (RFC 9116)
We welcome security researchers to inspect our platform and report potential vulnerabilities responsibly. Our security disclosure policy follows the RFC 9116 standard:
- Official Security Contact: security@cyfendo.com
- Canonical Security Specification: https://cyfendo.com/.well-known/security.txt
- Safe Harbor: We commit not to pursue legal action against security researchers who report vulnerabilities in good faith in accordance with responsible disclosure guidelines.
8. Contact Us & Data Processing Addendum (DPA)
For privacy inquiries, GDPR data subject requests, or to execute an enterprise Data Processing Addendum (DPA), please contact our Data Protection Office:
Email: privacy@cyfendo.com / security@cyfendo.com
Entity: Cyfendo Inc., Security & Compliance Office