Built to be trusted with the work.
Capital decisions touch real people and real businesses. We treat the data behind them that way — with deliberate engineering, documented practice, and a compliance posture you can put in front of a regulator.
How we think about it.
Data minimization
We collect only what's needed to score, underwrite, or verify — and we tell you exactly what that is. No silent enrichment, no shadow profiles.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest. Secrets are managed through hardened key stores, never checked into code or logs.
Least-privilege access
Role-based access controls, scoped service accounts, and audit trails on every read and write. Production access is logged and reviewed.
Responsible AI by design
Models are versioned, documented, and monitored for drift and disparate impact. Adverse-action reasoning is generated alongside every decision.
What we actually do.
Hosting & infrastructure
Hosted on SOC 2 compliant cloud infrastructure with regional data residency controls. Network isolation by environment.
Authentication
MFA enforced for all team members. Customer-facing auth supports SSO and rotation policies aligned to NIST 800-63 guidance.
Vulnerability management
Continuous dependency scanning, scheduled penetration testing, and a coordinated disclosure process for security researchers.
Incident response
24/7 on-call rotation, defined severity tiers, and customer notification commitments documented in our DPA.
Vendor management
Sub-processors are reviewed for security posture, data handling, and regulatory fit before integration. Current list available on request.
Compliance posture
SOC 2 certified. Lender compliance reporting, adverse-action handling, and state-level small business lending rules built into the platform.
SOC 2, explained.
What our SOC 2 certification covers and how to get the report.
What does SOC 2 certified mean?
SOC 2 is an independent auditor's confirmation that Cyphr's security program meets the AICPA's Trust Services Criteria. The audit examines how we handle customer data across five categories — security, availability, processing integrity, confidentiality, and privacy — and is the formal baseline most enterprise buyers, lenders, and regulators expect to see before sharing data with a vendor.
What does the audit actually cover?
A licensed third-party CPA firm reviews the controls behind our platform: how data is encrypted and stored, who can access production systems and under what conditions, how changes ship to production, how we monitor for incidents and respond to them, and how we vet sub-processors. The result is an attestation report — not a checklist — describing each control, the evidence reviewed, and the auditor's opinion.
What does this mean for customers?
You can rely on Cyphr to handle borrower and lender data with the same rigor your own security and compliance teams expect. SOC 2 gives diligence teams a recognized artifact to review, shortens vendor onboarding, and means the controls protecting your data have been verified by someone other than us.
Can I see the SOC 2 report and other diligence materials?
Yes. Email security@cyphrai.com for the SOC 2 report, our DPA, sub-processor list, and security questionnaire responses. We typically share under NDA and respond within two business days.
What other compliance does Cyphr support?
Lender compliance reporting and adverse-action handling are built into the platform, along with state-level small business lending rules. Bank connections run through SOC 2-certified providers. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), and every read/write is logged.
Found something? Tell us.
We welcome reports from security researchers and customers. Email security@cyphrai.com with details and a way to reach you. We'll acknowledge within two business days and work with you on a coordinated disclosure timeline.
For the SOC 2 report, data processing agreements, sub-processor lists, or vendor security questionnaires, email security@cyphrai.com and we'll route it the right way.
Doing diligence? We're ready.
Lenders, ESOs, and government partners — request the SOC 2 report, DPA, and sub-processor list and we'll send everything you need under NDA within two business days.