Security controls
- TLS protects traffic in transit.
- OAuth tokens are encrypted before database storage.
- Server-side secrets are not exposed to browser code.
- Database row-level security and server authorization isolate user records.
- OAuth state and PKCE controls protect connection flows.
- Rate limits and audit records support abuse detection and investigation.
Integration boundaries
Integrations begin read-only. Cyperion asks users or organization administrators to approve provider permissions. Connected emails, messages, files, and records are treated as untrusted data and cannot silently grant instructions or authority to the AI.
Responsible disclosure
If you believe you found a vulnerability, do not access other users’ data or disrupt the service. Submit reproduction steps and impact details through the Cyperion Support Center and select Security report. We will investigate good-faith reports.
Current scope
Cyperion does not claim a security certification that has not been independently awarded. Provider verification, external assessment, penetration testing, and enterprise controls are tracked as production-readiness work.