Trust Center

Every trust claim, backed by an artifact

Security, privacy, AI governance, subprocessors and continuity — published with the same source-and-evidence discipline the Regulatory Center uses for law.

Security

Evidence-backed

Security controls are tracked in the same Evidence Vault used across the platform — every control maps to an artifact, an owner and a review date, not a marketing statement.

ApproachRisk-based security program aligned to recognized control frameworks.
EvidenceControl evidence maintained in the Evidence Vault, refreshed on a review cycle.
Incident responseDocumented incident-response process, tested on a regular cadence.

Privacy

GDPR-aware

CYRKIL is designed to be GDPR-aware by design — data minimization, purpose limitation and documented lawful bases across the systems that process personal data.

Data protectionGDPR-aware architecture and processing practices.
Data subject rightsAccess, correction, erasure and portability requests are handled through a documented process.
ContactPrivacy inquiries route through the Contact page’s dedicated form.
Read the Privacy Policy

AI Governance

Governed AI

The same governance model documented for LISA — approved sources only, mandatory disclosure, human handoff on refusal, and a central kill switch — applies to every AI system CYRKIL operates. EU-hosted inference is preferred; a French corporate identity is never presented as implying data sovereignty on its own.

DisclosureAI systems are always identified as AI — never presented as human.
Approved sourcesPublic-facing AI answers only from CYRKIL’s approved source set.
Human handoffLegal, contractual and out-of-scope questions route to a human expert.
OversightA central kill switch and human review govern every deployed AI system.
See LISA’s governance model in action

Subprocessors

Public register

CYRKIL publishes its subprocessor register — the same transparency standard it asks suppliers to meet on the Supply Chain solution.

View the subprocessor register

Continuity

Summary

A summary of CYRKIL’s own business-continuity posture, built on the same Resilience capability offered on the platform.

Continuity planningDocumented continuity plan tied to real service dependencies.
TestingReviewed and tested on a regular cadence.
See the Resilience capability

Vulnerability Disclosure

VDP

Found a security issue? CYRKIL welcomes responsible disclosure through a dedicated intake — see the Contact page’s Vulnerability Disclosure Program tab.

Report a vulnerability

Certifications

Not yet published

CYRKIL does not display certification or attestation badges until they are issued and approved through the internal Claim Register. This section will list current certifications once that evidence exists — no certification is claimed here in the meantime.

Security Pack

On request

Request CYRKIL’s security pack — a structured evidence bundle for procurement and audit review, built from the same Evidence Vault used across the platform.

Request the security pack

Have a specific trust or procurement question?