CyronixCYRONIX SECURITY

Privacy Policy

Last updated: September 1, 2026

1. Introduction

Cyronix Dev & Security (“Cyronix,” “we,” “us”) operates the Cyronix Security Audit platform (the “Service”), which runs passive, authorized website security assessments and generates compliance-mapped reports. This policy explains what information we collect, how we use it, and the choices you have.

2. Information We Collect

We collect information in three categories:

  • Account information — name, email address, password (stored as a salted hash, never in plaintext), organization name, and role.
  • Scan & project data — the target URLs/domains you submit for assessment, scan results, findings, evidence artifacts (e.g. response headers, DNS records, TLS certificate metadata), and any generated reports.
  • Usage & billing information — log data (IP address, browser/device metadata, timestamps), support ticket contents, and — if you subscribe to a paid plan — the payment claim you submit, including the optional UPI transaction reference. Payment itself happens directly in your own bank or UPI app: we never receive or store card numbers, bank credentials, or UPI PINs, and no third-party payment processor is involved.

3. How We Use Information

We use the information above to:

  • Operate, maintain, and secure the Service, including authenticating your account and enforcing rate limits.
  • Run the scan modules you request and generate the resulting findings, scores, and PDF reports.
  • Send transactional email — verification links, password resets, scan-completion and billing notifications.
  • Provide customer support and respond to inquiries you submit.
  • Improve the Service, including diagnosing errors and understanding aggregate usage patterns.
  • Comply with legal obligations and enforce our Terms of Service.

4. Report Generation

Report narratives (executive, business, technical, and management summaries, the risk matrix, prioritized recommendations, and per-finding scenarios) are generated entirely within the Service by our own deterministic report engine, derived directly from your scan's findings. Your scan data is not sent to any third-party artificial-intelligence or large-language-model provider for this or any other purpose. Per-finding scenarios are illustrative descriptions of how a class of weakness could be misused, not claims of confirmed exploitation — the assessment is passive and no exploitation is attempted.

5. Third-Party Service Providers

We share data with a limited set of processors, only as needed to operate the Service: our transactional email provider (Resend) for account and notification emails, our cloud infrastructure and database providers (Vercel, Neon) for hosting and storage, and — only when you run the performance, accessibility, or SEO scan modules — Google's PageSpeed Insights API, which receives the target URL being assessed (never your account details). There is no payment processor: UPI payments settle directly between your bank and ours, and we store only the transaction reference you choose to submit. Report generation happens in-house, so no third-party AI provider receives your scan data. We do not sell your personal information to third parties.

6. Data Retention

We retain account and scan data for as long as your account is active, plus a reasonable period afterward to comply with legal, tax, or security-incident-response obligations. You may request deletion of your account and associated data at any time — see Section 8.

7. Security

We apply industry-standard safeguards, including encryption in transit (TLS) and at rest for sensitive fields, role-based access controls, and audit logging of administrative actions. No system is perfectly secure, and we cannot guarantee absolute security of information transmitted to the Service.

8. Your Rights

Depending on your jurisdiction (including under GDPR and CCPA), you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact us using the details in Section 12; we will respond within the timeframe required by applicable law.

9. Cookies

We use essential cookies only — httpOnly cookies that maintain your authenticated session (access and refresh tokens). We set no analytics or advertising cookies and use no cross-site trackers, so there is nothing to opt out of.

10. Children’s Privacy

The Service is intended for business use and is not directed at individuals under 16. We do not knowingly collect personal information from children.

11. International Data Transfers

Our infrastructure providers may process and store data in regions outside your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers.

12. Changes to This Policy & Contact

We may update this policy from time to time; the “Last updated” date above reflects the most recent revision. Material changes will be communicated via the Service or by email. Questions about this policy or your data can be directed to Cyronix Dev & Security.

Privacy Policy — Cyronix Security Audit