Trust Center
Every trust claim, backed by an artifact
Security, privacy, AI governance, subprocessors and continuity — published with the same source-and-evidence discipline the Regulatory Center uses for law.
Security
Evidence-backedSecurity controls are tracked in the same Evidence Vault used across the platform — every control maps to an artifact, an owner and a review date, not a marketing statement.
| Approach | Risk-based security program aligned to recognized control frameworks. |
| Evidence | Control evidence maintained in the Evidence Vault, refreshed on a review cycle. |
| Incident response | Documented incident-response process, tested on a regular cadence. |
Privacy
GDPR-awareCYRKIL is designed to be GDPR-aware by design — data minimization, purpose limitation and documented lawful bases across the systems that process personal data.
| Data protection | GDPR-aware architecture and processing practices. |
| Data subject rights | Access, correction, erasure and portability requests are handled through a documented process. |
| Contact | Privacy inquiries route through the Contact page’s dedicated form. |
AI Governance
Governed AIThe same governance model documented for LISA — approved sources only, mandatory disclosure, human handoff on refusal, and a central kill switch — applies to every AI system CYRKIL operates. EU-hosted inference is preferred; a French corporate identity is never presented as implying data sovereignty on its own.
| Disclosure | AI systems are always identified as AI — never presented as human. |
| Approved sources | Public-facing AI answers only from CYRKIL’s approved source set. |
| Human handoff | Legal, contractual and out-of-scope questions route to a human expert. |
| Oversight | A central kill switch and human review govern every deployed AI system. |
Subprocessors
Public registerCYRKIL publishes its subprocessor register — the same transparency standard it asks suppliers to meet on the Supply Chain solution.
View the subprocessor registerContinuity
SummaryA summary of CYRKIL’s own business-continuity posture, built on the same Resilience capability offered on the platform.
| Continuity planning | Documented continuity plan tied to real service dependencies. |
| Testing | Reviewed and tested on a regular cadence. |
Vulnerability Disclosure
VDPFound a security issue? CYRKIL welcomes responsible disclosure through a dedicated intake — see the Contact page’s Vulnerability Disclosure Program tab.
Report a vulnerabilityCertifications
Not yet publishedCYRKIL does not display certification or attestation badges until they are issued and approved through the internal Claim Register. This section will list current certifications once that evidence exists — no certification is claimed here in the meantime.
Security Pack
On requestRequest CYRKIL’s security pack — a structured evidence bundle for procurement and audit review, built from the same Evidence Vault used across the platform.
Request the security pack