Legal
Security
Last updated June 2026
Cyna holds some of the most sensitive parts of your business — your proposals, your billing, and your Clients' details — so protecting them is foundational, not an afterthought. This page describes the practices and controls we use to keep your data safe. Security is always evolving, and so is this page.
Infrastructure and hosting
Cyna runs on reputable cloud infrastructure providers that maintain industry certifications (such as SOC 2 and ISO 27001) for their facilities. We use isolated environments, network controls, and continuous monitoring, and we separate our development, staging, and production systems.
Encryption
Data is encrypted in transit using TLS, and data at rest is encrypted using strong, industry-standard algorithms. Secrets and credentials are stored in dedicated, access-controlled secret management rather than in code.
Application security
Security is built into how we ship. We follow secure development practices including code review, automated dependency and vulnerability scanning, and testing before changes reach production. We design with least privilege and defence in depth, and we engage independent testing of the platform as it matures.
Payments
Payments — both your subscription and the amounts you collect from Clients — are processed by Stripe, a PCI-DSS Level 1 certified provider. Card details are sent directly to Stripe and tokenised; we never store full card numbers on our systems. Sensitive payment flows support strong customer authentication where required.
Signature and acceptance integrity
When a Client accepts or signs a proposal, Cyna captures an acceptance record — including details such as the accepted document, signatory information, timestamps, and related metadata — designed to help evidence what was agreed, by whom, and when. These records are retained to support the integrity of your agreements.
Access controls and authentication
Internal access to production systems and customer data follows least-privilege principles, is limited to staff who need it, and is protected by strong authentication. In the product, role-based permissions let you control who on your team and which Clients can see what, and single sign-on (SSO) is available on Enterprise plans. We recommend using a strong, unique password for your account.
Monitoring and incident response
We log and monitor system and application activity to detect and investigate unusual behaviour. We maintain an incident response process to contain and remediate issues, and we will notify affected customers of security incidents as required by law and our agreements.
Tenant separation and backups
Customer data is logically separated so that one account cannot access another's. We take regular backups and maintain business-continuity and recovery practices so we can restore service and data in the event of disruption.
Vendors and subprocessors
We rely on a small set of trusted subprocessors — such as cloud hosting, Stripe for payments, email delivery, analytics, and AI providers — and we review their security practices and bind them to appropriate data-protection terms. See our Privacy Policy for how data is shared.
Privacy and compliance
Our security program supports our privacy commitments, including under the GDPR and similar laws. We offer a Data Processing Agreement for customers who need one, and we are continually strengthening our controls and pursuing recognised compliance standards as we grow. For details on what we collect and why, see our Privacy Policy.
Your data, your control
You own your data. You can export or delete your information, and manage who has access to it, at any time. When you close your account, we delete or anonymise your data in the ordinary course, subject to legal retention requirements.
Reporting a vulnerability
We genuinely want to hear from security researchers. If you believe you've found a vulnerability, please email security@cyna.so with the details and steps to reproduce. We will acknowledge your report, keep you updated, and ask that you give us a reasonable chance to fix the issue before any public disclosure. We won't pursue good-faith research that respects our users' privacy and data.