Security is not claimed. It is evidenced.
Our compliance posture, operational status and security practices: published, dated, and independently audited.
Certified, aligned, and audit-ready
SOC 2 Type II
The platforms and technology we deliver are built on SOC 2 Type II-certified infrastructure. Cyninges' own organizational certification is in progress.
ISO/IEC 27001
Delivered on ISO/IEC 27001-certified technology. Cyninges' own information security management system alignment is underway.
GDPR
Data protection by design and default, with processing records and data-subject rights honoured through this dashboard.
NIS2 Directive
Capability mapping underway for essential-entity clients operating under EU jurisdiction.
CCPA
California consumer rights honoured through the same self-service privacy controls.
EU AI Act
AI-driven portfolio being assessed against transparency and risk-tier obligations.
Threat activity across monitored estates
How we hold ourselves
- ENCEncryption in transit
TLS 1.3 across the site, with a security-reviewed content security policy and standard hardening headers.
- SECCoordinated disclosure
A published, monitored channel for security researchers to report findings in good faith.
- ACCLeast privilege
Access to systems and data is scoped to what each role requires.
- VENVendor review
Portfolio vendors are evaluated before we bring their technology to the region.
Found a vulnerability?
We welcome good-faith security research. Report findings to security@cyninges.com. We don't pursue legal action against researchers acting in good faith and staying within scope.
Our /.well-known/security.txt publishes the current disclosure policy and scope.