Security at Tyqra
This page describes the security principles Tyqra applies to the public website and to any contracted service. Detailed product controls are provided in the applicable service agreement, security schedule, or customer security review.
1. Access and authorization
Tyqra follows least-privilege principles for administrative access. Any production integration must be authorized by the customer and limited to the permissions required for the contracted use case.
2. Data protection
Tyqra uses encrypted transport for supported production connections and applies safeguards appropriate to the sensitivity of stored information. Credentials and customer secrets must not be submitted through the public website or ordinary email.
3. Logging and review
Where a contracted service executes actions, the applicable product configuration and agreement define approval requirements, audit events, retention, and customer access to records. Marketing demonstrations and ROI tools do not execute changes in customer systems.
4. Personnel and incident response
Personnel with authorized access are subject to confidentiality obligations. Tyqra maintains procedures for access review, vulnerability handling, and incident response appropriate to the services in operation.
5. Compliance status
Tyqra does not claim SOC 2 certification or any other independent attestation unless a current report is expressly identified in writing. Customers may request the current security documentation applicable to their proposed service.
6. Subprocessors
The public website does not send visitor content to an AI model. For a contracted production service, Tyqra will provide the then-current subprocessor list before processing customer personal data and will address changes under the applicable agreement and DPA.
7. Report a vulnerability
Send good-faith vulnerability reports to security@tyqra.app. Do not access other users' data, degrade availability, or use social engineering. Include enough detail to reproduce the issue.