Security at Cykanner

We take the security of your data seriously. Here's how we protect it.

Encryption in Transit

All connections use HTTPS, with HSTS enforced in production.

Tenant Isolation

Customer access is scoped to the customer's own organization. Authorized Cykanner personnel may use a time-limited (30-minute), read-only support session to view an organization's dashboard -- starting one creates an audit record of the acting account and time.

Session Security

Sessions use cryptographically secure tokens with SHA-256 hashing. Automatic expiry after 30 days, with a "sign out everywhere" option available at any time.

Passwordless Auth

Magic link authentication eliminates password-related vulnerabilities like credential stuffing.

Domain Verification

DNS TXT verification ensures only authorized users can monitor domains.

Activity Logging

Key account actions, including domain and monitored-email changes and breach acknowledgements, are logged with timestamps and actor information.

Regular Backups

Automated daily database backups, retained for 7 days, with point-in-time restore available within that window.

Report a Security Issue

If you've discovered a security vulnerability, please report it responsibly. We appreciate your help in keeping our users safe.

Email: [email protected]

We aim to respond to security reports within 24 hours and will keep you updated on remediation progress.