Security at Cykanner
We take the security of your data seriously. Here's how we protect it.
Encryption in Transit
All connections use HTTPS, with HSTS enforced in production.
Tenant Isolation
Customer access is scoped to the customer's own organization. Authorized Cykanner personnel may use a time-limited (30-minute), read-only support session to view an organization's dashboard -- starting one creates an audit record of the acting account and time.
Session Security
Sessions use cryptographically secure tokens with SHA-256 hashing. Automatic expiry after 30 days, with a "sign out everywhere" option available at any time.
Passwordless Auth
Magic link authentication eliminates password-related vulnerabilities like credential stuffing.
Domain Verification
DNS TXT verification ensures only authorized users can monitor domains.
Activity Logging
Key account actions, including domain and monitored-email changes and breach acknowledgements, are logged with timestamps and actor information.
Regular Backups
Automated daily database backups, retained for 7 days, with point-in-time restore available within that window.
Report a Security Issue
If you've discovered a security vulnerability, please report it responsibly. We appreciate your help in keeping our users safe.
Email: [email protected]
We aim to respond to security reports within 24 hours and will keep you updated on remediation progress.