Security
1. Overview
Pyvorin is committed to protecting the security of our customers' data and our infrastructure. This page outlines our security practices, certifications, and the measures we take to safeguard your information.
2. Infrastructure Security
- All production infrastructure runs on isolated virtual private clouds (VPCs) with strict network segmentation.
- Firewalls restrict inbound and outbound traffic to essential ports and IPs only.
- All data at rest is encrypted using AES-256.
- All data in transit is encrypted using TLS 1.3.
3. Access Control
- Multi-factor authentication (MFA) is required for all internal administrative access.
- Principle of least privilege: employees only have access to systems required for their role.
- All access is logged and audited regularly.
4. Application Security
- Regular dependency scanning and automated vulnerability alerts.
- Input validation, CSRF protection, and XSS mitigation on all user-facing endpoints.
- Rate limiting and abuse detection on public APIs.
5. Incident Response
We maintain a documented incident response plan. In the event of a confirmed security breach affecting customer data, we will notify affected users within 72 hours in accordance with GDPR requirements.
6. Reporting Security Issues
If you discover a vulnerability in our platform, please contact us immediately at security@pyvorin.com. We operate a responsible disclosure policy and appreciate your assistance in keeping Pyvorin secure.
This is a draft security statement. It MUST be reviewed by a qualified security professional and legal counsel before publication.
Version 1.0.0 | Effective May 1, 2026 | Requires professional legal review.