Security & Vulnerability Disclosure
Last updated: September 2026
This is a starting template written in plain language. It is not legal advice. Have it reviewed and adapted by qualified counsel for your jurisdiction before you rely on it.
We take the security of Cadryon and our customers' data seriously. This page describes how we protect data and how to report a vulnerability.
1. How we protect your data
- •Encryption in transit (TLS) for all traffic and encryption at rest for databases, storage, and backups.
- •Tenant isolation — each business's data is separated; access is scoped to the signed-in account's workspace.
- •Least-privilege access controls and audit logging of security-relevant actions.
- •Secrets (API keys, credentials) held in managed configuration, not in source code; customer-provided AI keys are stored encrypted.
- •Automated dependency scanning and static analysis in our build pipeline.
2. Reporting a vulnerability
If you believe you've found a security issue, please email security@cadryon.com with details and steps to reproduce. We welcome good-faith reports and will acknowledge receipt.
Please do not access or modify data that isn't yours, disrupt the service, or run automated scans that degrade availability. Give us reasonable time to remediate before any public disclosure.
3. Our commitment
- •We acknowledge reports promptly and keep you updated on remediation.
- •We triage by severity and aim to patch critical issues within 7–14 days.
- •We will not pursue legal action against researchers acting in good faith under this policy.
4. Scope
This policy covers the Cadryon platform and its official domains. Third-party services we integrate with (for example your connected email or code host) are governed by their own programs.
5. Contact
security@cadryon.com · A machine-readable version is at /.well-known/security.txt.

