Trust Center

Last updated: September 12, 2026

What this page is

An honest summary of how Kyrodata handles data: where it lives, how it is protected, how long we keep it, and where to report a security problem. Every statement here describes what is already running — nothing on this page is a promise about the future. Where we do not have something, we say so.

Where your data lives

The database runs on infrastructure in the São Paulo region, in Brazil. That is where your account, your usage history, and the foreign-trade data we serve are stored. The only processing that leaves the country is the AI model processing described below.

Encryption

Your data is encrypted in transit (HTTPS/TLS) and at rest. Passwords are stored as hashes, never as text. Card data never touches our servers — it is processed directly by our PCI DSS certified payment provider.

Application protections

The application is served with the following controls, which anyone can verify in the response headers:

  • HSTS with preload — the browser refuses to connect without TLS
  • Content-Security-Policy, to contain script injection
  • X-Frame-Options DENY, against clickjacking
  • X-Content-Type-Options nosniff, Referrer-Policy and Permissions-Policy
  • Bot verification on public forms
  • Constant-time comparison on credential checks
  • Edge access control that denies by default when a session is not valid

AI processing

The analysis and support assistants generate answers through a model provider, and that processing happens in the United States. We send only the text of your question and the context of the screen it was asked from — your name, email, company and other account data are not sent, because the question is about commodities, not about you. The provider does not use this content to train models and keeps abuse logs for up to 55 days. The legal basis is performance of the contract (LGPD art. 7, V).

How long we keep it

These are the periods, and they apply today:

  • Analysis assistant conversations: 90 days, then deleted automatically
  • Account data: for as long as the account exists
  • API and MCP server call logs: for as long as the account exists — they support credit metering and abuse investigation
  • Tax records: 5 years, as required by law, even after the account is deleted

Your rights, and how to exercise them

Data subject rights are not just a policy promise here: exporting and deleting your data are implemented as functions of your account, and you run them yourself — no ticket, no waiting for someone to reply. The data protection contact is [email protected].

Who we share with

We share data only with providers necessary to operate the service, in these categories:

  • Hosting and infrastructure
  • Payment processing
  • Product analytics
  • Error monitoring
  • Email delivery
  • Natural language processing for the assistants

We do not publish provider names. If you need that list for a vendor assessment, ask us in writing and we will consider the request case by case.

Audits and testing

Kyrodata went through a third-party penetration test and code audit in July 2026. Findings were handled internally. We do not publish the report or the list of findings: vulnerability detail, even once fixed, is a map for whoever is looking for the next one.

Availability

We publish live availability and incident history, including the MCP server component. We do not promise an SLA number — what we show is what was measured, not what we would like it to be.

Status and incidents

Reporting a vulnerability

If you found a security flaw, write to [email protected]. We acknowledge receipt within 5 business days. Anyone reporting in good faith, who gives us reasonable time to fix the issue, will not face action from us. We do not offer a financial reward — we would rather say that upfront than let you find out after the work is done.

View our security.txt

What we do not have

We do not hold SOC 2 or ISO 27001 certification, and we do not claim to be "compliant with" or "aligned to" them — without an audit, those words mean nothing. We also do not currently offer a standard data processing agreement (DPA) or a contractual SLA commitment. If any of these is a requirement for you to sign, talk to us: the honest answer may be that we do not meet it yet.

Related documents