What this page is
An honest summary of how Kyrodata handles data: where it lives, how it is protected, how long we keep it, and where to report a security problem. Every statement here describes what is already running — nothing on this page is a promise about the future. Where we do not have something, we say so.
Where your data lives
The database runs on infrastructure in the São Paulo region, in Brazil. That is where your account, your usage history, and the foreign-trade data we serve are stored. The only processing that leaves the country is the AI model processing described below.
Encryption
Your data is encrypted in transit (HTTPS/TLS) and at rest. Passwords are stored as hashes, never as text. Card data never touches our servers — it is processed directly by our PCI DSS certified payment provider.
Application protections
The application is served with the following controls, which anyone can verify in the response headers:
- HSTS with preload — the browser refuses to connect without TLS
- Content-Security-Policy, to contain script injection
- X-Frame-Options DENY, against clickjacking
- X-Content-Type-Options nosniff, Referrer-Policy and Permissions-Policy
- Bot verification on public forms
- Constant-time comparison on credential checks
- Edge access control that denies by default when a session is not valid
AI processing
The analysis and support assistants generate answers through a model provider, and that processing happens in the United States. We send only the text of your question and the context of the screen it was asked from — your name, email, company and other account data are not sent, because the question is about commodities, not about you. The provider does not use this content to train models and keeps abuse logs for up to 55 days. The legal basis is performance of the contract (LGPD art. 7, V).
How long we keep it
These are the periods, and they apply today:
- Analysis assistant conversations: 90 days, then deleted automatically
- Account data: for as long as the account exists
- API and MCP server call logs: for as long as the account exists — they support credit metering and abuse investigation
- Tax records: 5 years, as required by law, even after the account is deleted
Your rights, and how to exercise them
Data subject rights are not just a policy promise here: exporting and deleting your data are implemented as functions of your account, and you run them yourself — no ticket, no waiting for someone to reply. The data protection contact is [email protected].
Who we share with
We share data only with providers necessary to operate the service, in these categories:
- Hosting and infrastructure
- Payment processing
- Product analytics
- Error monitoring
- Email delivery
- Natural language processing for the assistants
We do not publish provider names. If you need that list for a vendor assessment, ask us in writing and we will consider the request case by case.
Audits and testing
Kyrodata went through a third-party penetration test and code audit in July 2026. Findings were handled internally. We do not publish the report or the list of findings: vulnerability detail, even once fixed, is a map for whoever is looking for the next one.
Availability
We publish live availability and incident history, including the MCP server component. We do not promise an SLA number — what we show is what was measured, not what we would like it to be.
Reporting a vulnerability
If you found a security flaw, write to [email protected]. We acknowledge receipt within 5 business days. Anyone reporting in good faith, who gives us reasonable time to fix the issue, will not face action from us. We do not offer a financial reward — we would rather say that upfront than let you find out after the work is done.
What we do not have
We do not hold SOC 2 or ISO 27001 certification, and we do not claim to be "compliant with" or "aligned to" them — without an audit, those words mean nothing. We also do not currently offer a standard data processing agreement (DPA) or a contractual SLA commitment. If any of these is a requirement for you to sign, talk to us: the honest answer may be that we do not meet it yet.