Security & trust

Clear boundaries.
Evidence behind the claims.

Security is an operating responsibility. This page distinguishes website controls, product design objectives and assurances that have not yet been established.

Website foundation

Small, controlled public surface.

The rebuilt pages use locally hosted fonts and scripts. Security headers restrict resource loading, framing and browser capabilities. This reduces avoidable third-party dependencies.

Measurement

Useful counts, not visitor surveillance.

Analytics is disabled in this build. The prepared measurement layer requires explicit consent, collects allowlisted events only, and excludes form text, email addresses and session replay.

Enquiries

Start without confidential data.

The form asks for your goal and contact details. Do not include sensitive project documents. The enquiry form confirms acceptance when the service returns a successful response. Email remains available if the service cannot be reached.

Product direction

Access and evidence are separate controls.

Tenant isolation, controlled permissions, traceable changes and tested recovery are engineering requirements. A public demonstration is not evidence that every production control is complete.

Assurance status: This website does not claim SOC 2 or ISO 27001 certification, a completed independent penetration test, or a guarantee of security. Scope-specific evidence should be reviewed before an enterprise engagement.

Responsible disclosure

Found a security issue?

Contact hello@kyroq.com with a concise description and safe reproduction steps. Do not send secrets or personal data, and do not access records that are not yours.

Report an issue

Before a production engagement

  • Agree the data, access and processing scope.
  • Review applicable security and privacy evidence.
  • Define responsibilities, retention and incident contacts.
  • Confirm recovery and release controls for the service used.