Trust Center
Version 1.0. First published 5 August 2026.
This page is informational, not contractual: the binding security commitments are Annex III of the Data Processing Addendum, and nothing on this page reduces them. Where this page and that Annex differ, the Annex is the commitment.
Security overview
The binding version of this list is DPA Annex III; this is the plain-language tour.
In transit. TLS on api.cyan.kiwi and on the site. Traffic between our own services runs inside Google Cloud, and traffic from our platform to the inference machines is encrypted in transit.
At rest. Data at rest in our systems is encrypted with provider-managed keys, including the inference machines’ attached disks.
Credentials. API keys are stored only as hashes; the plaintext key is shown to you once at creation and we cannot recover it. Dashboard authentication is delegated to a managed identity provider, so we hold no password material at all. Service credentials are held in a managed secret store and are never committed to the repository. The inference engines’ endpoints require key authentication.
Access. Our services run under dedicated, least-privilege service identities. Administrative access is scoped to the minimum necessary. Access to production systems, including the inference machines, is need-based and everyone with it is bound by confidentiality.
Change management. Deploys go through a controlled, scripted release process, and privacy-critical serving configuration is verified before release.
Availability and monitoring. We monitor availability continuously with our own probes, for our own operations; clause 7 of the Terms of Service states plainly that we currently offer no contractual availability commitment.
Backups. The customer database is backed up automatically with point-in-time recovery.
Data handling and retention
The customer-facing statement is the Privacy Notice (what we hold and for how long, and its table is the single source for retention periods); the binding processor commitment is clause 3.2 of the Data Processing Addendum.
Zero data retention is the default and is not a setting you have to ask for. The content of your requests and the responses returned to you are not written to any database, spend record or analytics store we operate. The usage ledger stores counts and costs only, never message content.
Two places content can exist outside a single request, both disclosed in clause 3.2 of the DPA: error messages in our infrastructure logs (30 days), and the in-memory prompt cache on the inference machines.
Hosting and processing locations
Our own infrastructure (API, databases, secrets, logs) runs on Google Cloud in the United States. Site hosting rides Google’s global CDN. Inference runs on cyankiwi’s own inference stack, on serverless GPU infrastructure from RunPod and Modal; the canonical statement of who processes what, where is the sub-processor register. We do not currently offer a per-customer choice of region.
International transfers
We are a UK company; our onward transfers land in the United States. EEA-to-UK flows stand on the renewed UK adequacy decisions (19 December 2025, running to 27 December 2031). Our own onward transfers to providers stand, per recipient, on the EU-US Data Privacy Framework with its UK Extension or on Standard Contractual Clauses with the UK Addendum, as recorded on the sub-processor register. The full treatment, including the fallback selections if adequacy lapses and whose transfers are whose, is clause 4 of the Data Processing Addendum.
Model intake
Before a model is listed and served we record, in a written intake register, its upstream repository, its licence and licence URL as verified against the repository’s own LICENSE file, any conditions the licence imposes on downstream users, the modalities we are prepared to declare, and an assessment of whether the model is made or adapted for creating child sexual abuse material or non-consensual intimate imagery. The record predates serving.
Our deployment process requires a licence record for every model before it is served, and a model with no recorded licence is withheld from the public catalog. The customer-facing result is the model catalog.
Inference infrastructure
Inference runs on our own inference stack: engines we deploy, configure and operate on serverless GPU infrastructure, described on the sub-processor register, including the prompt cache we operate.
No engine configuration takes customer traffic before passing our documented internal release gates. Those gates are our internal release criteria, not a contractual commitment.
Reporting a vulnerability
Email security@cyan.kiwi. We read reports and act on what we find.
We welcome research done in good faith and within these rules. We cannot waive criminal liability under the Computer Misuse Act 1990, and we cannot give you permission on behalf of RunPod, Modal, Google, Stripe or Hugging Face, so please do not test their infrastructure.
Rules of engagement: no denial of service or load testing, no accessing or modifying another customer’s data, no social engineering of anyone, and please give us reasonable time to fix an issue before publishing.
Incidents
If we become aware of a security incident affecting customer data we investigate, contain, and notify affected customers under the standard in the Data Processing Addendum (without undue delay after becoming aware). Where the incident is a personal data breach meeting the threshold, we notify the Information Commissioner’s Office within 72 hours where feasible.