Skip to content
Trust

Security Overview

This page summarizes how Zyphon thinks about security for the public site and how visitors can responsibly report concerns.

Last updated August 15, 2026

1. Public site controls

Zyphon uses reasonable safeguards for the public website, including managed hosting, access controls, dependency review, secure deployment practices, and monitoring appropriate for a marketing site.

The public site is intentionally limited in scope. Product systems such as Cognivox may have additional controls, policies, and security documentation.

2. Data minimization

We aim to collect only the information needed to operate the public site, respond to inbound requests, measure performance, and protect against abuse.

Visitors should avoid sending secrets, credentials, proprietary source code, sensitive personal data, or confidential business information through public contact channels unless we have agreed in writing.

3. Responsible disclosure

If you believe you found a vulnerability, please report it through the public contact channels listed on the site with enough detail for us to reproduce and assess the issue.

Do not exploit the issue, access data that is not yours, disrupt services, perform destructive testing, or publicly disclose details before Zyphon has had a reasonable opportunity to investigate.

4. User responsibilities

You are responsible for the devices, browsers, accounts, and networks you use to access Zyphon properties. Keep software updated and protect any credentials used with Zyphon products.

If you interact with a product such as Cognivox, follow that product's security guidance and acceptable use requirements.

5. Incident handling

When we identify a potential security issue, we assess scope, contain risk, remediate where appropriate, and communicate when required by law or when communication is useful to affected users.

This overview is informational and does not create a separate warranty, service-level commitment, or security guarantee.