Security

Client data is treated as infrastructure.

Zyphr uses India-hosted storage, encryption by default, role-based access, and clear audit records so advisory teams can review work with confidence.

Six controls that stay on.

These are platform controls, not optional add-ons.

India data residency

Portfolio, client, and advisory data is stored and processed within Indian jurisdiction.

Encryption at rest

Databases and object storage are encrypted using AES-256. Keys are managed through cloud KMS with automatic rotation.

Encryption in transit

Connections use TLS 1.2+ with modern cipher suites. Internal service traffic uses mTLS.

Role-based access control

Multi-seat plans enforce role boundaries. Advisors can only view and act on assigned clients.

Append-only audit ledger

Advisor actions are recorded in an append-only ledger. Corrections are written as forward-dated reversals.

Tenant isolation

Each advisory practice runs in an isolated data partition to prevent cross-tenant access.

Where your data lives.

Cloud provider

India-region hosting

Database encryption

AES-256 at rest

Transport

TLS 1.2+ and mTLS internal

Key management

Cloud KMS with auto-rotation

Backups

Daily encrypted snapshots, 30-day retention

Uptime target

99.9% SLA

Responsible disclosure.

If you discover a security vulnerability, email security@zyphrsystems.com with the issue, reproduction steps, and supporting evidence.

We acknowledge reports within 48 hours and aim to resolve confirmed issues within 15 business days. Please do not publicly disclose the issue until we have had reasonable time to investigate and remediate.

Security should be quiet and constant.

Every client record is encrypted, every advisor action is recorded, and the review stays inside a controlled workspace.