Security
Client data is treated as infrastructure.
Zyphr uses India-hosted storage, encryption by default, role-based access, and clear audit records so advisory teams can review work with confidence.
Six controls that stay on.
These are platform controls, not optional add-ons.
India data residency
Portfolio, client, and advisory data is stored and processed within Indian jurisdiction.
Encryption at rest
Databases and object storage are encrypted using AES-256. Keys are managed through cloud KMS with automatic rotation.
Encryption in transit
Connections use TLS 1.2+ with modern cipher suites. Internal service traffic uses mTLS.
Role-based access control
Multi-seat plans enforce role boundaries. Advisors can only view and act on assigned clients.
Append-only audit ledger
Advisor actions are recorded in an append-only ledger. Corrections are written as forward-dated reversals.
Tenant isolation
Each advisory practice runs in an isolated data partition to prevent cross-tenant access.
Where your data lives.
Cloud provider
India-region hosting
Database encryption
AES-256 at rest
Transport
TLS 1.2+ and mTLS internal
Key management
Cloud KMS with auto-rotation
Backups
Daily encrypted snapshots, 30-day retention
Uptime target
99.9% SLA
Responsible disclosure.
If you discover a security vulnerability, email security@zyphrsystems.com with the issue, reproduction steps, and supporting evidence.
We acknowledge reports within 48 hours and aim to resolve confirmed issues within 15 business days. Please do not publicly disclose the issue until we have had reasonable time to investigate and remediate.
Security should be quiet and constant.
Every client record is encrypted, every advisor action is recorded, and the review stays inside a controlled workspace.