← Back to portal
KYRA · Trust Center

Security & data protection

How KYRA protects your data and your customers’ data — and our answers to the questions vendor security reviews most often ask.

Last updated: 23 August 2026  ·  Owner: Kyra.bot Ltd  ·  Scope: the KYRA platform (MSP portal, bots and APIs)
This page summarises KYRA’s security posture and doubles as a pre-filled response to the common vendor security questionnaires — SIG Lite and the Cloud Security Alliance CAIQ. MSPs are welcome to share it with their own clients’ procurement or security teams. For a formally completed SIG Lite / CAIQ workbook, a penetration-test summary, or a signed DPA, contact us at the address in the footer.
This is a factual description of controls that are implemented in the product today. It is not a claim of third-party certification; where a control is partial or planned we say so.

1. Data encryption

2. Access control & authentication

3. Application security

4. Infrastructure, hosting & data residency

5. Data protection, privacy & sub-processors

KYRA processes personal data under UK GDPR as a processor acting on the MSP’s instructions. International transfers are covered by the UK IDTA / EU Standard Contractual Clauses.

Sub-processorPurposeRegion / safeguard
Microsoft AzureHosting & storageUK South
Azure OpenAIDefault AI inference & embeddingsUK South
Azure Communication ServicesTelephony (numbers, calls, SMS)UK
Azure AI (Voice Live)Real-time voice (STT/TTS)EU · Sweden Central
OpenAI / AnthropicOptional AI — Enterprise bring-your-own key onlyUSA · SCCs
StripeBilling & paymentsUSA · SCCs · PCI DSS L1
CloudflareEdge / DNSGlobal edge
BrevoTransactional emailEU

The authoritative, dated sub-processor list and the full privacy notice live at /privacy.html.

6. AI & customer-data usage no training

7. Business continuity, backup & retention

8. Logging, monitoring & audit

9. Vulnerability & change management

10. Questionnaire mapping & contact

The sections above map to the core domains of SIG Lite and the CSA CAIQ: encryption (§1), access control / IAM (§2), application & interface security (§3), datacentre & infrastructure (§4), data governance / privacy & supply chain (§5–6), business continuity & data retention (§7), logging & monitoring (§8), and threat & vulnerability management (§9).

For a completed SIG Lite / CAIQ workbook, a signed Data Processing Agreement, or a security review call, contact [email protected].