Security
Security at Cayu
Last updated: August 13, 2026
Cayu builds and operates AI systems for businesses where reliability, confidentiality, and control matter.
We apply security practices across our infrastructure, product development, access controls, personnel, and third-party services to protect customer information and the systems that process it.
Data Protection
We use technical and organizational safeguards designed to protect customer and company information.
Our practices include:
- Encryption of data in transit using industry-standard protocols
- Encryption of stored data where appropriate
- Access controls designed to restrict customer and production data to authorized personnel
- Separation of customer information through application and infrastructure access controls
- Secure handling of credentials, API keys, authentication tokens, and other secrets
- Data retention and deletion practices based on operational, contractual, and legal requirements
Customer Content remains the property of the customer. We do not use Customer Content to train public foundation models or models for unrelated customers without explicit written consent.
Identity and Access Management
Access to Cayu systems is granted based on business need and the principle of least privilege.
Security practices include:
- Multi-factor authentication for systems where supported and required
- Individual user accounts rather than shared credentials
- Role-appropriate access to systems and information
- Restricted access to production and customer environments
- Review and removal of access when responsibilities change or a person's relationship with Cayu ends
- Protection of passwords, API keys, tokens, and other authentication credentials
Access to sensitive systems is limited to authorized personnel and contractors who require it to perform their responsibilities.
Infrastructure and Application Security
Cayu applies security controls to the infrastructure and applications used to provide our services.
These practices include:
- Controlled access to production environments
- Secure configuration of infrastructure and cloud services
- Logging and monitoring of relevant application and infrastructure activity
- Protection of sensitive configuration and secrets
- Backup and recovery practices appropriate to the systems being operated
- Separation of development and production activities where appropriate
We periodically review our systems and security practices as our infrastructure and customer requirements evolve.
Secure Software Development
Security is incorporated into Cayu's software development process.
Our engineering practices include:
- Source-code version control
- Code review for material changes
- Controlled deployment of changes to production
- Management of software dependencies
- Identification and remediation of security vulnerabilities
- Testing of application changes before production deployment
- Restricting unauthorized changes to production systems
Engineers are responsible for following Cayu's security and software-development requirements when building or operating Company systems.
Monitoring and Incident Response
Cayu maintains processes for identifying, reporting, investigating, and responding to suspected security incidents.
Personnel are required to promptly report suspected events such as:
- Unauthorized access
- Compromised credentials
- Lost or exposed customer information
- Malware or suspicious activity
- Accidental disclosure of confidential information
- Material vulnerabilities or security-control failures
Security incidents are evaluated, contained, investigated, and remediated based on their nature and severity.
Where required by applicable law or contractual commitments, Cayu will provide appropriate notifications relating to a security or privacy incident.
Personnel Security
Employees and contractors with access to Cayu systems or confidential information are subject to security and confidentiality requirements.
These include:
- Confidentiality obligations
- Information-security responsibilities
- Access granted according to job responsibilities
- Security and privacy awareness requirements
- Requirements to promptly report security incidents
- Return of Company property and removal of system access upon termination or completion of an engagement
Personnel may access customer information only when authorized and necessary to perform their responsibilities.
Third-Party Services
Cayu uses third-party infrastructure and service providers to operate portions of our business and platform.
We evaluate material service providers based on the nature of the service and the information they may process.
Third parties that process confidential or customer information on our behalf are expected to maintain appropriate confidentiality, security, and data-protection safeguards.
Security Governance
Information security and privacy are overseen by Cayu management.
Cayu maintains documented policies and controls covering areas including:
- Information security
- Access control
- Data protection and privacy
- Secure development
- Incident response
- Personnel security
- Vendor and third-party risk
- Business continuity and recovery
Security responsibilities are assigned to designated Company personnel, with management responsible for oversight of material security risks and control effectiveness.
Cayu is implementing and maintaining controls designed to support its SOC 2 compliance program.
Privacy
Additional information about how Cayu collects, processes, retains, and shares personal information is available in our Privacy Policy.
Responsible Disclosure
If you believe you have identified a security issue involving Cayu, please contact us promptly and provide enough information for us to investigate.
Security contact: contact@cayu.ai
Please include “SECURITY” in the subject line for security-related reports.
We appreciate responsible reports that help us maintain the security of Cayu and our customers.