Sykik
SecurityPricing
Request early access
Back to sykik.ai

Technical and Organisational Measures

Version 1.0 — 1 August 2026Effective 1 August 202610 sectionssykik.ai/security

The measures Sykik maintains pursuant to Article 32 GDPR. This document is available as Annex III of Sykik's Data Processing Agreement and is referenced in Section 14 of the Privacy Policy. In case of any inconsistency, the version published here shall prevail.

One agreement, four documents — plus the Imprint
Terms of ServicePrivacy PolicyData Processing AgreementSecurity · TOMsImprint

The Terms of Service incorporate the Privacy Policy and the DPA by reference. The measures published on the Security page are Annex III of the DPA. The Imprint is the disclosure required by § 5 ECG and is not part of the agreement.

Sections
  1. 1Pseudonymisation and encryption
  2. 2Confidentiality
  3. 3Integrity
  4. 4Availability and resilience
  5. 5Ability to restore access
  6. 6Testing and evaluation
  7. 7Data minimisation
  8. 8Physical security
  9. 9Organisational measures
  10. Document control
SECTION 1

Pseudonymisation and Encryption

Encryption in transit
TLS 1.3 enforced on all public endpoints and internal service-to-service communication
Encryption at rest
AES-256 via Google Cloud Platform (GCP) managed keys. Customer-Managed Encryption Keys (CMEK) under evaluation for customer-specific workloads
Secrets management
All API keys, OAuth tokens, and database credentials stored in GCP Secret Manager with access audit logging
Pseudonymisation
Analytics and usage data pseudonymised where technically feasible; production Customer Data not pseudonymised as it is required in identifiable form for the AI processing the Controller directs
SECTION 2

Confidentiality

Access control model
Role-Based Access Control (RBAC) with least-privilege principle. Four tiers: viewer, developer, operator, administrator
Authentication
Multi-factor authentication (MFA) enforced for all human access to production infrastructure. Customer authentication via Clerk (OAuth 2.0 / SAML SSO)
Personnel
All personnel with access to production systems subject to confidentiality agreements
OAuth scope minimisation
Per-user, per-integration OAuth grants. Gmail, Calendar, Drive, and Chat scopes requested separately — users authorise only what they need
Human access to customer data
No routine human access. Access permitted only: (a) with customer's affirmative agreement for specific items, (b) for security incident investigation, (c) to comply with legal obligations, or (d) in aggregated/anonymised form
SECTION 3

Integrity

Audit logging
Immutable audit logs enabled on all production GCP services (Cloud Audit Logs). Admin activity, data access, and system events logged
Change management
All production changes ar
Code integrity
All commits signed. Dependency scanning (Dependabot / Snyk equivalent) on all repositories
Data integrity
Checksums verified on backup operations. Database write-ahead logging (WAL) enabled
SECTION 4

Availability and Resilience

Infrastructure
Google Cloud Platform, europe-west regions. Multi-AZ deployment with automatic failover
Backup policy
Daily encrypted snapshots, retained for 35 days. Cross-region replication for disaster recovery
Target RTO (planned)
To be defined (GCP managed infrastructure — availability targets set post-GA)
Target RPO (planned)
To be defined (daily backups, cross-region replication under evaluation)
Incident response
Documented runbook with escalation paths. Target: containment within 1 hour, notification to affected Controllers within 48 hours of confirmed breach
DDoS protection
Cloudflare edge network with DDoS mitigation
SECTION 5

Ability to Restore Availability and Access

Backup restoration
Tested annually with documented results
Disaster recovery plan
Documented, reviewed annually, and updated when infrastructure changes
Rollback capability
All deployments support single-command rollback via Terraform state versioning
SECTION 6

Regular Testing, Assessment, and Evaluation

Penetration testing
Annual external penetration test by an independent provider (planned — not yet conducted)
Vulnerability scanning
Automated vulnerability scanning on all container images and dependencies
Compliance audit
SOC 2 Type 2 audit planned. Internal readiness assessment conducted July 2026
Continuous monitoring
GCP Cloud Monitoring with alerting on anomalous access patterns, resource utilisation, and error rates
SECTION 7

Data Minimisation

Collection limitation
Only data categories necessary for the Service are collected (see Privacy Policy, Section 3)
OAuth scope granularity
Per-user, per-service OAuth grants ensure only explicitly authorised data is accessible
AI inference — Zero Data Retention
ZDR enabled on OpenRouter API calls where offered. Prompt/context data not persisted beyond the request-response cycle
Retention enforcement
Automated deletion policies per data category (see Privacy Policy, Section 12). No data retained beyond stated periods
SECTION 8

Physical Security

Sykik does not operate its own physical data centres. All production infrastructure runs on Google Cloud Platform.

Data centre certifications (GCP)
ISO 27001, SOC 1/2/3, PCI DSS, FedRAMP
Physical access control
GCP data centres: biometric access controls, 24/7 security personnel, video surveillance. Sykik personnel have no physical access to GCP facilities
Device security
All employee devices: full-disk encryption, screen lock enforced, mobile device management (MDM)
SECTION 9

Organisational Measures

Data Protection Officer
Hermann Wagner, sykik-privacy@sykik.ai — appointed under Art. 37 GDPR
Privacy by design / default
Data protection impact assessments (DPIAs) conducted for new features involving personal data. Privacy review in product development lifecycle
Staff training
Data protection and security training at onboarding, refreshed annually
Sub-processor management
Due diligence assessment before engagement. DPA required with every sub-processor. 14-day prior notice to Controllers for additions/changes
Policy review cycle
Privacy policy and TOMs reviewed at least annually, or upon material infrastructure/processing changes
Breach notification
Internal runbook targeting 72-hour notification to the Austrian DSB (Art. 33) and 48-hour notification to affected Controllers
PREAMBLE

Document Control

Version
1.0
Effective date
1 August 2026
Last reviewed
1 August 2026
Next review
1 August 2027 or upon material change
Classification
Public
Owner
Hermann Wagner, DPO
Published at
sykik.ai/security

This document is available as Annex III of Sykik's Data Processing Agreement and is referenced in Section 14 of Sykik's Privacy Policy. In case of any inconsistency, the version published at sykik.ai/security shall prevail.

The rest of the legal section
Terms of ServiceThe agreement that governs access to and use of Sykik.Privacy PolicyHow Sykik handles your data, and the rights you have over it.Data Processing AgreementThe Article 28 processor terms, the sub-processor register and the annexes.Impressum — Legal DisclosureWho operates sykik.ai, and who is answerable for it.
Sykik

AI agents that do the work — on the model you choose.

Product
  • What Sykik delivers
  • Chatbot vs. Sykik
  • How it works
  • Control & security
  • FAQ
Resources
  • Blog
  • Pricing
  • Security
Company
  • Contact
  • Imprint
Legal
  • Privacy
  • Terms
  • DPA
© 2026 Sykik. All rights reserved.Logos provided by Logo.dev