Trust

Compliance posture

Cynact is designed for environments where compliance matters: federal-adjacent buildings, regulated commercial sites, and utility innovation programs. This page summarizes where we stand against the standards procurement teams ask about.

Compliant
NDAA Section 889

Cynact Edge Nodes are sourced from US vendors not on the Section 889 prohibited-equipment list. Hardware-attestation documentation available for procurement.

Compliant
TAA (Trade Agreements Act)

All Edge Node appliances are manufactured in the United States or other designated countries under TAA. Letters of compliance from Protectli and OnLogic available on request.

Program in progress
SOC 2 Type II

Formal program underway with a third-party auditor. Type I bridging report available to qualified prospects under NDA. Type II report will be published when complete.

In effect
US data residency

Production data, audit logs, and backups are stored in US regions of Cloudflare and Supabase. We do not move customer data outside US data centers.

In effect
US-headquartered hardware vendors

Our Tier 1 hardware vendor (Protectli) and Tier 2/3 vendor (OnLogic) are both US-headquartered and US-assembling, with verified supply chains.

Compliant
CCPA / state privacy laws

Cynact honors data-subject access, deletion, and opt-out requests as required by the California Consumer Privacy Act and analogous state laws. See our Privacy Policy.

For procurement teams

We've helped buyers move Cynact through commercial procurement reviews on the first pass. We can provide, under NDA:

  • Hardware bill of materials with country-of-origin attestations
  • NDAA 889 and TAA letters from our hardware vendors
  • SOC 2 Type I bridge letter and current control summary
  • Sub-processor list (Cloudflare, Supabase, Stripe) and DPAs
  • Incident response and business-continuity overview

Email support@cynact.comwith your project and we'll route you to the right contact.

What's next

Our compliance roadmap is driven by customer demand. Active workstreams include SOC 2 Type II, GDPR readiness for international customers, and HIPAA-adjacent controls for healthcare-facility deployments. We don't pre-announce certifications we haven't earned — when they ship, you'll see them here.

Need a procurement packet?

Tell us your project and we'll send back the documentation your buyer needs.