Trust

Security at Cynact

Buildings are critical infrastructure. We treat them that way. This page summarizes how Cynact protects your data, your devices, and your sites — from the edge node on your wall to the cloud services that orchestrate them.

Encryption in transit

All traffic between your Edge Node, browser, mobile app, and the Cynact cloud is protected with TLS 1.2+ and modern cipher suites. Local protocol traffic on the LAN stays on the LAN.

Multi-factor authentication

Optional MFA on every account, enforceable at the tenant level. Admins can require MFA for all users with privileged roles.

Audit logs

Every command, configuration change, and privileged action is recorded with the actor, target, and timestamp — exportable for incident review and compliance.

Hardened edge hardware

Cynact Edge Nodes are US-built (Protectli, OnLogic). TPM 2.0 is standard; coreboot open-source firmware is available on commercial tiers for verifiable boot integrity.

US data residency

Tenant data, logs, and backups are stored in US-region infrastructure. We do not move customer data outside US data centers.

Granular permissions

Role-based access (Platform Admin, Admin, Manager, Viewer) with per-room and per-device scoping. The principle of least privilege is the default.

Architecture: local-first by design

Cynact runs the control loop on a US-built Edge Node installed at your site. Day-to-day actions — commanding a light, reading a thermostat, opening a lock — happen locally with sub-5 ms response times. Cloud services exist for remote access, multi-site rollups, and AI optimization, and they fail safely: if the internet drops, the building keeps running.

Remote access uses Cloudflare Tunnel, which means we never open inbound ports on your network. Every request is authenticated at the edge of Cloudflare's global network before it reaches your site.

Compliance posture

StandardStatusNotes
NDAA Section 889CompliantEdge hardware sourced from US vendors not on the prohibited-equipment list.
TAA (Trade Agreements Act)CompliantHardware is manufactured in the United States or other designated countries.
SOC 2 Type IIIn progressFormal program underway. We'll publish the report when complete.
US data residencyIn effectProduction data stays in US regions of our cloud providers.

Data handling

We collect only what we need to operate the Service: device state, telemetry, command history, and account information. Audio for the upcoming Voice AI feature is processed by on-device speech-to-text — raw audio never leaves the building. See our Privacy Policy for the full data inventory.

Reporting a security issue

If you believe you've found a vulnerability or you suspect unauthorized access, please email support@cynact.com. We acknowledge reports within one business day. We don't take legal action against good-faith security research.

This page

Version 1.0 · Last updated May 2026. We will revise as our program matures.