Trust
Security at Cynact
Buildings are critical infrastructure. We treat them that way. This page summarizes how Cynact protects your data, your devices, and your sites — from the edge node on your wall to the cloud services that orchestrate them.
Architecture: local-first by design
Cynact runs the control loop on a US-built Edge Node installed at your site. Day-to-day actions — commanding a light, reading a thermostat, opening a lock — happen locally with sub-5 ms response times. Cloud services exist for remote access, multi-site rollups, and AI optimization, and they fail safely: if the internet drops, the building keeps running.
Remote access uses Cloudflare Tunnel, which means we never open inbound ports on your network. Every request is authenticated at the edge of Cloudflare's global network before it reaches your site.
Compliance posture
| Standard | Status | Notes |
|---|---|---|
| NDAA Section 889 | Compliant | Edge hardware sourced from US vendors not on the prohibited-equipment list. |
| TAA (Trade Agreements Act) | Compliant | Hardware is manufactured in the United States or other designated countries. |
| SOC 2 Type II | In progress | Formal program underway. We'll publish the report when complete. |
| US data residency | In effect | Production data stays in US regions of our cloud providers. |
Data handling
We collect only what we need to operate the Service: device state, telemetry, command history, and account information. Audio for the upcoming Voice AI feature is processed by on-device speech-to-text — raw audio never leaves the building. See our Privacy Policy for the full data inventory.
Reporting a security issue
If you believe you've found a vulnerability or you suspect unauthorized access, please email support@cynact.com. We acknowledge reports within one business day. We don't take legal action against good-faith security research.
This page
Version 1.0 · Last updated May 2026. We will revise as our program matures.