Trust & Security

How we handle your data.

Cicero builds and operates its own products. That means we’re accountable end to end for how customer data is stored, protected, and served.

Where your data lives

Canadian data, Canadian hosting.

Our production infrastructure runs in Canada. Customer data is stored, processed, and backed up within Canadian jurisdiction unless a specific integration explicitly requires otherwise.

Encryption in transit and at rest

All customer data is encrypted in transit with TLS 1.2 or higher. At-rest data is encrypted using industry-standard AES-256 across managed database and object storage.

Least-privilege access

Access to production systems is limited to a small number of engineers, scoped by role, and audited. Multi-factor authentication is required for every account with production access.

Backups and recovery

Automated encrypted backups on a rolling schedule with point-in-time recovery. Restore procedures are documented and tested.

Monitoring and observability

Production systems are monitored 24/7 with automated alerting on availability, error rates, and anomalous access patterns. The team is paged for anything user-facing.

Patching and updates

Managed platforms and third-party dependencies are patched on a defined cadence. Critical security fixes are applied within our documented SLA.

Secrets management

API keys, credentials, and secrets are stored in a managed secrets vault and rotated on schedule. No secrets in source control, ever.

Privacy

How we treat customer data.

We collect the minimum data required to make our products work. We do not sell customer data. We do not share personally identifiable information with third parties except when strictly required to operate a product (for example, sending an email through an email service provider) or when required by law.

Full detail on data collection, retention, and your rights is in our Privacy Policy. For terms of service, see the Terms.

Uptime

Live status.

Our target uptime is 99.9% across our managed products. Live status, service health, and incident history are published at our status page.

Report a vulnerability

Responsible disclosure.

If you believe you’ve found a security issue in one of our products, we appreciate a coordinated disclosure. Please email [email protected] with a description of the issue and steps to reproduce. We’ll acknowledge within one business day and work with you on a fix.

Email [email protected]