Privacy Policy
What we collect, what the proxy inspects, how long any of it is kept, and what never leaves your own infrastructure.
Last updated: August 10, 2026
This Privacy Policy explains how Kysira Corporation ("Kysira," "we," "our," or "us") collects, uses, discloses, and protects information in connection with the Kysira website, platform, products, APIs, documentation, and related services (collectively, the "Services").
By using the Services, you agree to the practices described in this Policy. This Policy should be read together with our Terms of Service.
1. Who We Are
Kysira Corporation is the controller of personal information described in this Policy. Where Kysira processes data on behalf of a customer as part of delivering the Services, Kysira acts as a processor and handles that data under the customer's instructions and the applicable customer agreement.
Contact details are in Section 13.
2. Information We Collect
Information you provide. Account registration details (name, business email, company name, password), billing and subscription details, support and sales inquiries, demo requests, and any content you submit through forms.
Information collected automatically. When you visit our websites we collect IP address, browser and device type, operating system, referring URLs, pages viewed, and timestamps through server logs and analytics.
Product telemetry. When you deploy Kysira, the software generates security telemetry — request metadata, classification scores, decision outcomes (shadow or block), latency measurements, and the reason a request was scored the way it was. Where you enable it, this telemetry is sent to the Kysira control plane so it can be displayed in your dashboard.
Cookies and similar technologies. See Section 8.
3. Information We Do Not Want
The Services are built for security telemetry, not for collecting personal data at large. We ask that you do not deliberately send us special categories of personal data (health, biometric, genetic, precise geolocation, government identifiers, or financial account numbers) outside of what is strictly required for billing. Inbound HTTP traffic inspected by the proxy may incidentally contain personal data belonging to your end users; that data is processed transiently for classification and is handled as described in Section 5.
4. How We Use Information
- To provide, operate, secure, and maintain the Services
- To authenticate users and manage accounts, licenses, and entitlements
- To detect, investigate, and prevent attacks, fraud, and abuse
- To improve detection accuracy and reduce false positives
- To provide customer support and respond to inquiries
- To send service, security, and billing notices
- To send marketing communications where permitted, which you can opt out of at any time
- To comply with legal obligations and enforce our agreements
5. Request Inspection and Retention
The Kysira proxy inspects inbound HTTP requests to your application in order to classify them. Classification happens in-process, in memory, on the request hot path.
- Passed requests. Metadata (timestamp, source IP, method, path, score, decision) may be logged. Request bodies are not retained by default.
- Blocked requests. The payload that triggered the decision may be retained so your team can review the event and tune thresholds.
- Retention. Security event data is retained for the retention window configured for your account, after which it is deleted or aggregated into non-identifying statistics.
- Self-hosted deployments. If you run Kysira entirely inside your own infrastructure without connecting to the Kysira control plane, request data stays in your environment and is never transmitted to us.
6. Legal Bases for Processing
Where the EU or UK GDPR applies, we process personal information on the basis of: performance of a contract with you; our legitimate interests in securing, operating, and improving the Services; compliance with legal obligations; and, where required, your consent.
7. How We Share Information
We do not sell personal information and we do not share it for cross-context behavioral advertising.
We share information with:
- Service providers who host, monitor, support, or bill for the Services under contractual confidentiality and security obligations — including our cloud infrastructure provider, Google Cloud Platform
- Professional advisors such as auditors, accountants, and lawyers
- Authorities where required by law, subpoena, or valid legal process
- An acquirer in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy
8. Cookies and Analytics
Our marketing website uses strictly necessary cookies and Google Analytics to understand aggregate traffic patterns. Analytics cookies record pages viewed and approximate location derived from IP address. You can block cookies in your browser or use the Google Analytics opt-out browser add-on. The application at app.kysira.ai uses only cookies and local storage required for authentication and session management.
9. Data Security
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit (TLS) and at rest, least-privilege access controls, isolated production environments, audit logging, and dependency and vulnerability scanning. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. International Transfers
Kysira is based in the United States and information may be processed in the United States and in other countries where our service providers operate. Where required, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
11. Your Rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, and to withdraw consent. Residents of California may request disclosure of the categories of personal information collected and may exercise their rights without discriminatory treatment.
To exercise a right, emailsupport@kysira.ai with "Privacy" in the subject line. We will verify your identity before acting and will respond within the period required by applicable law. You also have the right to lodge a complaint with your local supervisory authority.
12. Children's Privacy
The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
13. Contact Us
Kysira Corporation
251 Little Falls Drive
Wilmington, DE 19808
New Castle County, United States
Email: support@kysira.ai — for privacy inquiries, put "Privacy" in the subject line.
Website: kysira.ai
14. Changes to This Policy
We may update this Policy from time to time. Material changes will be posted here with a revised "Last Updated" date and, where required, communicated to you directly. Continued use of the Services after an update constitutes acceptance of the revised Policy.