Skip to main content
Powered by first-party Wentzel.ai connectors — no third-party brokers

Security & Compliance

Tamper-evident audit logging, immutable archive, role-based access, and policy-gated tool execution — built for teams that need to pass an audit, not just claim they could.

Architecture pillars

How Cytra Support handles every AI tool call your team makes.

Tamper-evident audit log
Every event hashes the prior event. Mutating one row breaks the chain — and the nightly validator flags it.
S3 with Object Lock (Compliance mode)
Bucket-level immutability set at creation. Even bucket owners cannot delete locked objects. Configurable retention per plan.
Policy + approval enforcement
JSON-rule policies block or gate calls before they reach the backend. Slack approval workflows for high-risk actions.
Per-workspace isolation
Every MCP call runs against your bearer token, your connections, your policies. No cross-tenant data path.
Hash-chained event timeline
Athena over S3 reconstructs any agent's full action history for forensic review or auditor evidence.
RBAC with 4 roles
viewer, editor, member, admin. Workspace audit visibility scopes to the actor's role.

Retention by plan

PlanHot retentionArchive (Object Lock)Export
Free7 daysnone
Team90 days1 year (Glacier)CSV
Enterprise365 days7 years (Compliance mode)CSV + S3 + Splunk + Datadog

Compliance status

Where Cytra Support sits today, and where it's headed.

SOC 2 Type II
in process
HIPAA / BAA
template — request via sales (Enterprise)
SEC Rule 17a-4 retention
configurable
GDPR DPA
template — request via sales
PCI DSS
passthrough (Stripe)
Penetration testing
planned

Need a security review or BAA?

Cytra Support is designed for teams that face an auditor. Send us your security questionnaire — we'll respond in two business days.