Powered by first-party Wentzel.ai connectors — no third-party brokers
Security & Compliance
Tamper-evident audit logging, immutable archive, role-based access, and policy-gated tool execution — built for teams that need to pass an audit, not just claim they could.
Architecture pillars
How Cytra Support handles every AI tool call your team makes.
Tamper-evident audit log
Every event hashes the prior event. Mutating one row breaks the chain — and the nightly validator flags it.
S3 with Object Lock (Compliance mode)
Bucket-level immutability set at creation. Even bucket owners cannot delete locked objects. Configurable retention per plan.
Policy + approval enforcement
JSON-rule policies block or gate calls before they reach the backend. Slack approval workflows for high-risk actions.
Per-workspace isolation
Every MCP call runs against your bearer token, your connections, your policies. No cross-tenant data path.
Hash-chained event timeline
Athena over S3 reconstructs any agent's full action history for forensic review or auditor evidence.
RBAC with 4 roles
viewer, editor, member, admin. Workspace audit visibility scopes to the actor's role.
Retention by plan
| Plan | Hot retention | Archive (Object Lock) | Export |
|---|---|---|---|
| Free | 7 days | none | — |
| Team | 90 days | 1 year (Glacier) | CSV |
| Enterprise | 365 days | 7 years (Compliance mode) | CSV + S3 + Splunk + Datadog |
Compliance status
Where Cytra Support sits today, and where it's headed.
SOC 2 Type II
in process
HIPAA / BAA
template — request via sales (Enterprise)
SEC Rule 17a-4 retention
configurable
GDPR DPA
template — request via sales
PCI DSS
passthrough (Stripe)
Penetration testing
planned
Need a security review or BAA?
Cytra Support is designed for teams that face an auditor. Send us your security questionnaire — we'll respond in two business days.