Sycora
LEGAL // DATA_GOVERNANCE_&_PRIVACY

Privacy & Data
Sovereignty.

We value technical integrity and client confidentiality. This Privacy Policy details how we collect, protect, and handle your data and source code across all software engineering sprints and advisory engagements.

Policy Version2026.1 SPEC
Zero Data Monetization
256-Bit TLS & At-Rest Encryption
Mutual NDA Ready
100% Client Codebase Ownership
256-Bit
Encryption Standard
TLS in transit & AES at rest
0%
Data Monetization
We never sell or trade data
100%
Code Sovereignty
Full client IP ownership
Zero-Retention
AI Model Training Policy
No public model fine-tuning
Legal Directives

Data Protection &
Compliance Framework.

Last Updated: August 2026 // Production Policy

DATA_COLLECTIONDIRECTIVE_01

1. Information We Collect

We only collect data strictly necessary to scope, engineer, and deploy software services, manage technical communication, and comply with contractual obligations.

Client Inbound & Intake Details

When you initiate a discovery audit, project request, or contact our engineering team, we collect your name, business email, organization name, technical specifications, and project budget parameters.

Compliance Standard

Technical Telemetry & Analytics

We collect non-identifiable technical metadata such as browser version, edge network latency, operating system, and anonymous Core Web Vitals performance benchmarks to optimize delivery speeds.

Compliance Standard

Proprietary Codebases & Credentials

Any repository access, API keys, or database credentials shared for development purposes are stored exclusively in encrypted environment vaults and purged upon project handoff.

Compliance Standard
DATA_USAGEDIRECTIVE_02

2. How We Use Your Information

Your data is used solely to deliver software engineering sprints, provide architectural reviews, and maintain direct client communication.

Service Delivery & Scoping

We use your technical inputs to formulate fixed-milestone sprint scopes, design entity relationship diagrams (ERDs), and engineer production web and mobile software.

Compliance Standard

Communication & Technical Updates

We send sprint progress reports, staging preview URLs, code review briefings, and billing statements directly to your authorized technical contacts.

Compliance Standard

Zero Public Model Training

We do not sell, rent, or monetize your proprietary business data or source code. We never use client codebases or confidential data to train public foundation AI models.

Compliance Standard
DATA_SECURITYDIRECTIVE_03

3. Data Protection & Security Architecture

We employ defense-in-depth security standards to protect your technical assets, databases, and communication channels.

Encryption Protocols

All web traffic and intake forms are encrypted using 256-bit TLS (Transport Layer Security) in transit and AES-256 encryption at rest.

Compliance Standard

Access Control & Mutual NDAs

Access to client infrastructure and sensitive documentation is restricted to senior engineering architects assigned to your sprint, backed by mutual Non-Disclosure Agreements (NDAs).

Compliance Standard

Credential Sanitization

We enforce strict environment variable separation (e.g., Vercel Secrets, AWS KMS, Doppler) to prevent accidental credential leakage in version control.

Compliance Standard
DATA_SHARINGDIRECTIVE_04

4. Third-Party Infrastructure Providers

We only share data with vetted cloud infrastructure and development vendors essential for hosting, deployment, and communication.

Cloud Hosting & Edge CDNs

We utilize industry-standard cloud providers including Vercel, Amazon Web Services (AWS), Supabase, and Cloudflare to host staging environments and route API telemetry.

Compliance Standard

Analytics & Monitoring

We may use privacy-first telemetry tools (such as Sentry, PostHog, or Datadog) to track uptime reliability and error logs without storing personally identifiable information.

Compliance Standard

Legal Disclosures

We only disclose information if required by applicable law, regulatory enforcement, or a binding court order.

Compliance Standard
USER_RIGHTSDIRECTIVE_05

5. Your Rights & Data Sovereignty

You retain full ownership of your data and intellectual property with total rights to access, modify, or permanently purge your records.

Access & Rectification

You may request a copy of all personal and project data we hold regarding your account or update any inaccuracies at any time.

Compliance Standard

Complete Data Erasure (Right to be Forgotten)

Upon milestone completion and final handoff, you can request the permanent deletion of all intake records, staging databases, and temporary environment credentials.

Compliance Standard

Full IP Ownership

All custom source code, design systems, database schemas, and documentation produced during our engagement belong 100% to you upon milestone settlement.

Compliance Standard
POLICY_GOVERNANCEDIRECTIVE_06

6. Policy Updates & Contact

We periodically review this policy to reflect new security standards, legal compliance guidelines, and technical infrastructure updates.

Policy Evolution

Any material changes to our privacy practices will be updated directly on this page with an updated revision date.

Compliance Standard

Direct Security & Privacy Contact

For privacy questions, data deletion requests, or NDA inquiries, contact our security team directly at privacy@sycora.dev.

Compliance Standard
CONFIDENTIAL DISCOVERY PROTOCOL

Need a Mutual NDA Before
Sharing Your Codebase?

We routinely execute bilateral Non-Disclosure Agreements prior to reviewing client repositories, technical PRDs, and database architectures.

Enterprise-Grade Code Protection • Direct Senior Architect Review