Security architecture · grounded 26 June 2026

Specifications,
not promises.

The controls that exist today: a fixed engine configuration, account-level ownership, private assessments, EU storage, team-access records and a defined deletion workflow.

Code 815a6ecSupabase hdabafayniwyotpalwcxAWS eu-west-1Checked 26 June 2026
01 / Purpose

Three guarantees hold the report together.

This page documents controls found in the inspected code and live data service. Where no implemented system supports a claim, that claim is omitted.

Pygar’s security posture starts with a stable engine configuration, direct ownership of assessment data and private-by-default access.

G-01Stability

A fixed engine configuration produces your result. Model changes are deliberate and dated, never silent.

G-02Ownership

You can export or delete your assessment data from your account at any time, without a support queue.

G-03Privacy

Assessment content is private to your account by default and is never shared upline without your consent.

Scope rule. This specification describes only controls that exist in the inspected implementation.
02 / Invitation lifecycle

Team access begins with a controlled invitation.

A manager issues an invitation carrying a single-use claim token, valid for 7 days.

State 01 / PENDING

A single-use invitation has been created.

The invitation carries a unique claim token, valid for 7 days, and can be revoked before it is used.

REVOKEDEXPIRED
On claim, a seat moves from available to allocated and the invitation is consumed and removed. An unclaimed invitation can be revoked by the manager or expires after 7 days. A claim token is single-use and cannot be replayed.
03 / Data handling

Protection, location and retention in one ledger.

These statements describe the inspected implementation without adding application-level controls or retention promises that are not present.

Encryption at rest
Protection
Provider-managed encryption at rest.
Encryption in transit
Protection
TLS in transit.
Data residency
Location
Stored in the EU (AWS eu-west-1).
Active records
Retention
Retained for the lifetime of the account.
Deletion
Retention
A deletion request starts a 30-day grace period; after it ends, records are removed from primary storage.
Team-access events
Access record
Invitations, revocations and consent changes are recorded.
04 / Compliance

State only what the product supports.

The record below is deliberately limited to rights and applicability that are grounded in the current product and its use.

SupportedGDPR

Export, deletion and access rights are honoured for EU and UK data subjects.

Not applicableHIPAA

Pygar.AI is not a Covered Entity and does not process Protected Health Information. Reports are not clinical diagnoses.

Deliberate limit. No Data Protection Officer claim is included because designation has not been confirmed for publication.
05 / Vulnerability disclosure
Responsible reporting route

Security reports should reach a monitored owner.

Report security issues to security@pygar.ai. The inbox is monitored and routes to the responsible engineering owner.

Email security@pygar.ai

Security review

Review the controls that exist today.

This page is intentionally shorter than its predecessor. It describes the current implementation without extending beyond it.