Security architecture · grounded 26 June 2026
Specifications,
not promises.
The controls that exist today: a fixed engine configuration, account-level ownership, private assessments, EU storage, team-access records and a defined deletion workflow.
Three guarantees hold the report together.
This page documents controls found in the inspected code and live data service. Where no implemented system supports a claim, that claim is omitted.
Pygar’s security posture starts with a stable engine configuration, direct ownership of assessment data and private-by-default access.
A fixed engine configuration produces your result. Model changes are deliberate and dated, never silent.
You can export or delete your assessment data from your account at any time, without a support queue.
Assessment content is private to your account by default and is never shared upline without your consent.
Team access begins with a controlled invitation.
A manager issues an invitation carrying a single-use claim token, valid for 7 days.
A single-use invitation has been created.
The invitation carries a unique claim token, valid for 7 days, and can be revoked before it is used.
Protection, location and retention in one ledger.
These statements describe the inspected implementation without adding application-level controls or retention promises that are not present.
| Encryption at rest Protection | Provider-managed encryption at rest. |
|---|---|
| Encryption in transit Protection | TLS in transit. |
| Data residency Location | Stored in the EU (AWS eu-west-1). |
| Active records Retention | Retained for the lifetime of the account. |
| Deletion Retention | A deletion request starts a 30-day grace period; after it ends, records are removed from primary storage. |
| Team-access events Access record | Invitations, revocations and consent changes are recorded. |
State only what the product supports.
The record below is deliberately limited to rights and applicability that are grounded in the current product and its use.
Export, deletion and access rights are honoured for EU and UK data subjects.
Pygar.AI is not a Covered Entity and does not process Protected Health Information. Reports are not clinical diagnoses.
Security reports should reach a monitored owner.
Report security issues to security@pygar.ai. The inbox is monitored and routes to the responsible engineering owner.
Email security@pygar.ai
