Security at CyrForge
Last Updated: August 23, 2026
CyrForge is operated by Elemental Genius LLC. This page describes how we protect the data you keep in CyrForge, and how to reach us if you believe you have found a security problem.
We have written this page to be accurate rather than impressive. Where we have not yet completed a control, we say so.
Reporting a Vulnerability
If you believe you have found a security vulnerability in CyrForge or on cyrforge.com, please report it to us directly.
Email: [email protected] — please put "Security" in the subject line.
We ask that you:
- Give us a reasonable description of the issue and the steps to reproduce it
- Allow us a reasonable opportunity to investigate and remediate before public disclosure
- Avoid privacy violations, data destruction, service degradation, and any access to accounts that are not your own
If you follow the guidance above, we will not pursue or support legal action against you for your research. We will acknowledge your report, keep you informed of our progress, and credit you if you would like to be credited.
A machine-readable contact is published at /.well-known/security.txt in accordance with RFC 9116.
Hosting and Infrastructure
- The CyrForge application runs on Google Cloud Platform / Firebase App Hosting.
- Application data is stored in Cloud Firestore.
- The marketing site at cyrforge.com is a static site served behind Cloudflare, which terminates TLS at the edge.
- We do not operate our own datacenters or physical infrastructure. Physical and environmental security is inherited from Google Cloud and Cloudflare.
Encryption
- In transit: all traffic to CyrForge and cyrforge.com is served over HTTPS/TLS. TLS is terminated at the edge, and internal hops do not leave the provider network.
- At rest: data stored in Cloud Firestore is encrypted at rest by Google Cloud using AES-256, managed by Google's key management infrastructure.
Authentication and Access Control
- Authentication is handled by Google Identity Platform, supporting email/password and Google Sign-In. We do not implement custom authentication or password storage.
- Passwords, where used, are stored and verified by Identity Platform. Elemental Genius LLC never sees or stores plaintext passwords — they are never sent to our servers at all, because your browser authenticates directly with Identity Platform.
- Passwords must be at least 12 characters. This is enforced by Identity Platform, not merely suggested by the signup form.
- Two-factor authentication is available on every account and can be enabled under Settings. CyrForge supports time-based one-time passwords (TOTP) from any authenticator app, including Google Authenticator, Microsoft Authenticator, 1Password, Bitwarden, and Authy. Enabling it requires a verified email address.
- We deliberately do not offer SMS as a second factor. SMS codes can be intercepted by phishing pages and by SIM-swap attacks, which makes them meaningfully weaker than an authenticator app.
- Sign-in, account creation, and password reset are protected by Google reCAPTCHA Enterprise, which blocks requests that appear to be automated. The check is invisible — there is no puzzle to solve. reCAPTCHA never receives your password or any of your CRM data.
Google and Gmail Access
The Gmail integration is not currently available — it is a planned feature, disabled in the product, and CyrForge requests no Gmail permissions from anyone today. Google Sign-In (basic profile) is separate and unaffected.
As designed for its eventual launch: connecting a Google account will be optional, requesting openid, email, and two restricted Gmail scopes — gmail.readonly and gmail.compose — so the assistant can search your mailbox, read a message you have asked about, summarize correspondence, and prepare draft replies. No Drive, Calendar, or Contacts access. The mailbox is read only during a request you initiate; there is no background sync, and no message content is stored on our systems. CyrForge writes drafts but does not send email on your behalf — the assistant reads mail from people you may not know, so allowing it to both read untrusted input and send messages would let a stranger attempt to steer it into forwarding your correspondence; every outbound message passes through you. Gmail content will be processed only by Google Gemini — a restriction enforced in code, not by policy alone. See the Privacy Policy for the full disclosure.
AI Features
AI features process your data only when you invoke them, and their inputs are not retained. Business-card photos you scan are OCR'd by Google Cloud Vision and processed in memory, never stored. Voice dictation runs on your browser's built-in speech recognition — CyrForge never receives audio, only the text transcript. The weekly digest sends aggregate numbers, not records. The default provider is Google Gemini via Vertex AI under Google Cloud's enterprise terms, which prohibit training on customer content; an Anthropic, OpenAI, or Gemini key you supply routes those features to your chosen provider instead.
Data Isolation
Every account's data is stored under its own user path (users/{uid}/...) and enforced by server-side Firestore security rules. A signed-in user cannot read or write another account's records; isolation is enforced by the datastore, not by application code alone.
Paid-feature access is granted through backend-managed entitlements. Stripe's webhook is received by a server-side endpoint that verifies the webhook signature before acting on it, and the resulting entitlement record is written by a privileged backend credential to a location that no browser client can write. Access is gated on that server-written record rather than on anything the client supplies.
Payments
Subscription billing is processed by Stripe, Inc. Card details are collected directly by Stripe. Elemental Genius LLC does not receive, process, or store full payment card numbers, and CyrForge's servers are never in the cardholder data path. Stripe is a PCI DSS Level 1 certified service provider.
Subprocessors
The third parties that process data on our behalf are listed, with purpose and location, in the Privacy Policy. We update that list before engaging a new subprocessor that processes personal data.
Data Retention and Deletion
You can delete your account and its data yourself, at any time, from Settings inside CyrForge. Deletion is immediate and permanent rather than a request we process later: the subscription is cancelled, CyrForge's access to your Google account is revoked at Google, your records are deleted, and your sign-in credentials are removed last so that a partial failure leaves you able to sign in and retry. It remains available even if your subscription has lapsed. Billing records that Stripe is legally required to keep are the exception. Full detail is in the Privacy Policy.
You can revoke CyrForge's access to your Google account independently at myaccount.google.com/permissions.
Incident Response
If we become aware of a breach affecting your personal data, we will investigate promptly, take steps to contain and remediate it, and notify affected users and any applicable regulators within the timeframes required by law — including the 72-hour notification window under GDPR Article 33 where it applies.
Privacy Compliance
CyrForge is designed to support the rights described under GDPR and CCPA, including access, correction, deletion, portability, and objection. See the Privacy Policy and GDPR pages.
Current Limitations
In the interest of transparency:
- CyrForge has not completed a SOC 2 Type II audit or ISO 27001 certification.
- We have not engaged a third-party penetration test to date.
- We do not currently operate a paid bug bounty program, though we welcome and will credit good-faith reports.
- Two-factor authentication is optional, not required. We encourage it and prompt you to enable it, but an account without it is protected by its password alone.
- We do not check your password against databases of previously breached passwords. The available way to do this would require your password to be sent to our servers, and we have chosen to keep the stronger property that it never is.
- CyrForge does not yet offer a screen listing your active sessions and devices. Changing your password signs you out everywhere, but you cannot revoke an individual session on its own.
We will update this page as that posture changes.
Contact
Elemental Genius LLC Email: [email protected] Address: Brockport, NY 14420 Phone: 585-204-0942
© 2026 Elemental Genius LLC. All rights reserved.
Report a security issue.
Email [email protected] with “Security” in the subject line and we'll acknowledge your report.
No credit card required
14-Day free trial
