How we approach trust and security
As a service-led advisory firm we aim for documented, transparent delivery. The principles below describe our practical operating frame — not a certification and not a compliance guarantee.
We only describe practices consistent with our current operations. Specific controls may vary by project and environment.
Data minimization
We request and handle only data needed for the engagement. Client data is handled on a need-to-know basis and we avoid creating unnecessary copies.
AI-assisted, human-reviewed
Where AI supports preparation or structuring, client-facing professional outputs are reviewed by a human expert. We do not promise automated compliance decisions or certification.
Sensitive data and cloud AI
Our operating principle is not to send identifiable or sensitive client data into public cloud AI tools. Exact handling rules are defined by the engagement and agreements between the parties.
Access and authentication
Account-bound and internal surfaces use modern authentication (Clerk). Internal tools are protected with role-based access control.
Transport and platform
The public website and application are served over HTTPS. Hosting and database providers run on industry-standard platforms; detailed infrastructure configuration is not published as security detail.
Responsibility boundaries
Regcytech provides advisory, readiness support, documentation and implementation support. We are not an accredited certification body, do not replace legal advice, and do not guarantee authority or customer acceptance.
Security contact
Please send vulnerability or security reports to our central contact address. Do not include sensitive client data in the first message.
hello@regcytech.comDiscuss your starting point
A short discovery conversation to clarify the situation — with no obligation.