Back to Platform

Privacy Policy

Effective Date: October 15, 2026

This Privacy Policy applies to the CyCity Quantum Web Standard (CQWS) enterprise platform, including our core kernel module, billing portal, and provisioning APIs. Our privacy posture is defined by one foundational truth: if we do not hold your data, it cannot be compromised.

1. The Principle of Zero-Knowledge Architecture

Unlike traditional cloud security platforms that proxy your traffic through their infrastructure to perform deep packet inspection (DPI) or threat analysis, CQWS operates on a strict Zero-Knowledge architectural principle. We engineer our systems explicitly so that we cannot see, access, decrypt, or intercept your operational data.

Our infrastructure is blind to your payloads by mathematical necessity. Because CQWS utilizes Information-Theoretic Security (ITS) via One-Time Pad semantics applied directly at the kernel layer (Ring-0) on your own metal, the decryption keys never leave your internal memory space and are immediately zeroized post-consumption.

2. Data We Do Not Collect

We firmly believe that metadata is data. Therefore, our platform actively rejects the collection of operational telemetry. We explicitly do not collect, log, or monitor:

  • The contents of any network packets processed by the CQWS kernel module.
  • Source and destination IP addresses of your internal or external traffic.
  • Network topology graphs or endpoint discovery metrics.
  • Cryptographic key material, including generated One-Time Pads or private ML-DSA keys.

3. Data We Collect for Provisioning and Billing

To provide licensing, authentication, and node management services through the CQWS Billing Portal, we collect only the absolute minimum required administrative data:

  • Account Credentials: Corporate email addresses and bcrypt-hashed passwords utilized for account provisioning and administrative alerts.
  • Public Cryptographic Material: Public keys associated with your ML-DSA (Dilithium) identity handshakes, required solely to verify the authenticity of your licensed nodes.
  • Hardware Identifiers: Non-reversible cryptographic hashes of your server hardware configurations (e.g., CPU/Motherboard IDs) strictly for hardware-locked license node binding.
  • Payment Information: Billing details which are tokenized and processed entirely by our Tier-1 PCI-DSS compliant payment gateway (Stripe). We never touch, store, or transmit your raw credit card numbers or banking information on CyCity servers.

4. Third-Party Sharing and Subprocessors

We do not sell, rent, or monetize your administrative data. We share essential billing data strictly with our financial processors for the sole purpose of maintaining your subscription and ensuring legal tax compliance.

Our strictly vetted subprocessors include:

  • Stripe, Inc. - For secure payment processing and subscription lifecycle management.
  • Amazon Web Services (AWS) - For hosting the highly-available API endpoints that serve our licensing and public-key directory services.

No third party, including CyCity personnel or our hosting providers, has access to any cryptographic material or network payloads.

5. Law Enforcement and Subpoenas

As a foundational security provider, we are occasionally subject to legal requests for data. Our response policy is dictated by our architecture: we cannot hand over what we do not possess.

If compelled by a valid legal subpoena originating from a jurisdiction with authority over CyCity, we can only provide the administrative data we hold (e.g., billing records, email addresses, and node license counts). We cannot wiretap, decrypt, or intercept client communications, nor can we be forced to alter our codebase to introduce such capabilities.

6. Your Rights & GDPR/CCPA Compliance

Regardless of your geographic location, we extend the protections of the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) to all enterprise clients globally. You maintain total sovereign control over your provisioning data.

You maintain the right to:

  • Access: Request a full export of all administrative data tied to your account.
  • Rectification: Correct any inaccurate billing or contact information.
  • Erasure ("Right to be Forgotten"): Request full deletion of your account. Upon termination, your cryptographic identity is permanently revoked, and all administrative data is scrubbed from our active directories within 72 hours, subject only to legally mandated financial retention periods.

7. Contact the Privacy Team

For inquiries regarding this policy, data subject access requests, or to contact our Data Protection Officer (DPO), please email us via secure channels at compliance@cycity.io.