Pyronpyronstudio.Open Studio
PYRON TRUST CENTER

How we handle security, privacy and reliability.

Trust comes from transparency. This page explains what Pyron does to protect your data and keep your websites running — and what it does not yet claim.

Security architecture

All data is transmitted over TLS. Authentication uses secure session tokens. API requests validate origin and require verified email. Stored social credentials are encrypted at rest. Server-side authorization is enforced on every request.

Privacy by default

Pyron does not sell customer data. Analytics are only collected where explicitly configured. Subscriber consent timestamps are recorded. You can export or delete your data at any time.

GDPR / AVG

Pyron provides tooling to help you meet your GDPR obligations: subscriber consent records and unsubscribe handling. Using Pyron does not automatically make your website GDPR compliant — that depends on how you configure and use it.

Backups

A backup and restore runbook is available for operators. Backup scheduling, off-server storage and successful recovery tests must be configured and verified for each deployment.

Availability

Pyron uses a durable background job architecture for publishing, email and automation. Failed jobs are retried with backoff. We do not claim a specific uptime SLA on this page unless it is contractually backed.

Incident handling

Security issues are handled privately. If you discover a vulnerability, see our Responsible Disclosure page. We commit to investigating reports before public disclosure.

Certifications

Pyron does not currently hold ISO 27001, SOC 2 or other formal certifications. This will be updated if and when certifications are obtained.

Data portability

Contact support to arrange an export of your CMS content, subscriber lists and configuration. Confirm available export formats before subscribing.

Contact us about security