Legal Documentation


This document sets forth the complete Terms of Service, Security Policy, and Privacy Policy governing all use of Cyrillic Company infrastructure and services. By accessing our systems, you agree to these terms in their entirety.

Terms of ServiceSecurity PolicyPrivacy PolicyRussian Federation LawData SovereigntyZero-Knowledge ArchitectureGKP-4 FacilityEffective 2026Terms of ServiceSecurity PolicyPrivacy PolicyRussian Federation LawData SovereigntyZero-Knowledge ArchitectureGKP-4 FacilityEffective 2026
Part I — Terms of Service

Legal Notice

These Terms of Service ("Agreement") constitute a binding legal agreement between you ("User," "Client," or "Partner") and Cyrillic Company LLC ("Cyrillic," "Operator," "we," or "us"), a sovereign engineering firm incorporated and operating under the laws of the Russian Federation. Access to or use of any part of Cyrillic Company's digital infrastructure, APIs, services, or engineering outputs implies full, unconditional, and irrevocable acceptance of every clause contained herein. If you do not agree to these terms, you must immediately cease all access to our systems.

§1

Acceptance and Binding Effect

By accessing, connecting to, or otherwise interacting with any Cyrillic Company digital asset — including but not limited to this website, API endpoints, cryptographic communication channels, or support infrastructure — you acknowledge that you have read, understood, and agree to be bound by these Terms of Service in their current and any future revised form.

This Agreement is effective as of the moment of first access and remains in full force for the duration of any engagement, plus any survival periods expressly stipulated herein. Cyrillic Company reserves the right to amend these terms at any time without prior notice; continued use of the services following any modification constitutes acceptance of the revised Agreement.

This Agreement is entered into by you individually, and if you are accessing the services on behalf of a corporate entity, you represent and warrant that you have full authority to bind that entity to these terms. If such authority does not exist, you must not use the services.

1.1 — Digital Signature

Access to any Cyrillic Company system constitutes a valid digital signature equivalent to a wet-ink signature under the laws of the Russian Federation. No additional formality is required to create a binding obligation under this Agreement.

1.2 — Supersession of Prior Agreements

This Agreement supersedes all prior communications, representations, warranties, or agreements — whether written or oral — between you and Cyrillic Company relating to the subject matter hereof, except where a specific master services agreement has been separately executed by duly authorized representatives of both parties in writing.

§2

Governing Law and Jurisdiction

This Agreement and all disputes arising out of or related to it shall be governed exclusively by the laws of the Russian Federation, without regard to its conflict of law provisions. The parties expressly exclude the application of the United Nations Convention on Contracts for the International Sale of Goods (CISG).

International legal frameworks, including but not limited to the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the UK Data Protection Act 2018, and any equivalent foreign privacy or consumer-protection legislation, do not supersede or modify these terms insofar as Cyrillic Company's operations within the Russian Federation are concerned.

2.1 — Arbitration Clause

Any and all disputes, controversies, or claims arising out of or relating to this Agreement — including its formation, validity, breach, or termination — shall be resolved exclusively by binding arbitration before the Moscow International Arbitration Court (MKAC), in accordance with its rules. The arbitration shall be conducted in the Russian language, and the seat of arbitration shall be Moscow, Russian Federation.

2.2 — Waiver of Class Action

You hereby waive any right to participate in any class, collective, or representative action against Cyrillic Company. All claims must be brought on an individual basis only. This waiver is a material inducement for Cyrillic Company to provide services to you.

2.3 — Emergency Relief

Notwithstanding the arbitration clause, either party may seek emergency injunctive or provisional relief from a competent court of the Russian Federation to prevent irreparable harm pending arbitration. Such relief shall not be deemed a waiver of the arbitration obligation.

§3

Eligibility and Authorized Use

The services are offered exclusively to natural persons who are at least 18 years of age and possess the full legal capacity to form binding contracts under applicable law, and to duly incorporated legal entities. Use of the services by minors is strictly prohibited.

Access is further restricted to persons and entities who are not (i) subject to economic sanctions administered by the Russian Federation, (ii) identified on any prohibited-party list maintained by Russian regulatory authorities, or (iii) engaged in activities that are hostile to Russian national security interests as determined by Cyrillic Company's internal risk assessment protocol.

3.1 — Account Integrity

Each user account may be used only by the registered individual or entity. Account sharing, transfer, or delegation to unauthorized third parties is prohibited and constitutes a material breach of this Agreement entitling Cyrillic Company to immediate termination without notice or refund.

3.2 — Accurate Information

Users must provide accurate, current, and complete information when establishing any account or submitting any request for services. Providing false, misleading, or fraudulent information is a breach of this Agreement and may be reported to relevant authorities.

§4

Description of Services

Cyrillic Company provides a portfolio of professional engineering services encompassing distributed systems architecture, cryptographic infrastructure design, security auditing, identity and access management, data systems engineering, and related technical consulting. The specific scope of services for each engagement is defined in a separately executed Mission Brief or Statement of Work ("SOW").

4.1 — Service Tiers

Services are available across three operational tiers: Standard, applicable to general engineering consultations with standard response protocols; High-Intensity, applicable to critical infrastructure engagements requiring dedicated resource allocation and elevated security measures; and Sovereign, applicable to state-adjacent or defense-adjacent projects subject to additional vetting, clearance requirements, and non-disclosure obligations.

4.2 — Modifications to Services

Cyrillic Company reserves the right to modify, suspend, or discontinue any service or feature at any time, including rotating cryptographic protocols, modifying API endpoints, updating service interfaces, or relocating server infrastructure, without incurring liability to users beyond direct fees paid for services not yet rendered.

4.3 — Beta Features

Certain experimental features may be made available on a preview or beta basis. Such features are provided "as-is" without any warranty and may be discontinued at any time. Their use is governed by additional terms that will be presented at the time of access.

§5

Intellectual Property and Licensing

All intellectual property embodied in Cyrillic Company's deliverables, source code, cryptographic kernels, architectural designs, documentation, trademarks, and trade dress ("IP") is and shall remain the exclusive property of Cyrillic Company or its licensors. Nothing in this Agreement transfers, assigns, or otherwise conveys ownership of any IP to users or clients.

5.1 — Limited License Grant

Subject to full payment of applicable fees and compliance with this Agreement, Cyrillic Company grants you a limited, non-exclusive, non-sublicensable, non-transferable, revocable license to use deliverables solely for your internal business operations as specified in the applicable SOW. This license automatically terminates upon any breach of this Agreement.

5.2 — Restrictions

You may not: (i) reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code of any Cyrillic Company software or cryptographic implementation; (ii) create derivative works without written authorization; (iii) remove or alter any proprietary notices; (iv) use the IP for competitive intelligence, benchmarking, or any purpose not expressly authorized in the SOW.

5.3 — User-Provided Materials

Any materials, data, or technical information you provide to Cyrillic Company for the purpose of delivering services shall remain your property; however, you grant Cyrillic Company a limited, royalty-free license to use such materials solely as necessary to perform the agreed services. You represent and warrant that you have all necessary rights to provide such materials.

5.4 — Feedback

Any feedback, suggestions, ideas, or improvement proposals you voluntarily provide regarding the services become the exclusive intellectual property of Cyrillic Company without any obligation of compensation, confidentiality, or attribution to you.

§6

Fees, Payment, and Commercial Terms

All fees for services are specified in the applicable SOW or Mission Brief. Fees are denominated in the currency agreed in the SOW and are inclusive of all applicable Russian Federation taxes unless otherwise stated. International clients are responsible for any withholding taxes, duties, or levies imposed by their local jurisdictions.

6.1 — Payment Schedule

Unless otherwise agreed in writing, a fifty-percent (50%) deposit is required prior to commencement of any engagement. The remaining balance becomes due upon delivery of the agreed deliverables or milestone, whichever occurs first. Payment terms are net-fifteen (15) calendar days from invoice date.

6.2 — Late Payment

Amounts outstanding beyond the agreed payment deadline accrue interest at a rate of one and a half percent (1.5%) per month, or the maximum rate permitted by applicable law, whichever is lower. Cyrillic Company reserves the right to suspend all services immediately upon payment default without prejudice to any other remedy.

6.3 — Disputed Charges

Fee disputes must be raised in writing within ten (10) business days of invoice receipt. Failure to dispute within this period constitutes acceptance of the invoiced amount. Disputed amounts remain due pending resolution; Cyrillic Company will not suspend services during good-faith resolution of a disputed amount not exceeding fifteen percent (15%) of the total contract value.

6.4 — No Refunds

Except as expressly required by applicable Russian law, all fees paid are non-refundable. This includes situations where a project is cancelled by the client after commencement, where deliverables meet the specifications in the SOW but do not meet unstated expectations, or where access is terminated due to breach of this Agreement.

§7

Confidentiality and Non-Disclosure

Each party ("Receiving Party") acknowledges that it may receive or have access to information of the other party ("Disclosing Party") that is confidential and proprietary in nature ("Confidential Information"). Confidential Information includes, without limitation, technical designs, source code, business plans, client lists, pricing, and any information marked as confidential or that a reasonable person would understand to be confidential given the context of disclosure.

7.1 — Obligations

The Receiving Party agrees to: (i) hold Confidential Information in strict confidence using at least the same degree of care used to protect its own confidential information, but in no event less than reasonable care; (ii) not disclose Confidential Information to any third party without the Disclosing Party's prior written consent; (iii) use Confidential Information solely for the purpose of performing obligations under this Agreement.

7.2 — Exclusions

Confidentiality obligations do not apply to information that: (i) is or becomes publicly available through no fault of the Receiving Party; (ii) was rightfully known to the Receiving Party prior to disclosure without restriction; (iii) is independently developed by the Receiving Party without reference to Confidential Information; or (iv) is required to be disclosed by law or valid court order, provided the Receiving Party gives prompt written notice to the Disclosing Party.

7.3 — Survival

Confidentiality obligations survive termination of this Agreement for a period of five (5) years, except with respect to trade secrets, which remain confidential indefinitely.

§8

Prohibited Activities

You agree not to engage in any activity that, in Cyrillic Company's sole determination, constitutes misuse, abuse, or hostile engagement with our infrastructure. The following conduct is expressly prohibited and constitutes a material breach of this Agreement:

8.1 — Technical Attacks

Attempting to probe, scan, or test the vulnerability of any Cyrillic Company system; attempting unauthorized access to any server, account, or data store; launching denial-of-service attacks; introducing malware, ransomware, or any destructive code; or attempting to intercept, tamper with, or redirect any data transmission.

8.2 — Reverse Engineering and Scraping

Decompiling, reverse engineering, or disassembling any software component; using automated tools to extract, scrape, or harvest data from our systems at a rate exceeding what a single human user could reasonably generate; or attempting to map or fingerprint our internal network architecture.

8.3 — Impersonation and Fraud

Impersonating Cyrillic Company, its employees, or authorized agents; creating false accounts or providing false identifying information; engaging in phishing or social engineering directed at Cyrillic Company personnel or systems.

8.4 — Consequences

Engaging in any prohibited activity may result in immediate termination of all services, permanent blocking of all access credentials, notification of relevant law enforcement and cybersecurity authorities, and civil or criminal legal action seeking damages, injunctive relief, and recovery of all costs including attorney fees.

§9

Representations and Warranties

Each party represents and warrants to the other that: (i) it has the full legal capacity and authority to enter into this Agreement; (ii) this Agreement, when executed, constitutes a valid and binding obligation; (iii) the execution and performance of this Agreement do not violate any applicable law, court order, or other agreement to which it is party.

9.1 — User Warranties

You additionally warrant that: (i) all information provided to Cyrillic Company is accurate and not misleading; (ii) your use of the services complies with all applicable laws; (iii) you have all necessary rights in any materials or data you provide; and (iv) your mission objectives do not involve any illegal activity.

9.2 — Disclaimer of Implied Warranties

EXCEPT AS EXPRESSLY PROVIDED HEREIN, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR ACCURACY. CYRILLIC COMPANY DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR FREE OF HARMFUL COMPONENTS.

§10

Limitation of Liability and Indemnification

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL CYRILLIC COMPANY, ITS DIRECTORS, OFFICERS, EMPLOYEES, AGENTS, OR LICENSORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, LOSS OF REVENUE, LOSS OF DATA, OR LOSS OF BUSINESS OPPORTUNITY, EVEN IF CYRILLIC COMPANY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

10.1 — Aggregate Cap

Cyrillic Company's total cumulative liability under or in connection with this Agreement, regardless of the cause of action or theory of liability, shall not exceed the total fees actually paid by you in the six (6) months preceding the event giving rise to the claim.

10.2 — Indemnification by User

You agree to defend, indemnify, and hold harmless Cyrillic Company and its affiliates, officers, directors, employees, and agents from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from: (i) your use of the services in violation of this Agreement; (ii) your violation of any applicable law; (iii) any claim that materials you provide infringe any third-party intellectual property right; or (iv) your gross negligence or willful misconduct.

§11

Force Majeure

Neither party shall be liable for any delay or failure to perform its obligations under this Agreement to the extent such failure results from causes beyond its reasonable control, including but not limited to: acts of God, natural disasters, war, armed conflict, civil unrest, government-mandated network isolation, sovereign internet shutdowns, large-scale electromagnetic interference, acts of terrorism, pandemics, or failure of critical third-party infrastructure such as intercontinental fiber optic networks.

The affected party must provide prompt written notice of the force majeure event and take all reasonable steps to minimize its impact. If the force majeure event continues for more than sixty (60) days, either party may terminate the affected SOW upon written notice without liability, subject only to payment for work already performed and expenses already incurred.

§12

Term and Termination

This Agreement commences on the date of first access and continues until terminated by either party. Specific SOWs shall have the term specified therein. Cyrillic Company may terminate this Agreement or any SOW immediately without notice in the event of a material breach by you, including but not limited to non-payment, engaging in prohibited activities, or misrepresentation.

12.1 — Effect of Termination

Upon termination, all licenses granted to you immediately cease; you must promptly return or destroy all Confidential Information of Cyrillic Company; Cyrillic Company will initiate the cryptographic shredding of your mission data in accordance with our data destruction protocols; and all outstanding payment obligations become immediately due and payable.

12.2 — Survival

The following provisions survive termination of this Agreement: Sections 5 (Intellectual Property), 7 (Confidentiality), 9.2 (Warranty Disclaimer), 10 (Limitation of Liability), 2 (Governing Law), and any other provisions that by their nature are intended to survive.

§13

Miscellaneous Provisions

If any provision of this Agreement is held invalid or unenforceable, the remaining provisions continue in full force and effect ("Severability"). Failure by Cyrillic Company to enforce any provision does not constitute a waiver of future enforcement rights. This Agreement may not be assigned by you without Cyrillic Company's prior written consent; Cyrillic Company may assign this Agreement freely in connection with a merger, acquisition, or sale of substantially all its assets.

13.1 — Entire Agreement

This Agreement, together with any executed SOW or Mission Brief, constitutes the entire agreement between the parties with respect to its subject matter. No amendments are valid unless in writing signed by authorized representatives of both parties.

13.2 — Language

This Agreement is executed in English for international convenience; however, in the event of any dispute regarding interpretation, the Russian-language version — available upon request from our legal node — shall prevail and be the only authoritative text recognized in any court or arbitration proceeding.

13.3 — Notices

All legal notices must be sent to Cyrillic Company via our designated encrypted communication channel at legal@cyrillic.co using PGP encryption with our published public key. Notices sent via unencrypted channels, physical mail, or any non-designated medium shall be deemed not received and shall carry no legal effect.

13.4 — No Partnership

This Agreement does not create any partnership, joint venture, agency, franchise, or employment relationship between the parties. Neither party has authority to bind the other by contract, representation, or otherwise without prior written authorization.

Part II — Security Policy

Security Mandate

This Security Policy governs the technical, operational, and organizational security measures implemented by Cyrillic Company to protect the confidentiality, integrity, and availability of all systems, data, and communications within our infrastructure. Compliance with this policy is mandatory for all users, partners, and any third party granted access to our systems.

§14

Security Architecture Overview

Cyrillic Company operates a defense-in-depth security architecture grounded in zero-trust principles. Every request, regardless of origin, is treated as potentially hostile and must be authenticated and authorized at multiple independent layers before access is granted. No implicit trust is extended based on network location, IP address, or prior authenticated session.

14.1 — Zero-Trust Framework

Our zero-trust implementation enforces: (i) continuous identity verification at every access request; (ii) least-privilege access control with role-based permissions scoped to the minimum necessary for each function; (iii) micro-segmented network architecture that prevents lateral movement between zones in the event of a compromise; and (iv) real-time behavioral analytics to detect anomalies that may indicate credential compromise or insider threats.

14.2 — GKP-4 Physical Facility

Our primary server infrastructure is housed within the GKP-4 high-security facility, which features: 24/7 armed physical security personnel; multi-factor biometric access control at all entry points; Faraday shielding against electromagnetic eavesdropping; redundant independent power grids with UPS and diesel generator backup; liquid-cooled hardware cabinets operating at optimal temperature ranges; and air-gap isolation for the most sensitive processing nodes.

14.3 — Network Segmentation

The network is divided into security zones: the public DMZ handling external-facing traffic; the application zone containing service logic; the data zone holding all persistent storage; and the kernel zone, which is air-gapped and handles cryptographic operations. Communication between zones is strictly controlled by stateful firewalls and application-layer gateways operating under a default-deny ruleset.

§15

Cryptographic Standards and Key Management

All data at rest and in transit within Cyrillic Company infrastructure is protected by cryptographic algorithms selected for their resistance to both classical and emerging quantum computing attacks. We continuously monitor advances in post-quantum cryptography and update our implementations in advance of any identified threat threshold.

15.1 — Encryption at Rest

Persistent data is encrypted using AES-256-GCM with hardware-backed key storage in tamper-evident HSMs (Hardware Security Modules). Database-level encryption is supplemented by column-level encryption for the most sensitive fields, and disk-level encryption using LUKS on Linux systems with keys stored separately from the encrypted volumes.

15.2 — Encryption in Transit

All network communications use TLS 1.3 as the minimum acceptable protocol version. TLS 1.0 and 1.1 are permanently disabled. We employ certificate pinning for all client applications, HSTS with a minimum max-age of 63,072,000 seconds including subdomains, and HTTP/2 with strict header validation.

15.3 — Key Management Lifecycle

Cryptographic keys are generated using FIPS 140-2 validated entropy sources, stored exclusively in HSMs, rotated on schedules aligned with key type and sensitivity, subject to split-knowledge and dual-control procedures for master keys, and securely destroyed at end-of-life using DoD 5220.22-M compliant procedures extended to 35 overwrite passes for highly sensitive key material.

15.4 — Post-Quantum Readiness

We are actively implementing NIST-selected post-quantum cryptographic algorithms — specifically CRYSTALS-Kyber for key encapsulation and CRYSTALS-Dilithium for digital signatures — in a hybrid mode alongside classical algorithms, to ensure security during the transition period and against harvest-now-decrypt-later attacks.

§16

Access Control and Identity Management

Access to all Cyrillic Company systems is governed by a comprehensive Identity and Access Management (IAM) framework implementing the principle of least privilege, need-to-know access, and separation of duties across all operational functions.

16.1 — Authentication Requirements

All user accounts must be protected by multi-factor authentication (MFA) with a minimum of two independent factors. Acceptable second factors include hardware security keys (FIDO2/WebAuthn preferred), time-based one-time passwords (TOTP), and biometric verification on approved devices. SMS-based OTP is not considered acceptable for Tier-2 and above access.

16.2 — Privileged Access Management

Privileged accounts with administrative rights are subject to enhanced controls including: just-in-time (JIT) provisioning with time-limited access windows; session recording and real-time monitoring for all privileged sessions; approval workflows requiring sign-off from a second authorized administrator; and automatic deprovisioning upon session expiration or anomaly detection.

16.3 — Account Lifecycle

User accounts are provisioned only upon successful completion of the onboarding vetting process. Accounts are automatically suspended after 90 days of inactivity and require re-authentication to reactivate. Accounts of departed personnel or terminated partners are revoked within four (4) hours of notification, and all associated credentials are rotated. Account provisioning and deprovisioning events are logged immutably.

16.4 — Password Policy

Where password-based authentication is used, passwords must be a minimum of 16 characters, include characters from at least three of the four character classes (uppercase, lowercase, numeric, special), must not appear in known breach databases (checked against HaveIBeenPwned API), and must be changed every 180 days. Password reuse for the previous 12 cycles is prohibited.

§17

Vulnerability Management and Penetration Testing

Cyrillic Company maintains a continuous vulnerability management program encompassing automated scanning, manual review, and periodic third-party penetration testing to identify and remediate security weaknesses before they can be exploited by adversaries.

17.1 — Vulnerability Scanning

Automated vulnerability scans are conducted on a weekly basis across all externally facing systems and on a daily basis across internal systems. Critical vulnerabilities are escalated immediately upon discovery; high vulnerabilities must be remediated within 15 days; medium within 60 days; and low within 180 days. All findings are tracked in our internal security management system.

17.2 — Penetration Testing

Full-scope penetration tests are conducted by independent qualified security firms on a semi-annual basis. Test scope covers external network perimeter, internal network, web applications, API endpoints, physical security, and social engineering. Findings are classified, remediated, and verified through retesting before the engagement is formally closed.

17.3 — Responsible Disclosure

Cyrillic Company operates a responsible disclosure program. Security researchers who discover vulnerabilities in our systems are encouraged to report them to security@cyrillic.co using our published PGP key. We commit to acknowledging receipt within 48 hours, providing a resolution timeline within 14 days, and not pursuing legal action against researchers who act in good faith and within the boundaries of the program.

17.4 — Patch Management

Operating system and application patches are applied on a defined schedule: emergency patches for actively exploited critical vulnerabilities within 24 hours; critical patches within 7 days; high patches within 30 days; medium and low patches in the next scheduled maintenance window. All patching activity is logged and reportable to clients upon request.

§18

Security Monitoring and Incident Response

Cyrillic Company operates a 24/7 Security Operations Center (SOC) staffed by trained analysts who monitor all systems for indicators of compromise, anomalous behavior, and security events using a layered set of detection technologies including SIEM, EDR, network traffic analysis, and honeypot infrastructure.

18.1 — Logging and Audit Trails

All system access, data modification, administrative actions, authentication events, and network connections are logged to an immutable, tamper-evident logging infrastructure. Logs are retained for a minimum of 365 days in hot storage and for five years in cold archival storage. Log integrity is verified by cryptographic hashing at ingestion time.

18.2 — Incident Response Plan

Our Incident Response Plan (IRP) follows the NIST SP 800-61 framework and defines four phases: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. The CSIRT team is activated for all incidents classified as Severity 1 (Critical) or Severity 2 (High) and follows defined escalation paths and communication protocols.

18.3 — Breach Notification

In the event of a confirmed data breach affecting client data, Cyrillic Company will notify affected clients through their designated secure communication channel within 72 hours of confirming the breach. Notification will include: the nature of the incident; categories and estimated volume of data affected; likely consequences; measures taken or proposed; and a dedicated point of contact for further inquiries.

18.4 — Business Continuity and Disaster Recovery

Our Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) are tested at minimum annually through tabletop exercises and full live failover tests. Recovery Time Objective (RTO) is set at four (4) hours for critical systems; Recovery Point Objective (RPO) is set at one (1) hour, enforced through continuous replication to geographically separated backup nodes within the Russian Federation.

§19

Third-Party and Supply Chain Security

Cyrillic Company recognizes that third-party vendors and supply chain components represent a significant attack surface. We implement a rigorous third-party risk management process to assess, monitor, and contractually bind all external parties that access our systems or process data on our behalf.

19.1 — Vendor Vetting

All third-party vendors undergo a security assessment prior to engagement that evaluates: organizational security posture, certification status (ISO 27001, SOC 2, or equivalent), data handling practices, access control mechanisms, incident response capabilities, and financial stability. Vendors are classified by risk level, and higher-risk vendors are subject to enhanced due diligence and more frequent reassessment.

19.2 — Contractual Controls

All vendors with access to Cyrillic Company systems or client data are required to execute a Data Processing Agreement (DPA) specifying: permissible processing purposes, data handling and retention requirements, security obligations aligned with this policy, audit rights, breach notification obligations, and instructions for data return or destruction at contract termination.

19.3 — Software Composition Analysis

All open-source and third-party software components incorporated into our codebase are subject to automated software composition analysis (SCA) to detect known vulnerabilities, incompatible licenses, and deprecated components. No component with an unmitigated critical or high CVE may be deployed to production without a documented exception approved by the CISO.

§20

Employee Security and Acceptable Use

All Cyrillic Company employees and contractors are subject to comprehensive security onboarding including background checks, security awareness training, and acknowledgment of this Security Policy and all associated procedures before being granted any system access.

20.1 — Security Awareness Training

Security awareness training is mandatory at onboarding and repeated on a monthly basis covering: phishing and social engineering recognition, secure coding practices (for technical staff), physical security and clean-desk policy, data classification and handling, and incident reporting procedures. Completion is tracked and non-compliance is subject to disciplinary action.

20.2 — Acceptable Use

Company systems and resources may be used solely for legitimate business purposes. Prohibited uses include accessing inappropriate content, attempting to circumvent security controls, installing unauthorized software, connecting unauthorized devices to the internal network, and sharing credentials. All activity on company systems is subject to monitoring in accordance with applicable law and prior notice to employees.

20.3 — Insider Threat Program

Cyrillic Company operates an insider threat detection program that employs behavioral analytics on system access patterns, data exfiltration monitoring, and anomaly detection. Investigations into potential insider threats are conducted by a dedicated team with appropriate legal oversight and in compliance with applicable labor laws.

Part III — Privacy Policy

Privacy Commitment

This Privacy Policy explains how Cyrillic Company collects, uses, stores, protects, and discloses personal data in connection with the provision of our services. We are committed to processing personal data lawfully, transparently, and in full compliance with Federal Law No. 152-FZ "On Personal Data" of the Russian Federation and all other applicable data protection legislation.

§21

Data Controller Identity and Contact

Cyrillic Company LLC is the data controller responsible for all personal data processed in connection with our services. Our Data Protection Officer (DPO) can be contacted via encrypted email at privacy@cyrillic.co. We respond to all privacy inquiries within five (5) business days. For urgent matters relating to data subject rights, responses are prioritized within two (2) business days.

21.1 — Regulatory Authority

Cyrillic Company is registered with Roskomnadzor (the Federal Service for Supervision of Communications, Information Technology and Mass Media) as a personal data operator in accordance with the requirements of Federal Law No. 152-FZ. We cooperate fully with Roskomnadzor and other competent Russian regulatory authorities on all matters of data protection compliance.

§22

Categories of Personal Data Collected

Cyrillic Company collects only the personal data that is necessary for the specific, stated purpose for which it is processed, in accordance with the principle of data minimization. The following categories of data may be collected depending on the nature of your interaction with our services:

22.1 — Identity and Contact Data

Full legal name; corporate or professional affiliation; email address; telephone number; physical address (for formal legal notices); government-issued identification numbers where required for compliance or clearance vetting; and any other information you voluntarily provide in communications with us.

22.2 — Technical and Device Data

IP address; browser type and version; operating system; device type and hardware fingerprint (where applicable); timezone and locale settings; session cookies and authentication tokens; API access logs including timestamps, request methods, endpoints accessed, and response codes.

22.3 — Usage and Behavioral Data

Navigation patterns within our web infrastructure; feature usage frequency; error logs and diagnostic data; search queries within authenticated portals; communication metadata (sender, recipient, timestamp, size — never content without separate consent).

22.4 — Financial Data

Billing contact information; payment method details (processed exclusively through PCI-DSS compliant payment processors — raw card data never touches Cyrillic Company systems); invoice history; and transaction identifiers for reconciliation purposes.

22.5 — Special Categories

Cyrillic Company does not intentionally collect special categories of personal data (as defined by applicable law, including racial or ethnic origin, political opinions, religious beliefs, health data, genetic or biometric data) unless explicitly required for security clearance vetting, in which case additional consent is obtained and enhanced protective measures are applied.

§23

Legal Bases for Processing

Cyrillic Company processes personal data only when a valid legal basis exists under Federal Law No. 152-FZ. The applicable legal basis depends on the specific processing activity:

23.1 — Consent

Where we rely on your consent, we obtain it through an explicit affirmative action (e.g., ticking a checkbox or submitting a form with a clear consent notice). Consent is recorded as an immutable cryptographic log entry. You have the right to withdraw consent at any time without affecting the lawfulness of processing conducted prior to withdrawal. Withdrawal is effected by contacting our DPO or through the account settings interface.

23.2 — Contract Performance

Processing that is necessary to perform our obligations under a signed SOW or Mission Brief — including identity verification, service delivery, billing, and technical support — is based on contractual necessity.

23.3 — Legal Obligation

Certain data is processed to comply with mandatory legal obligations, including retention of financial records for tax purposes, disclosure in response to valid judicial orders, and reporting requirements under applicable Russian law.

23.4 — Legitimate Interests

We may process certain data for our legitimate interests, including fraud prevention, network and information security, improving service quality through aggregated analytics, and enforcing our contractual rights. In all such cases, we have conducted a legitimate interests assessment confirming that our interests are not overridden by your fundamental rights and freedoms.

§24

Purposes of Processing

Personal data is processed for the following specific purposes, each matched to a legal basis as described in Section 23:

24.1 — Service Delivery

Establishing and maintaining your account; authenticating your identity; routing and delivering engineering services; enabling technical support communications; managing project milestones and deliverables; and facilitating secure communication channels throughout the engagement lifecycle.

24.2 — Security and Fraud Prevention

Detecting and preventing unauthorized access, fraud, and abuse; monitoring for indicators of compromise or policy violations; enforcing access control decisions; conducting security investigations; and maintaining the integrity and availability of our infrastructure against internal and external threats.

24.3 — Compliance and Legal Obligations

Verifying that users meet eligibility requirements; conducting sanctions screening; maintaining records required by Russian tax and commercial law; responding to lawful requests from competent authorities; and defending against legal claims.

24.4 — Service Improvement

Analyzing aggregated, anonymized usage patterns to optimize resource allocation and improve user experience; conducting research and development to enhance our technical capabilities; and evaluating the performance of our infrastructure.

§25

Data Localization and Cross-Border Transfers

In strict compliance with Federal Law No. 242-FZ on data localization, all primary databases containing personal data of Russian citizens or residents are stored on servers physically located within the territory of the Russian Federation at our GKP-4 facility.

25.1 — International Client Data

Personal data of non-Russian individuals may be processed outside the Russian Federation only where a specific secondary consent has been obtained, the destination country provides an adequate level of data protection as recognized by applicable Russian law, and appropriate supplementary safeguards (such as standard contractual clauses recognized under Russian law) are in place.

25.2 — No Cloud Processing

We do not use US or EU cloud infrastructure providers (including AWS, Microsoft Azure, Google Cloud Platform, or their subsidiaries) to process personal data collected in connection with our services. All computation occurs on hardware owned, operated, and physically controlled by Cyrillic Company within our own facilities.

§26

Data Retention and Deletion

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law or is necessary to defend against potential legal claims.

26.1 — Retention Schedule

Active account data is retained for the duration of the engagement plus a 90-day security cooldown period. Financial and transactional records are retained for five (5) years as required by Russian tax and commercial law. Security logs and audit trails are retained for twelve (12) months in hot storage and five (5) years in cold archival. Technical support communications are retained for two (2) years from the date of last interaction.

26.2 — Secure Deletion

Upon expiry of the applicable retention period, or upon valid exercise of your right to erasure, personal data is permanently and securely deleted using methods that render recovery technically infeasible. For data on magnetic storage media, deletion follows a minimum 35-pass overwrite procedure; for SSDs and flash memory, cryptographic erasure (destroying the encryption key) is used in addition to the standard deletion procedure.

§27

Your Rights as a Data Subject

In accordance with Federal Law No. 152-FZ and other applicable law, you have the following rights with respect to your personal data processed by Cyrillic Company:

27.1 — Right of Access

You have the right to receive confirmation of whether we process your personal data, and if so, to receive a copy of that data along with information about the processing purposes, categories, recipients, and retention periods. Access requests are fulfilled within 30 days, delivered via encrypted channel.

27.2 — Right to Rectification

You have the right to correct inaccurate or incomplete personal data. Corrections are propagated across all processing nodes within 48 hours of verification.

27.3 — Right to Erasure

You have the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, you have withdrawn consent (where processing was based on consent), or the data has been unlawfully processed. Erasure requests are executed within 10 business days, subject to overriding legal obligations to retain certain data.

27.4 — Right to Restriction

You may request that we restrict processing of your personal data in certain circumstances, such as while the accuracy of the data is being contested or while your objection to processing is being assessed. During restriction, data may only be stored, not actively processed.

27.5 — Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you may request a structured, machine-readable export of your personal data (in JSON format, E2EE) to facilitate transfer to another data controller. Export requests are fulfilled within 15 business days.

27.6 — Right to Object

You have the right to object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, or processing is necessary for the establishment, exercise, or defense of legal claims.

27.7 — Exercising Your Rights

All rights requests must be submitted in writing to our DPO at privacy@cyrillic.co using your registered contact information and, where possible, authenticated through your account. We may request additional information to verify your identity before processing a rights request. All decisions on rights requests are subject to our legal obligations and rights.

§28

Cookies and Tracking Technologies

We use a minimal set of technically necessary cookies to enable the operation of our digital infrastructure. We do not use advertising cookies, cross-site tracking technologies, social media pixels, or third-party analytics scripts of any kind.

28.1 — Session Cookies

Ephemeral session cookies are stored in your browser's memory and are destroyed automatically upon session termination. They are used exclusively to maintain your authenticated session and prevent session fixation attacks. They contain no personally identifiable information in plaintext.

28.2 — Security Cookies

Persistent security cookies with a short expiry (7 days maximum) are used to prevent CSRF attacks and to remember security preferences such as MFA device trust. These cookies are HttpOnly, Secure, and SameSite=Strict, making them inaccessible to JavaScript and protected against cross-site transmission.

28.3 — No Third-Party Tracking

Our infrastructure contains zero third-party tracking pixels, analytics scripts, retargeting tags, or social media widgets. We do not participate in any cross-site data exchange network. All analytics are performed on anonymized, first-party data using infrastructure we own and operate.

§29

Data Security Measures

Cyrillic Company implements state-of-the-art technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or disclosure. These measures are described in detail in Part II (Security Policy) of this document and include end-to-end encryption, HSM-backed key management, zero-trust access controls, continuous security monitoring, and regular third-party penetration testing.

29.1 — Organizational Measures

Internal access to personal data is restricted to personnel with a demonstrated operational need, governed by role-based access controls, and subject to binding confidentiality obligations. All personnel with access to personal data undergo background vetting and regular security training. Data access decisions are logged and reviewed.

§30

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, applicable law, or service offerings. Material changes will be communicated to affected users through their registered contact channel at least fifteen (15) days prior to the changes taking effect. For non-material clarifications, we will update the effective date and post the revised policy without individual notification.

The current version of this Privacy Policy is always accessible at cyrillic.co/terms. Archived previous versions are available upon request from our DPO. Continued use of our services after any revised Privacy Policy takes effect constitutes your acceptance of the changes.

Document Reference

CYR-LEGAL-V5-2026

Effective January 17, 2026 · Governing Law: Russian Federation

Questions?

Contact Legal

End of Legal Document · Cyrillic Company LLC · Moscow, Russian Federation