Ciright Finance

Security and privacy

Private means protected—not merely hidden behind a private-looking screen.

Ciright Finance reuses Ciright/Keyra identity and Core permissions. Private documents, previews, search results, exports, and AI responses remain authorization-scoped.

Document controls

  • Authenticated, authorized upload only
  • Quarantine and file-type validation before processing
  • Private encrypted storage with protected transport
  • Scoped access and controlled previews
  • Transient handling of document passwords
  • Retention and malware/sandbox checks on the processing path

What we will not claim

This site does not claim that only the user can decrypt a document while that same document is sent to server-side AI processing. Unsupported certification badges are prohibited. Security copy describes implemented storage, processing, access, and retention controls.

Personal vs business

A personal return may include a business schedule beside household information. Business-scoped extraction must not expose unrelated spouse, dependent, SSN, wage, or investment information to the business team. Original, business derivative, and extracted facts may carry different grants.

AI boundary

Document text is data, not operational authority. Uploaded content cannot instruct the system to change permissions, run SQL, invite users, send files externally, or release payments.