Security
Cirrys holds your clients' network details, contacts and passwords. Here is how we look after them.
Every client is kept apart
Each MSP sees only its own clients, and each client's staff see only their own company. That check runs on the server for every page and every change, never just by hiding buttons. Automated tests try to read and change another client's and another MSP's records through every action, and every one has to be refused.
Passwords are encrypted, and every view is logged
- Credentials in the vault are encrypted with AES-256-GCM. The key is kept outside the database, so a copy of the database alone can't be read.
- Seeing a password needs a reason, and every view is recorded with who, when and why.
- Your clients only see passwords you choose to share with them, and only staff you give permission to, optionally limited to certain locations.
Files stay private
Photos and documents on requests are stored privately. There are no public links: each file is checked against the request it belongs to before it is shown. Files on internal notes are visible to your team only.
Monitoring reads, it doesn't change
Cirrys connects to UniFi with a read-only Site Manager API key. It watches status and devices; it can't change your clients' network configuration.
Email you can trust
- Email is sent from your own domain, signed with DKIM (2048-bit keys, rotated automatically) and covered by SPF and DMARC.
- Delivery requires TLS, so mail is never sent unencrypted.
- No tracking pixels and no rewritten links.
Encrypted in transit
All traffic to Cirrys uses HTTPS. The companies we use for hosting, storage and email are listed in our privacy policy.
Coming next
- Sign-in with your Microsoft or Google work account for your team, and one-time email links for your clients.
- An audit log of changes across the account.
Report a problem
If you think you've found a security issue, email security@cirrys.com. We'll reply within two working days.