Trust Center

Security, privacy and how Kryston actually works.

Cybersecurity buyers vet vendors before they trust them with anything. This page states plainly what kryston.net collects, what tools touch client work, and how credentials and data are handled, so a review of Kryston doesn't have to start from scratch.

What this website actually collects

kryston.net runs no analytics, no advertising pixels and no tracking cookies. There is nothing to consent-gate because nothing is being tracked; you can confirm this yourself in your browser's network inspector. The only information the site receives is whatever you choose to send by emailing contact@kryston.net directly.

Client engagement data is handled separately, under the terms agreed for that engagement and the Data Processing Agreement where one applies. What's collected, why, and for how long is scoped to that specific work rather than to the website.

Security posture

kryston.net is self-hosted on a VPS running Debian with nginx in front of it, over TLS with HSTS and a restrictive Content Security Policy. Multi-factor authentication is enabled on every account used to run Kryston, including hosting, email and domain management.

Client credentials (CMS, CRM, social accounts) are requested only for the scope of the current work, shared through encrypted vault links rather than email or chat, and not retained past the point they're needed.

Access and least privilege

Where a platform supports it, Kryston asks for role-scoped access rather than full admin, uses a distinct login per client rather than one reused login, and removes access at the end of an engagement instead of leaving it standing.

Incident response

If Kryston discovers or is notified of a security incident affecting a client's data, the client will be notified within 72 hours of confirmation, with what's known at that point and what happens next.

Vulnerability disclosure

If you've found a security issue on kryston.net and its subdomains, report it to security@kryston.net. Kryston will acknowledge good-faith reports, work to fix confirmed issues promptly, and won't pursue legal action against research conducted in good faith and without accessing or exfiltrating data beyond what's needed to demonstrate the issue. See security.txt.

Vendor vetting

Kryston favors tools that are self-hosted or privacy-focused over the mainstream default, when that trade-off doesn't sacrifice reliability the work depends on. Proton was chosen for business email on this basis: not because it's a perfect solution to data sovereignty, but because it's the best compromise found between keeping operations in one place and taking privacy seriously.

01 Subprocessors

Tools that touch Kryston's or a client's data

Kept short and current on purpose. In-house tools are listed too, for transparency, even where no third party is involved.

ToolPurposeCategory
SpaceshipDomain registration and VPS hosting for kryston.netThird-party
ProtonBusiness email (contact@, privacy@, security@kryston.net)Third-party
MangoolsKeyword and SERP research toolingThird-party
GeoptieAI search / GEO visibility auditingThird-party
In-house CRMClient and pipeline records; self-hosted, not a third-party serviceIn-house, not a subprocessor

AI use

Kryston uses Claude, Gemini and ChatGPT to help build and maintain kryston.net itself, including the ongoing SEO, AEO and GEO work described on this site, and to help draft content that's intended for publication. Client-confidential data is not entered into these tools. Kryston also runs a self-hosted, in-house retrieval system over its own reference material; client data is never included in it.

Response times

Kryston aims to respond to inquiries sent to contact@kryston.net within one business day. Specific engagements may agree faster commitments in writing.

02 Legal

The documents behind this page

Each of the three documents below covers a different part of the relationship: what this website collects, what governs using it, and what governs a paid engagement that touches your data.

Questions before you engage Kryston?

Vendor risk reviews are normal in this market. Email directly with what your process needs and Kryston will fill in the gaps this page doesn't cover.