Security at Cyclops
Your cultivation data is your business. Here's how we protect it.
Your data stays in the US
All Cyclops data is stored and processed in United States data centers. Our team is US-based.
Encrypted everywhere
- Every connection to Cyclops uses HTTPS (TLS). Unencrypted connections aren't accepted.
- Your data is encrypted at rest with AES-256.
- Integration credentials, like your Metrc API key, get an extra layer of encryption before they're stored, and are only ever shown masked.
Your team, your permissions
Every organization's data is kept separate. Role-based permissions let you decide what each person on your team can see and change.
Metrc and traceability integrations
- Our Metrc integration is read-only. Cyclops never creates, changes or deletes anything in Metrc.
- We recommend creating a dedicated Metrc user for Cyclops with view-only permissions.
- You enter your API key directly in Cyclops. We'll never ask you to email or text it.
- You can revoke Cyclops's access anytime from your Metrc account.
- Data from Metrc is used only to run your Cyclops account. It is never sold, shared or combined with other customers' data.
How we operate
- Multi-factor authentication is required on every administrative account.
- Critical security patches are applied within 30 days.
- Access to production systems is limited to the people who need it.
- Secrets and keys are never stored in our source code.
If something goes wrong
If a security incident affects your data, we'll notify you promptly and meet every notification requirement set by state regulators.
Report a vulnerability
Found a security issue? Email security@cyclops.systems. We acknowledge reports within 2 business days and welcome good-faith security research.
Last updated: September 30, 2026
