California, United States · CCPA / CPRA

CCPA / CPRA-compliant AI

The CCPA (now amended by the CPRA) doesn't ban AI processing of personal information, but it does require disclosure, opt-out mechanisms, and data minimization. Tokenization is the cleanest minimization technique — by the time a request reaches OpenAI or Anthropic, the personal information is gone.

  • 01

    Built-in CCPA-classed detectors

    SSN, financial account, geolocation, government ID detectors all included.

  • 02

    Subprocessor isolation

    Each project has its own provider key and detector config — easy to map to a CCPA disclosure.

What CCPA / CPRA requires you to do

• Right to know — Consumers can ask what PI you've shared with third parties. With Cypherz, the answer for AI vendors is 'none, only tokenized surrogates.'

• Right to delete — Delete the project vault key and every tokenization mapping becomes unrecoverable.

• Sensitive PI restrictions — SSN, financial info, precise geolocation — Cypherz has built-in detectors for each.

How Cypherz helps

• Built-in CCPA-classed detectors — SSN, financial account, geolocation, government ID detectors all included.

• Subprocessor isolation — Each project has its own provider key and detector config — easy to map to a CCPA disclosure.

Important caveat

Legal advice is between you and counsel. Cypherz provides infrastructure controls only.

Common questions

Frequently asked.

Does Cypherz make my app CCPA / CPRA-compliant by itself?

No tool can — compliance is a posture across people, process, and technology. Cypherz handles a critical technical layer (pseudonymization, encryption, audit logging) but you still need policy, training, and assessment.

Where is Cypherz hosted?

EU (Hetzner — Helsinki and Falkenstein) by default for the managed product. Self-host anywhere with one docker-compose command if your compliance posture requires it.

Do you sign formal agreements?

Yes — Business and Enterprise tiers include DPAs and BAAs. We're working through SOC 2 Type II audit; ask for our latest report.

Can I get an audit log export?

Yes — every action is logged with structured metadata, exportable via the API. Common formats supported for SIEM ingestion.

Get started

Bring your AI features into CCPA / CPRA scope cleanly.

Sign up free. Create a project. The audit trail starts logging from request one.