Maya

Security — Overview

Audience: Compliance, Legal, Security, Bank ITUpdated 2026-04-28

Security — Overview

This page is a one-stop summary of Maya's security posture. Every claim here is expanded in a dedicated page. Every dedicated page is referenced here.

Summary

AreaPosition
Data scopeMaya ingests only verified LLM bot traffic and the public URLs it touched. Filtering happens inside the brand's perimeter before transmission.
PIINone. No customer identifiers, cookies, sessions, device IDs, or ad IDs are transmitted. IP addresses are hashed or stripped at source.
EncryptionTLS 1.3 in transit. AES-256 at rest. Per-tenant data isolation.
HostingTürkiye-only. Maya is a Turkish company; tenant data is processed and stored on servers in Türkiye. No cross-border transfer.
Sub-processorsListed in the DPA. Minimal set. No data sharing with model providers beyond zero-retention enterprise endpoints used for prompt simulation.
Penetration testingAnnual third-party. Executive summary available under NDA.
ComplianceKVKK-aligned. GDPR-aligned. ISO 27001 program in flight.
Incident responseDefined SLA for notification (≤72h material incident, ≤24h confirmed breach).
Customer controlsData export, account deletion, source-side filter customization, per-account email notification controls.

Reference