Privacy policy
What we collect, why, how long we keep it and who processes it.
Last updated Sep 4, 2026
01Account data
Name, work email, company name and a password hash. We use it to run your account, to verify your address and to contact you about the service.
02Configuration files
The raw XML you upload is stored in tenant-scoped ephemeral storage and deleted immediately after successful normalization, unless you explicitly enable retention. A failed upload may be kept for no more than 24 hours for troubleshooting.
03Derived data
Normalized entities, findings, evidence records, reports, plans and diagrams are kept for the retention period on your plan, and you can delete them sooner.
04What we never log
Raw configuration, credentials, private keys, certificate material, internal addresses, rule names and client identifiers do not enter analytics, traces, error reports or support bundles.
05Model processing
Where model enrichment is enabled, the model receives normalized, redacted facts for an existing finding. It never receives the raw configuration, and its output is validated against a strict schema.
06Cookies
A session cookie to keep you signed in and a small number of strictly necessary preferences. No advertising cookies and no cross-site tracking.
07Subprocessors
We use a small set of infrastructure providers for hosting, object storage, email delivery, payments and, where enabled, model inference. The current list is available on request.
08Your rights
You can access, correct, export or delete your data from the application, or by writing to us. We answer within thirty days.
09Contact
Write to us with any privacy question, including a request to be told exactly what we hold about you.