Privacy Policy
Last updated: July 27, 2026
What we collect
Account data from Google sign-in (name, email, profile image); the content you provide (agent profiles, control statuses, policy documents, uploaded questionnaires, evidence results, integration configurations); and standard service logs. We do not sell personal data and do not use your content to train models.
How we use it
To operate the service: generating documents you request (content is sent to our LLM provider, Anthropic, for generation and is subject to their API data handling terms), answering questionnaires from your own data, displaying the trust page you choose to publish, and processing payments via Stripe. Integration credentials you provide (e.g. observability API keys, GitHub tokens) are encrypted at rest and used only to perform the actions you configure.
Sign-in data
Google sign-in is used solely for authentication. We request only basic profile scopes and never access your Google data beyond name, email, and profile image. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Sharing
Content you publish to your trust page is public by your choice. Service providers we rely on: hosting infrastructure, Stripe (payments), Anthropic (generation), Resend (email notifications). Each receives only what is necessary to provide their function.
Retention and deletion
Data is retained while your account is active. You can export your content at any time and request deletion of your account and all associated data by emailing us; deletion is completed within 30 days.
Contact
97shivasingh@gmail.com