aisecurity.llc
Data Processing Addendum — Public Summary
This is a Public DPA Summary, not an executed agreement. It explains when aisecurity.llc offers a Data Processing Addendum, the topics it covers, and how it relates to the Privacy Policy, Subprocessors list, Evidence Handling Policy, and applicable SOW. A signer-ready or negotiated DPA — with annexes, processing instructions, security measures, audit provisions, transfer mechanisms, subprocessor provisions, and controller/processor obligations — is provided through the contracting process.
A DPA is used when customer personal data is processed on behalf of a customer. Not every scoping conversation requires a DPA. High-level business contact information and non-sensitive scoping usually do not require a full DPA. Customer materials that contain personal data may require a DPA. Confidential, regulated, or security-sensitive materials may also require SOW-, ROE-, or evidence-handling terms even when a DPA is not applicable. Customers should avoid sending personal data or regulated data through public forms. DPA terms may be included in or attached to a private offer, SOW, or enterprise agreement.
1. Plain-English Summary
- This page is a Public DPA Summary. It is not itself the executed DPA.
- A DPA is used when customer personal data is processed on behalf of a customer.
- Not every scoping conversation requires a DPA.
- High-level business contact information and non-sensitive scoping usually do not require a full DPA.
- Customer materials that contain personal data may require a DPA. Confidential, regulated, or security-sensitive materials may also require SOW-, ROE-, or evidence-handling terms even when a DPA is not applicable.
- Customers should avoid sending personal data or regulated data through public forms.
- The executed DPA — with its annexes and specific instructions — controls over this summary for any given engagement.
2. What the Executed DPA Adds
This summary describes our general DPA posture. It does not contain, and should not be read as, the full text of an executed agreement. A signed customer DPA typically adds:
- Annexes describing the specific categories of data, data subjects, and processing activities for that customer.
- Detailed processing instructions from the customer, including any restrictions on AI-assisted processing.
- The specific technical and organizational security measures committed to for that engagement.
- Audit and inspection provisions, including their scope, frequency, and notice requirements.
- International transfer mechanisms applicable to that customer's data flows (for example Standard Contractual Clauses).
- Subprocessor terms, including notification or objection rights specific to that agreement.
- Controller and processor obligations allocated between the parties for that engagement.
None of the specific commitments above are made by this public summary alone. They apply only once a DPA is executed and only as written in that DPA.
3. When a DPA Is Needed
A DPA is typically needed when:
- Customer personal data is processed in a workspace or platform feature.
- Service evidence includes personal data.
- Logs, traces, screenshots, prompts, or artifacts contain personal data.
- LMS, Academy, or Workforce Readiness records are processed for customer users.
- SSO, SAML, OIDC, SCIM, or provisioning data is processed.
- Integrations process employee, customer, or user identity data.
- Workbench Copilot or AI-assisted workflows process personal data under customer instruction.
- Professional services require customer or customer-user personal data.
- A customer's procurement or legal process requires one.
A DPA is not usually needed for:
- Browsing public pages.
- Public research or library pages.
- Basic contact forms using business contact details.
- High-level, non-sensitive scoping.
- Public target information.
- Anonymized or aggregated discussions.
- General sales conversations with no customer personal data.
4. Processing Roles
- The customer is usually controller or business for customer personal data it provides.
- aisecurity.llc may act as processor or service provider for customer personal data processed through platform or services.
- aisecurity.llc may act as independent controller for its own business operations, billing, security, fraud and abuse prevention, and marketing or admin data.
- Exact roles may be defined in the DPA, SOW, order form, or enterprise agreement.
See the controller/processor explanation in the Privacy Policy for the general framework these roles follow.
5. Relationship Matrix
How controller/processor role, agreement type, customer ownership, AI Provider usage, deployment model, and security boundary typically apply differs by product or engagement surface. This table is the shared reference for that breakdown; other policy pages link here instead of repeating it.
Scroll horizontally to see all columns →
| Surface | Controller / Processor | Agreement | Customer Ownership | AI Provider Usage | Deployment Model | Security Boundary |
|---|---|---|---|---|---|---|
| Website | aisecurity.llc acts as independent controller for visitor, prospect, and business-contact data. | Terms of Service and Privacy Policy; no DPA typically required. | Not applicable — no Customer Content is processed on the public site. | Deployment-dependent; limited to enabled public-site AI features, if any. | Hosted Deployment, operated by aisecurity.llc. | Security Practices page and Terms of Service. |
| AI Security Workbench | aisecurity.llc acts as processor/service provider for Customer Data processed through the platform. | DPA plus the applicable SOW, Order Form, Private Offer, or enterprise agreement. | Customer retains ownership of Customer Content, subject to a limited license to provide the Services. | Depends on the enabled feature, customer configuration, and agreement; see AI Usage Policy. | Hosted Deployment by default; Customer-managed Deployment where agreed. | Security Practices page, Evidence Handling Policy, and applicable DPA/SOW. |
| Professional Services | aisecurity.llc acts as processor/service provider for Customer Data used to deliver the engagement, and as controller for its own engagement business records. | Signed SOW, Order Form, Assessment Terms Addendum, and Rules of Engagement where testing is involved. | Customer owns submitted Customer Content and Customer Data; deliverable ownership follows the SOW. | Deployment- and agreement-dependent; AI-free or restricted processing may be available where agreed in writing. | Typically Hosted Deployment tooling operated by aisecurity.llc personnel under the engagement scope. | Evidence Handling Policy, Assessment Terms Addendum, and Rules of Engagement. |
| Academy | aisecurity.llc acts as processor for learner data administered by a customer organization, and as controller for its own course and certification records. | Terms of Service, plus a DPA where learner Personal Data is processed on a customer's behalf. | Customer/learner-submitted data remains customer/learner data; course content is owned by aisecurity.llc. | Deployment-dependent; used only where an AI-assisted training feature is enabled. | Hosted Deployment. | Privacy Policy, DPA, and AI Usage Policy. |
| Workforce Readiness | aisecurity.llc acts as processor for candidate/employee assessment data administered by a customer organization. | Terms of Service, plus a DPA where Personal Data is processed on a customer's behalf. | Customer/candidate-submitted data remains customer/candidate data. | Deployment-dependent; outputs are not used by aisecurity.llc to make automated employment decisions. | Hosted Deployment. | Privacy Policy, DPA, and AI Usage Policy; human review governs consequential employment decisions. |
| OEM | Role depends on the OEM agreement; aisecurity.llc typically has no direct data relationship with the OEM partner's end customers. | Signed OEM or licensing agreement defining responsibility, support, and data boundaries. | Not applicable to aisecurity.llc directly — the OEM partner and its end customers own their respective data and integration. | Deployment-dependent, per the OEM partner's own configuration and agreement. | Customer-managed or partner-managed deployment, per the OEM agreement. | Security Practices page ('Partner and OEM Applicability') and the OEM agreement. |
| Partner | Independent business relationship; not a data-processing relationship unless the partner agreement states otherwise. | Signed partner, reseller, or interoperability agreement. | Not applicable to aisecurity.llc directly unless the partner agreement involves shared customer data. | Deployment-dependent, per the partner integration and agreement. | Varies by partner integration; defined in the partner agreement. | Terms of Service and the applicable partner agreement. |
| Pilot | aisecurity.llc acts as processor/service provider for the bounded Customer Data in scope for the pilot. | Signed pilot SOW defining the bounded input, capability, output contract, data boundary, and IP ownership. | Customer retains ownership of its Customer Content; the data boundary and IP ownership are set out explicitly in the pilot SOW. | Deployment- and agreement-dependent, limited to the selected module in scope. | Hosted Deployment by default, bounded to the pilot scope. | The pilot SOW and the Evidence Handling Policy. |
6. Categories of Personal Data
- Business contact data.
- Account and user profile data.
- Organization and workspace membership.
- Role, entitlement, and seat data.
- SSO, SAML, OIDC, and SCIM identity and provisioning data.
- LMS, Academy, and Workforce Readiness enrollment, progress, and assessment data.
- Support communications.
- Scoping and intake data.
- Uploaded artifacts and evidence where they contain personal data.
- Logs, traces, prompts, screenshots, or reports where they contain personal data.
- Workbench Copilot or chat content where it contains personal data.
- Integration metadata.
- Billing metadata.
7. Processing Purposes When Acting as Processor or Service Provider
When aisecurity.llc acts as a processor or service provider, it processes covered personal data only for customer-instructed purposes documented in the applicable DPA, SOW, order form, or service configuration.
- Provide website, platform, and services.
- Manage accounts, organizations, seats, roles, and entitlements.
- Perform scoping and packet generation.
- Deliver AI Launch, pentest/red-team, product security, governance, training, and related services.
- Provide Workbench Copilot and AI-assisted workflows where enabled.
- Support integrations and connectors.
- Provide LMS, Academy, and Workforce Readiness access.
- Generate reports, evidence packets, and due-diligence artifacts.
- Process private offers, SOWs, NDAs, DPAs, ROEs, and procurement workflows.
- Provide support.
- Secure the platform.
- Prevent abuse.
- Process billing and subscriptions.
- Comply with legal obligations.
8. Subprocessors
See the Subprocessors page for the current public list. This summary does not itself list every subprocessor obligation; those are set out in the executed DPA.
- Subprocessors may include core platform providers, AI Providers, payment processors, communications providers, analytics or diagnostics providers, and customer-configured integrations.
- Not every subprocessor is used for every customer.
- Customer-configured integrations are enabled by the customer or admin and may involve third-party terms.
- Enterprise agreements may define subprocessor notification or objection rights; this summary does not itself grant those rights.
9. AI and Model Training
- Customer data is not used to train public AI models.
- aisecurity.llc does not authorize third-party AI Providers to train on customer content submitted through approved service or platform pathways.
- AI Providers may process inputs and outputs to provide enabled features.
- AI processing may vary by feature, deployment (Hosted Deployment or Customer-managed Deployment), configuration, and agreement.
- Customers may request AI-free or restricted processing for certain professional services where available and agreed in writing.
- DPA or SOW terms may specify AI handling instructions.
10. Security Measures
- Access controls.
- Least privilege.
- Workspace and organization separation.
- Encryption in transit.
- Encryption at rest where supported by infrastructure providers.
- Evidence handling and minimization.
- Redaction defaults.
- Approved intake channels.
- Logging and monitoring where appropriate.
- Vulnerability management.
- Subprocessor and vendor review.
- Incident response process.
See the Security Practices page for the implementation status of each control and the Evidence Handling Policy for the operational summary. The executed DPA states the specific security measures committed to for that engagement.
11. International Transfers
Processing may involve providers or infrastructure outside the customer's jurisdiction. Where required, transfer mechanisms may include SCCs, DPA terms, provider safeguards, or other lawful mechanisms. Exact transfer terms are defined in the executed DPA or enterprise agreement, not in this summary.
12. Deletion and Return
- Return or deletion is handled according to the DPA, SOW, Data Retention & Redaction Policy, and legal obligations.
- Customers may request deletion or export where supported.
- Some records may be retained for billing, legal, security, audit, or fraud-prevention obligations.
- Backups and logs may have limited residual retention.
- Evidence artifacts may have engagement-specific retention rules.
13. Security Incident / Breach Assistance
- Notice and cooperation are defined in the DPA or SOW, not in this summary.
- Customers should provide a security contact.
- Incident handling depends on the nature of the data, service, and agreement.
- Vulnerability reports follow the Vulnerability Disclosure Policy.
14. Data Subject Requests
- The customer is usually responsible for responding to requests about customer personal data.
- aisecurity.llc will provide reasonable assistance as defined in the DPA or SOW.
- Requests related to aisecurity.llc-controlled account or business data may be handled under the Privacy Policy.
15. How to Request a DPA
Tell us:
- Organization name.
- Services or products in scope.
- Jurisdiction or region needs.
- Data categories.
- Whether customer, personal, or regulated data will be processed.
- Whether AI-assisted processing is allowed or restricted.
- Preferred agreement path.
16. Key Terms
- Customer Data
- Any data processed on a customer's behalf through the Services, including Customer Content, account and workspace data, and Personal Data the customer or its users submit or generate.
- Personal Data
- Information that identifies or relates to an identifiable individual, as defined by applicable data protection law. Personal Data may appear in account records, scoping intake, evidence artifacts, or integration metadata.
- AI Provider
- A third-party or internal model provider used to process prompts, content, or artifacts for an AI-assisted feature. Which AI Provider is used, and how it processes data, depends on the deployment, the feature, customer configuration, and the applicable agreement.
- Hosted Deployment
- A deployment model where aisecurity.llc operates the infrastructure, platform, and AI Provider connections used to deliver the Services.
- Customer-managed Deployment
- A deployment model where the customer operates some or all of the infrastructure, AI Provider connections, or execution environment, subject to the applicable agreement. Security and processing characteristics for a Customer-managed Deployment depend on that customer's own configuration and are not identical to a Hosted Deployment.
Data Processing Addendum — Public Summary · aisecurity.llc · Effective June 27, 2026 · Version 1.1