NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

aisecurity.llc

Privacy Policy

Effective June 27, 2026 · aisecurity.llc

Buyer-focused summary

  • We do not sell personal information.
  • We do not use customer content to train public AI models.
  • Public forms are not for secrets, access keys, regulated production data, or other confidential evidence.
  • AI-assisted outputs that matter to customers require human review.
  • Confidential engagement material is handled under the applicable NDA, SOW, DPA, ROE, or evidence handling terms.
  • For paid professional services, signed agreements can override general website policy language for that engagement.

1. Scope of This Policy

This Privacy Policy covers the public website, trust center, legal pages, service scoping and intake forms, no-cost scoping retainer and NDA workflows, private offers and SOW workflows, the customer portal and platform web UI, SecEng Copilot and other LLM-powered chat features, generated packets and reports, LMS and academy training seats, checkout and subscription flows, and related tools and integrations that aisecurity.llc makes available.

It applies to website visitors, prospects, scoping users, platform users, customer organization members, admins, assigned legal or finance contacts, training users, users of SecEng Copilot, users of a browser extension or native app where available, users of integrations and connectors, and people named in procurement, legal, security, or technical scoping workflows.

For paid professional services or enterprise workspaces, the applicable signed agreement may add more specific terms for that engagement.

2. Data We Collect

We collect the information you provide, information generated by your use of the Services, and limited information from third parties that you authorize or connect. On the public website, we also use cookies and similar technologies for operation, preferences, and analytics; see our Cookie Policy. Do not submit secrets, access keys, customer personal data, regulated production data, or other confidential material through public forms unless an approved secure channel and the applicable agreement path cover it.

2.1 Account and contact data

Names, work emails, phone numbers if provided, company details, job titles, account credentials, communication preferences, and other contact details used to create or manage accounts and communicate about the Services.

2.2 Organization and role data

Organization names, workspace names, user assignments, seat counts, role assignments, entitlements, admin status, approval contacts, team membership, tenant identifiers, and similar data used to manage org workspaces and access controls.

2.3 Billing and transaction metadata

Plan selections, subscription status, invoice records, seat purchases, entitlement changes, transaction IDs, order references, tax or billing contact data, and payment-provider metadata. We do not store full card numbers; card processing is handled by the payment provider.

2.4 Scoping and procurement data

Intake answers, discovery notes, no-cost scoping retainer requests, NDA requests, private offer requests, SOW drafts, DPA requests, ROE terms, approval memos, vendor onboarding materials, contract packet status, and legal, finance, procurement, or security contacts involved in the buying process.

2.5 Service and packet intake data

Service request descriptions, target systems, target URLs, domains, IP ranges, architecture diagrams, system descriptions, questionnaires, evidence requests, assessment goals, and feature-specific inputs needed to scope or generate packets, reports, or work products.

For tools such as the code scanner, adversarial range, RAG harness, artifact analyzer, runtime proxy, or model gateway, this can include the test inputs, trace metadata, routing metadata, and output artifacts needed to operate the feature.

2.6 Target and system metadata

Environment names, cloud account metadata, repository names, app names, deployment metadata, workspace identifiers, SSO tenant identifiers, access boundaries, and other non-secret system descriptors needed to perform the requested service.

2.7 Uploaded artifacts and evidence

Uploaded files, prompts, instructions, logs, traces, screenshots, findings, evidence packs, reports, questionnaire materials, code snippets, trace exports, and assessment artifacts that you choose to submit through the Services or that are generated as part of the work.

2.8 Chat and copilot inputs and outputs

Prompts, questions, messages, files, retrieved context, model outputs, draft packets, citations, and workflow guidance submitted to or generated by SecEng Copilot or other AI-assisted features.

2.9 Integration and connector metadata

Service names, scopes, permissions, sync state, event metadata, and content received from connected services where you authorize an integration. Depending on the feature, this may include metadata from Slack, GitHub, Jira, Google Workspace, Microsoft, Okta, cloud providers, ticketing systems, repositories, LMS tools, or other SaaS services.

2.10 Authentication, SSO, and SCIM data

Sign-in identifiers, SAML, OIDC, or SCIM metadata, provisioning and deprovisioning events, group and role mappings, session data, MFA indicators, and audit events related to enterprise onboarding and identity management.

2.11 Training and LMS usage data

Enrollment and seat assignment data, course progress, completion status, quiz or lab results, badge or certificate status, xAPI or SCORM events, and related training telemetry for academy and LMS users.

2.12 Product telemetry and diagnostics

Feature usage, error logs, request IDs, routing decisions, trace metadata, redaction events, browser or device information, crash data, performance metrics, and diagnostic signals from the website, platform, extension, native app, runtime proxy, model gateway, or trace tooling where enabled.

2.13 Support communications

Support tickets, email threads, chat transcripts, call notes, and attachments you send when asking for help or reporting a problem.

2.14 Security logs and abuse-prevention data

Authentication logs, IP and approximate location data, rate-limit events, suspicious activity records, audit logs, fraud-prevention signals, and investigation data used to secure the Services and respond to abuse or incidents.

3. Sensitive Security Material

Some engagements involve security-sensitive material. That may include architecture diagrams, target URLs, domains, and IP ranges, cloud account metadata, system descriptions, prompts and system instructions, RAG source descriptions, agent tools and actions, logs and traces, screenshots, findings, evidence packs, questionnaire materials, and SOW, ROE, or access details.

We handle that material according to the applicable agreement path, evidence policy, DPA, SOW, ROE, NDA, or other signed terms for the engagement. If no approved secure channel and agreement are in place, do not send secrets, access keys, regulated data, or production credentials through public forms.

4. SecEng Copilot and AI Chat

When SecEng Copilot or another AI-assisted chat feature is enabled, users may submit prompts, questions, files, and artifacts for help with scoping, packet generation, security analysis, drafting, triage, report generation, and workflow guidance.

  • Copilot outputs may be stored with the workspace, intake, or project where needed to provide the Service.
  • Copilot may use approved model providers or internal tooling, depending on the feature and deployment path.
  • Customer content submitted through approved business or API pathways is not authorized for provider model training.
  • Do not submit secrets or regulated data unless the applicable agreement and secure channel allow it.
  • Human review is required before consequential customer-facing deliverables, findings, attestations, claims, or legal or procurement artifacts leave the workflow.
  • Copilot is not a substitute for customer approval, legal advice, or authorized testing boundaries.

See our AI Usage Policy and Customer Data & Model Training page for related commitments.

5. Integrations and Connectors

Where enabled, you may connect third-party services to the Services. The data processed depends on the integration, the permissions you grant, and the feature you use.

  • OAuth scopes and other permissions should be minimized to what you authorize.
  • Customer admins control connection, revocation, and workspace configuration where supported.
  • Connected data is used to provide the requested feature or service.
  • Customer-configured integrations may involve third-party processors that are not used for every customer.
  • Examples, where enabled, may include Slack, GitHub, Jira, Google Workspace, Microsoft, Okta, cloud providers, ticketing systems, repositories, LMS tools, or other SaaS tools.

If you connect a third-party service, its own terms and privacy policy also apply.

6. Browser Extension and Native App

If you use a browser extension or native app where available, the client may process page context, selected text, local files, local traces, request and response metadata, or other security artifacts only as needed for the enabled feature.

  • Local processing may occur where supported by the feature or deployment path.
  • Data sent to aisecurity.llc or to providers depends on the feature configuration and permissions you grant.
  • Do not use the extension or native app to capture data you are not authorized to assess.
  • Diagnostic logs may be collected for reliability, security, and support if enabled.

7. Payments, Subscriptions, Seats, and Entitlements

When you purchase through checkout or manage a subscription, a payment provider such as Stripe processes payment details. We receive transaction metadata, plan information, subscription status, invoice records, seat counts, and entitlement data needed to administer the purchase.

  • Admins may assign seats and roles where the product supports it.
  • Enterprise purchases may use a private offer, SOW, invoice, or contract path instead of self-service checkout.
  • We do not store full card numbers.

8. Legal and Procurement Workflow Data

We collect NDA requests, no-cost scoping retainer information, private offer details, SOW materials, DPA requests, ROE terms, vendor onboarding data, legal, finance, procurement, and security contacts, approval memos, and contract packet status when those workflows are part of the engagement.

We use that information to prepare, approve, administer, and evidence the engagement.

9. How We Use Data

We use data for the following purposes:

  • Provide, operate, and secure the website, platform, and Services.
  • Manage accounts, organizations, workspaces, roles, entitlements, and seat assignments.
  • Process scoping, intake, packet generation, and customer evidence workflows.
  • Prepare private offers, SOWs, contracts, procurement packets, and other commercial documents.
  • Deliver training, licenses, and LMS or academy features.
  • Operate SecEng Copilot, AI chat, runtime proxy, model gateway, trace tooling, and related products.
  • Process integrations and connectors that you choose to enable.
  • Provide support, respond to requests, and communicate about the Services.
  • Prevent abuse, fraud, and unauthorized access.
  • Comply with legal obligations and enforce our agreements.
  • Improve reliability and product experience using appropriate safeguards and limited operational telemetry.

We do not use client confidential engagement materials to train public models, publish examples, or improve unrelated offerings except as permitted by an applicable agreement or written approval.

10. Model Training and AI Providers

Customer data is not used to train public AI models. We do not authorize third-party AI providers to train on customer content submitted through approved business or API pathways.

Provider-specific retention or processing is governed by the provider terms, our agreements, and our subprocessor notices. Customers may request AI-free or restricted processing paths where available and agreed in writing.

See our Customer Data & Model Training page and AI Usage Policy for related details.

11. Sharing and Subprocessors

We do not sell personal information. We may share data with:

  • Hosting, infrastructure, storage, and database providers.
  • Authentication, identity, and security service providers.
  • Analytics, diagnostics, email, and communications providers.
  • Payment processors.
  • Approved AI model providers.
  • Support tools and internal operations tools.
  • Customer-configured integrations that you choose to connect.
  • Legal, compliance, or professional advisers when required.

Some subprocessors are core platform providers. Others are conditional, feature-specific, customer-configured, or only used when a customer enables the relevant integration. See our Subprocessors page for the current list.

12. Retention and Deletion

We retain data for as long as needed for the relevant purpose, which may include:

  • Account and billing records for service delivery, tax, accounting, fraud, legal, and contractual needs.
  • Scoping and intake records to administer the engagement and preserve the evidence trail.
  • Security evidence according to the applicable SOW, evidence handling terms, retention policy, or customer instructions.
  • Generated packets and reports in the customer workspace unless deleted or expired under the agreement.
  • Logs and telemetry for limited operational and security periods.

Deletion requests are honored subject to legal, security, billing, and contractual requirements. If a customer-specific retention or redaction policy applies, that policy controls for that engagement.

13. Security

We use access controls, least privilege, role-based access, workspace separation, encryption in transit and at rest where supported, audit logging where appropriate, and secure handling practices for credentials and secrets.

We also review vendors before use and provide a vulnerability disclosure path for security issues. No system is perfectly secure.

To report a security vulnerability, see our Vulnerability Disclosure Policy.

14. Customer and Admin Controls

  • Admins can manage users, seats, roles, and workspace access where available.
  • Integrations can be revoked where supported.
  • Customers can request deletion or export subject to agreement and law.
  • Customers can choose scoped agreement paths for confidential or security-sensitive material.
  • Customers can avoid submitting sensitive details until an NDA, SOW, DPA, or ROE is in place.

15. International Transfers

aisecurity.llc is based in the United States. If you use the Services from outside the US, your data may be transferred to and processed in the US or other jurisdictions where our providers operate.

Where required, we use standard contractual clauses or comparable transfer mechanisms with our providers and agreements.

16. Children

Our Services are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has submitted personal information to us, contact privacy@aisecurity.llc and we will address it.

17. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, port, or object to certain processing, and to withdraw consent where processing is consent-based.

California residents may have additional rights under the CCPA/CPRA. EEA, UK, and Swiss residents may also have the right to complain to a local data protection authority.

To exercise a right, email privacy@aisecurity.llc with enough information for us to verify your request. We will respond as required by applicable law.

18. Relationship to Contracts

This Privacy Policy describes general practices. For paid professional services, private offers, security testing, customer data processing, or enterprise workspaces, the applicable SOW, DPA, NDA, ROE, evidence handling policy, or other signed agreement may provide more specific terms.

If there is a conflict for that engagement, the signed agreement controls to the extent permitted by law.

19. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date and provide notice through the site or by email when appropriate.

20. Contact Us

For questions about this Privacy Policy or our data practices:

Privacy Policy · aisecurity.llc · Effective June 27, 2026 · Version 2.0

← Back to Legal