aisecurity.llc
Privacy Policy
Effective June 27, 2026 · aisecurity.llc
Buyer-focused summary
- We do not sell personal information.
- We do not use customer content to train public AI models.
- Public forms are not for secrets, access keys, regulated production data, or other confidential evidence.
- AI-assisted outputs that matter to customers require human review.
- Confidential engagement material is handled under the applicable NDA, SOW, DPA, ROE, or evidence handling terms.
- For paid professional services, signed agreements can override general website policy language for that engagement.
1. Scope of This Policy
This Privacy Policy covers the public website, trust center, legal pages, service scoping and intake forms, no-cost scoping retainer and NDA workflows, private offers and SOW workflows, the customer portal and platform web UI, Workbench Copilot and other LLM-powered chat features, generated packets and reports, LMS and academy training seats, checkout and subscription flows, and related tools and integrations that aisecurity.llc makes available.
It applies to website visitors, prospects, scoping users, platform users, customer organization members, admins, assigned legal or finance contacts, training users, users of Workbench Copilot, users of a browser extension or native app where available, users of integrations and connectors, and people named in procurement, legal, security, or technical scoping workflows.
For paid professional services or enterprise workspaces, the applicable signed agreement may add more specific terms for that engagement.
2. Controller and Processor Roles
aisecurity.llc acts as a controller for data it collects to run its own business — website analytics, prospect and account data, billing and tax records, marketing communications, and security or fraud-prevention data.
aisecurity.llc acts as a processor or service provider for Customer Data submitted through the platform, scoping workflows, or Professional Services, and processes that data only for the customer-instructed purposes documented in the applicable DPA, SOW, order form, or service configuration.
The same customer relationship can involve both roles at once — for example, aisecurity.llc is a controller for the billing contact's account data and a processor for the Customer Content that contact's organization submits for a security review. See the Relationship Matrix in the Data Processing Addendum — Public Summary for how this typically breaks down by product or engagement surface.
2.1 Lawful basis (where GDPR, UK GDPR, or a similar law applies)
Where a lawful-basis framework applies, we generally rely on the following. A given purpose can rely on more than one basis depending on the deployment, feature, and agreement in place.
| Purpose | Typical lawful basis |
|---|---|
| Creating and administering an account, workspace, or engagement | Performance of a contract |
| Billing, invoicing, seats, and entitlements | Performance of a contract; legal obligation (tax, accounting) |
| Scoping, packet generation, and service delivery | Performance of a contract; legitimate interests in operating the Services |
| Security, fraud, and abuse prevention | Legitimate interests; legal obligation where applicable |
| AI-assisted features (Workbench Copilot and similar) | Performance of a contract or legitimate interests, depending on the feature and agreement |
| Non-essential analytics and similar cookies | Consent, where required by applicable law |
| Legal claims, disputes, and compliance | Legal obligation; legitimate interests |
3. Data We Collect
We collect the information you provide, information generated by your use of the Services, and limited information from third parties that you authorize or connect. On the public website, we also usecookies and similar technologies for essential operation, saved preferences, and analytics where enabled. See the Cookie Policy for categories, purposes, providers, retention, and available controls.Do not submit secrets, access keys, customer personal data, regulated production data, or other confidential material through public forms unless an approved secure channel and the applicable agreement path cover it.
3.1 Account and contact data
Names, work emails, phone numbers if provided, company details, job titles, account credentials, communication preferences, and other contact details used to create or manage accounts and communicate about the Services.
3.2 Organization and role data
Organization names, workspace names, user assignments, seat counts, role assignments, entitlements, admin status, approval contacts, team membership, tenant identifiers, and similar data used to manage org workspaces and access controls.
3.3 Billing and transaction metadata
Plan selections, subscription status, invoice records, seat purchases, entitlement changes, transaction IDs, order references, tax or billing contact data, and payment-provider metadata. We do not store full card numbers; card processing is handled by the payment provider.
3.4 Scoping and procurement data
Intake answers, discovery notes, no-cost scoping retainer requests, NDA requests, private offer requests, SOW drafts, DPA requests, ROE terms, approval memos, vendor onboarding materials, contract packet status, and legal, finance, procurement, or security contacts involved in the buying process.
3.5 Service and packet intake data
Service request descriptions, target systems, target URLs, domains, IP ranges, architecture diagrams, system descriptions, questionnaires, evidence requests, assessment goals, and feature-specific inputs needed to scope or generate packets, reports, or work products.
For AI Security Workbench tools, this can include the test inputs, trace metadata, routing metadata, and output artifacts needed to operate the feature you use.
3.6 Target and system metadata
Environment names, cloud account metadata, repository names, app names, deployment metadata, workspace identifiers, SSO tenant identifiers, access boundaries, and other non-secret system descriptors needed to perform the requested service.
3.7 Uploaded artifacts and evidence
Uploaded files, prompts, instructions, logs, traces, screenshots, findings, evidence packs, reports, questionnaire materials, code snippets, trace exports, and assessment artifacts that you choose to submit through the Services or that are generated as part of the work.
3.8 Chat and copilot inputs and outputs
Prompts, questions, messages, files, retrieved context, model outputs, draft packets, citations, and workflow guidance submitted to or generated by Workbench Copilot or other AI-assisted features.
3.9 Integration and connector metadata
Service names, scopes, permissions, sync state, event metadata, and content received from connected services where you authorize an integration. Depending on the feature, this may include metadata from Slack, GitHub, Jira, Google Workspace, Microsoft, Okta, cloud providers, ticketing systems, repositories, LMS tools, or other SaaS services.
3.10 Authentication, SSO, and SCIM data
Sign-in identifiers, SAML, OIDC, or SCIM metadata, provisioning and deprovisioning events, group and role mappings, session data, MFA indicators, and audit events related to enterprise onboarding and identity management.
3.11 Training and workforce readiness usage data
Enrollment and seat assignment data, course progress, completion status, quiz or lab results, badge or certificate status, xAPI or SCORM events, readiness-survey responses, interview-practice records, and related training or assessment telemetry for Academy and Workforce Readiness users.
3.12 Product telemetry and diagnostics
Feature usage, error logs, request IDs, routing decisions, trace metadata, redaction events, browser or device information, crash data, performance metrics, and diagnostic signals from the website, platform, extension, native app, or AI Security Workbench tooling where enabled.
3.13 Support communications
Support tickets, email threads, chat transcripts, call notes, and attachments you send when asking for help or reporting a problem.
3.14 Security logs and abuse-prevention data
Authentication logs, IP and approximate location data, rate-limit events, suspicious activity records, audit logs, fraud-prevention signals, and investigation data used to secure the Services and respond to abuse or incidents.
4. Sensitive Security Material
Some engagements involve security-sensitive material. That may include architecture diagrams, target URLs, domains, and IP ranges, cloud account metadata, system descriptions, prompts and system instructions, RAG source descriptions, agent tools and actions, logs and traces, screenshots, findings, evidence packs, questionnaire materials, and SOW, ROE, or access details.
We handle that material according to the applicable agreement path, evidence policy, DPA, SOW, ROE, NDA, or other signed terms for the engagement. If no approved secure channel and agreement are in place, do not send secrets, access keys, regulated data, or production credentials through public forms.
5. Workbench Copilot and AI Chat
When Workbench Copilot or another AI-assisted chat feature is enabled, users may submit prompts, questions, files, and artifacts for help with scoping, packet generation, security analysis, drafting, triage, report generation, and workflow guidance.
- Copilot outputs may be stored with the workspace, intake, or project where needed to provide the Service.
- Copilot may use approved AI Providers or internal tooling, depending on the feature and deployment path.
- Customer content submitted through approved business or API pathways is not authorized for AI Provider model training.
- Do not submit secrets or regulated data unless the applicable agreement and secure channel allow it.
- Human review is required before consequential customer-facing deliverables, findings, attestations, claims, or legal or procurement artifacts leave the workflow.
- Copilot is not a substitute for customer approval, legal advice, or authorized testing boundaries.
See our AI Usage Policy and Customer Data & Model Training page for related commitments.
6. Integrations and Connectors
Where enabled, you may connect third-party services to the Services. The data processed depends on the integration, the permissions you grant, and the feature you use.
- OAuth scopes and other permissions should be minimized to what you authorize.
- Customer admins control connection, revocation, and workspace configuration where supported.
- Connected data is used to provide the requested feature or service.
- Customer-configured integrations may involve third-party processors that are not used for every customer.
- Examples, where enabled, may include Slack, GitHub, Jira, Google Workspace, Microsoft, Okta, cloud providers, ticketing systems, repositories, LMS tools, or other SaaS tools.
If you connect a third-party service, its own terms and privacy policy also apply.
7. Browser Extension and Native App
If you use a browser extension or native app where available, the client may process page context, selected text, local files, local traces, request and response metadata, or other security artifacts only as needed for the enabled feature.
- Local processing may occur where supported by the feature or deployment path.
- Data sent to aisecurity.llc or to AI Providers depends on the feature configuration and permissions you grant.
- Do not use the extension or native app to capture data you are not authorized to assess.
- Diagnostic logs may be collected for reliability, security, and support if enabled.
8. Payments, Subscriptions, Seats, and Entitlements
When you purchase through checkout or manage a subscription, a payment provider such as Stripe processes payment details. We receive transaction metadata, plan information, subscription status, invoice records, seat counts, and entitlement data needed to administer the purchase.
- Admins may assign seats and roles where the product supports it.
- Enterprise purchases may use a private offer, SOW, invoice, or contract path instead of self-service checkout.
- We do not store full card numbers.
9. Legal and Procurement Workflow Data
We collect NDA requests, no-cost scoping retainer information, private offer details, SOW materials, DPA requests, ROE terms, vendor onboarding data, legal, finance, procurement, and security contacts, approval memos, and contract packet status when those workflows are part of the engagement.
We use that information to prepare, approve, administer, and evidence the engagement.
10. How We Use Data
We use data for the following purposes:
- Provide, operate, and secure the website, platform, and Services.
- Manage accounts, organizations, workspaces, roles, entitlements, and seat assignments.
- Process scoping, intake, packet generation, and customer evidence workflows.
- Prepare private offers, SOWs, contracts, procurement packets, and other commercial documents.
- Deliver Academy and Workforce Readiness training, licenses, and reporting features.
- Operate Workbench Copilot, AI chat, and other AI Security Workbench tools.
- Process integrations and connectors that you choose to enable.
- Provide support, respond to requests, and communicate about the Services.
- Prevent abuse, fraud, and unauthorized access.
- Comply with legal obligations and enforce our agreements.
- Improve reliability and product experience using appropriate safeguards and limited operational telemetry.
We do not use client confidential engagement materials to train public models, publish examples, or improve unrelated offerings except as permitted by an applicable agreement or written approval.
11. AI Providers and Deployment-Aware Processing
Customer data is not used to train public AI models. We do not authorize third-party AI Providers to train on customer content submitted through approved business or API pathways.
How an AI Provider processes data is not identical across the Services. It depends on the deployment (Hosted Deployment or Customer-managed Deployment), the customer's configuration, the specific feature invoked, and the applicable agreement. A feature available in a Hosted Deployment may route to a different AI Provider, or none, in a Customer-managed Deployment.
Provider-specific retention or processing is governed by the provider terms, our agreements, and our subprocessor notices. Customers may request AI-free or restricted processing paths where available and agreed in writing.
See our Customer Data & Model Training page and AI Usage Policy for related details.
13. Retention and Deletion
There is no single universal retention schedule. How long we retain a given record depends on the combination of:
- The applicable agreement (SOW, DPA, NDA, ROE, Evidence Handling Policy, or Data Retention & Redaction Policy).
- The account or workspace type and whether it remains active.
- Legal, tax, accounting, audit, and other legal obligations.
- Security needs, including fraud, abuse, and incident-response records.
- Customer instructions, where the applicable agreement gives the customer retention or deletion control.
- Product or feature configuration, including customer-selected retention settings where offered.
Within those constraints, retention generally follows:
- Account and billing records for service delivery, tax, accounting, fraud, legal, and contractual needs.
- Scoping and intake records to administer the engagement and preserve the evidence trail.
- Security evidence according to the applicable SOW, evidence handling terms, retention policy, or customer instructions.
- Generated packets and reports in the customer workspace unless deleted or expired under the agreement.
- Logs and telemetry for limited operational and security periods.
Deletion requests are honored subject to legal, security, billing, and contractual requirements. If a customer-specific retention or redaction policy applies, that policy controls for that engagement.
14. Security
We use access controls, least privilege, role-based access, workspace separation, encryption in transit and at rest where supported, audit logging where appropriate, and secure handling practices for credentials and secrets. See the Security Practices page for the current implementation status of each control.
We also review vendors before use and provide a vulnerability disclosure path for security issues. No system is perfectly secure.
To report a security vulnerability, see our Vulnerability Disclosure Policy.
15. Customer and Admin Controls
- Admins can manage users, seats, roles, and workspace access where available.
- Integrations can be revoked where supported.
- Customers can request deletion or export subject to agreement and law.
- Customers can choose scoped agreement paths for confidential or security-sensitive material.
- Customers can avoid submitting sensitive details until an NDA, SOW, DPA, or ROE is in place.
16. International Transfers
aisecurity.llc is based in the United States. If you use the Services from outside the US, your data may be transferred to and processed in the US or other jurisdictions where our providers operate.
Where required, transfer safeguards may include Standard Contractual Clauses or other lawful mechanisms documented in the applicable DPA, provider terms, or enterprise agreement.
17. Children
The Services are intended for business, professional, and enterprise-training use and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has submitted personal information to us, contact privacy@aisecurity.llc and we will address it.
18. Workforce Readiness, Academy, and Human Decision-Making
Workforce Readiness and Academy features can produce readiness scores, practice feedback, credential status, and similar outputs about a candidate, employee, or learner. aisecurity.llc does not use those outputs to make automated employment decisions on its own behalf. Where a customer uses Workforce Readiness or Academy outputs to inform its own hiring, promotion, or training decisions, that customer is responsible for ensuring a human reviews and remains accountable for the consequential decision.
This boundary applies in addition to, and does not replace, the human-review requirements in our AI Usage Policy.
19. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, port, or object to certain processing, and to withdraw consent where processing is consent-based.
California residents may have additional rights under the CCPA/CPRA. EEA, UK, and Swiss residents may also have the right to complain to a local data protection authority.
To exercise a right, email privacy@aisecurity.llc with enough information for us to verify your request. We will respond as required by applicable law.
20. Relationship to Contracts
This Privacy Policy describes general practices. For paid professional services, private offers, security testing, customer data processing, or enterprise workspaces, the applicable SOW, DPA, NDA, ROE, evidence handling policy, or other signed agreement may provide more specific terms.
If there is a conflict for that engagement, the signed agreement controls to the extent permitted by law.
This Privacy Policy works together with the Terms of Service, AI Usage Policy, Responsible AI governance page, Data Processing Addendum — Public Summary, and Security Practices page. Where those documents overlap, the more specific document controls for that topic.
21. Key Terms
- Customer Content
- Files, prompts, targets, code, findings, artifacts, and other material a customer or its users submit to or generate through the Services. The customer retains ownership of Customer Content, subject to the limited license needed to provide the Services.
- Customer Data
- Any data processed on a customer's behalf through the Services, including Customer Content, account and workspace data, and Personal Data the customer or its users submit or generate.
- Personal Data
- Information that identifies or relates to an identifiable individual, as defined by applicable data protection law. Personal Data may appear in account records, scoping intake, evidence artifacts, or integration metadata.
- AI Provider
- A third-party or internal model provider used to process prompts, content, or artifacts for an AI-assisted feature. Which AI Provider is used, and how it processes data, depends on the deployment, the feature, customer configuration, and the applicable agreement.
- Hosted Deployment
- A deployment model where aisecurity.llc operates the infrastructure, platform, and AI Provider connections used to deliver the Services.
- Customer-managed Deployment
- A deployment model where the customer operates some or all of the infrastructure, AI Provider connections, or execution environment, subject to the applicable agreement. Security and processing characteristics for a Customer-managed Deployment depend on that customer's own configuration and are not identical to a Hosted Deployment.
- Academy
- The LMS-based training product providing courses, labs, and certification workflows for security engineering and AI security skills, accessed through seat-based licenses.
- Workforce Readiness
- The AI Security Workforce Readiness product line (role taxonomy, readiness surveys, interview practice, hiring calibration, and workforce reporting) used to assess and develop AI security skills for candidates, employees, and hiring teams.
22. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date and provide notice through the site or by email when appropriate.
23. Contact Us
For questions about this Privacy Policy or our data practices:
- Privacy: privacy@aisecurity.llc
- Legal: legal@aisecurity.llc
- Security: security@aisecurity.llc
- Website: aisecurity.llc
Privacy Policy · aisecurity.llc · Effective June 27, 2026 · Version 2.1