Privacy

Last updated: 2026-04-29 — placeholder. The final policy ships with v1.0 launch and will be reviewed by counsel.

What we collect

What we don't collect

Where it lives

All scan data + audit logs in the EU (eu-north-1 / Hetzner FSN1). Retention default 30 days; Enterprise tier 7 years for EU AI Act audit-trail requirements. Self-host LLM option keeps inference on customer infrastructure for sovereign-EU customers.

PII-safe LLM preprocessing

Per Patent A IC8: every cloud LLM call passes through a Microsoft Presidio + spaCy NER preprocessor that swaps PII for type-preserving placeholders ([NAME_1], [EMAIL_1], [ADDRESS_1]) before transmission, then restores on response. Round-trip non-PII byte-diff is zero by construction; the audit log records { prompt_redacted, restored_count, leakage_check } per call.

Questions: [email protected].