Last updated · 23 July 2026
How we process and protect personal data.
Technical identifiers (hostname, UUID), system and network activity of protected endpoints, and AI decisions. No file content or full email is stored.
Detect, qualify and respond to security incidents on endpoints, and improve our detection models.
Raw logs and activity: 90 days. Decisions and annotations: 365 days. Durations can be adapted contractually.
Access, rectification, erasure, portability, and the right not to be subject to a fully automated decision, mitigated by SHAP explainability and human review.
Encryption in transit and at rest, internal mTLS, vault-based secret management and an immutable audit log.