Effective Date: December 19, 2025
Version: 1.0


Our Commitment

AegisPrime is built by security professionals, for security professionals. We understand data sensitivity and have designed our platform with privacy as a core principle.


Data We Collect

What You Submit for Analysis

  • Security alerts, logs, or event data you paste into the console
  • Processing: Analyzed in-memory only
  • Storage: Raw alert text is not retained as long-term stored content
  • Retention: Raw analysis input is not used for model training or resale

Analysis Results

  • Determinations, risk/severity, confidence, recommended actions, and response drafts generated by the Service
  • Storage: May be retained when a guided case is saved for case queue review and follow-up
  • Retention: Retained only as needed to provide case review, lifecycle, and operational follow-up features

Usage Data

  • Request counts associated with access keys
  • Timestamps of requests
  • Guided workflow type, outcome, severity, confidence, and validation status in aggregate
  • Purpose: Service quality and rate limiting

What We Do NOT Collect

  • Raw guided answers, response drafts, handoff text, or operator notes for telemetry
  • Personal identifiable information (PII) intentionally extracted from your alerts for resale or advertising
  • IP addresses of your SOC endpoints
  • Customer/client data for training public AI models

How We Use Data

Purpose Data Used
Provide guided analysis Submitted case details and structured workflow inputs
Display and save cases Guided result snapshots and saved case metadata
Rate limiting Request counts associated with access keys
Service improvement Aggregate usage stats without raw case content

Data Sharing

We do NOT:

  • Sell your data to anyone
  • Share data with advertisers
  • Use your data to train public AI models
  • Provide data to third parties

We MAY:

  • Use third-party threat intelligence APIs (OTX, UrlScan) to enrich analysis
  • These services only receive artifact hashes/values, not full alert context

Data Security

  • All traffic encrypted via HTTPS/TLS
  • Access keys hashed before storage (SHA-256)
  • No sale or public-model training use of submitted alert content
  • Infrastructure hosted in US-based data centers (Railway/Cloudflare)

Your Rights

You may:

  • Request deletion of any stored data
  • Revoke your access key at any time
  • Request information about data we hold

Contact: [email protected]


Children’s Privacy

AegisPrime is a professional security tool not intended for users under 18.


Changes to This Policy

We may update this policy. Material changes will be communicated to authorized users when practical.


Contact

AegisPrime
Email: [email protected]


Last Updated: December 19, 2025