Skip to content
Legal

Data Processing Addendum

This summary describes how we process personal data as your processor. A full, signable DPA (with Standard Contractual Clauses) is available on request and forms part of your agreement.

Last updated: August 14, 2026

Roles

For platform data, you are the controller and we are the processor. We process personal data only on your documented instructions and for the purpose of providing the Platform and Services.

Scope of processing

Subject matter: AI-usage security telemetry and console data. Data subjects: your workforce/endpoint users. Data types: machine/user attribution, AI-tool metadata, key presence (not values), audit logs — as detailed in the Trust Center. We do not process special-category data by design.

Security measures

Encryption in transit (TLS 1.2+) and at rest; RBAC and MFA; least-privilege access; tenant isolation; secret masking at collection; tamper-evident audit logging; and, optionally, fully in-VPC processing with no egress.

Subprocessors

The current list is published in the Trust Center. We will give notice of new subprocessors and offer you the right to object. In-VPC deployments use no external data subprocessors.

Data-subject requests

We assist you in responding to access, deletion, correction and portability requests, and forward any request we receive directly to you.

Breach notification

We notify you without undue delay and within 72 hours of confirming a personal-data breach affecting your data, with the information you need to meet your own obligations.

Deletion & return

On termination we make your data available for export for 30 days, then delete it (and instruct subprocessors to do the same) unless retention is legally required.

Need a signed DPA + SCCs? Request it here and we'll return an executable copy.