01. Data Collection
We collect only what an engagement requires: information to reach and work with your team, and the audit material we need to review to assess how your team uses AI coding tools day to day.
Client & Contact Details
Names, roles, company information, and correspondence needed to scope and deliver an audit engagement.
Engagement Data
Reviewed pull requests, codebase excerpts, and AI-usage logs from your team, examined to assess day-to-day AI coding tool usage.
02. Processing Protocols
Processing is kept deliberately narrow to the audit at hand. Material from one engagement is never mixed into another client's audit, and sensitive content found during review is handled carefully before it ever reaches a report.
Sensitive Material Redaction
Credentials, secrets, and proprietary code snippets found while reviewing PRs or codebases are redacted or anonymized before they appear in any report.
Findings Validation
Audit findings are checked against the reviewed evidence before they're written up, so the report reflects what the team actually does.
Engagement Logging
Activity during an engagement is logged so we can account for what was accessed and when, for as long as the engagement is active.
Our contact and audit-request forms use Cloudflare Turnstile, a privacy-friendly CAPTCHA alternative, to protect against spam and automated abuse. Turnstile runs invisibly in most cases and may process technical and usage data as part of that verification. For details, see Cloudflare's Turnstile Privacy Policy.
03. User Rights
You retain control over the data we hold about you and your organization for the duration of an engagement and beyond.
Right of Access
Request a copy of the personal and engagement data we hold about you or your organization.
Right to Erasure
Ask us to delete non-essential data once it's no longer required for an active engagement or legal obligation.
Right to Transparency
Ask how your data was handled during an engagement, including what was reviewed and what was redacted from reporting.
04. Retention Logic
We retain data only for as long as it is required to service active audits or satisfy ongoing obligations, including for clients on a monthly retainer. Retention windows are tied to the specific engagement - a one-off audit's underlying material is retained only as long as needed to finalize the report and support any follow-up, while retainer clients' data is retained for the life of the engagement. Where no active obligation applies, clients may request early deletion at any time through the Right to Erasure process outlined in Section 03.
- Retained only for the duration of active audits or compliance obligations
- Windows scoped to the nature of the engagement (one-off vs. ongoing retainer)
- Early deletion available on request via Right to Erasure