PricingGetting Started
Legal & Compliance

Privacy Policy

Last Updated: March 2026Version 3.2Applicable to All Exogram Services

1. Introduction & Foundational Principle

Exogram LLC ("Exogram," "we," "our," or "us"), a Washington limited liability company, provides an Authority Runtime and Governed Autonomy Runtime that evaluates autonomous AI agent execution payloads against customer-configured constraints, generating cryptographic audit proofs.

Our fundamental privacy architecture is built on a straightforward principle: we evaluate agent execution payloads; we do not train on your data.

This Privacy Policy explains how we collect, process, secure, retain, and dispose of information when you access our websites, use our APIs and developer tools, or deploy our runtime infrastructure. It also outlines your statutory privacy rights under global data protection frameworks, including the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and related privacy laws.

2. Controller vs. Processor Roles

Data protection laws distinguish between a "Data Controller" (the entity determining the purposes and means of processing) and a "Data Processor" (or "Service Provider," the entity processing data on behalf of a controller).

Exogram as Data Processor:

When you connect autonomous AI agents, register custom vault assertions, or stream execution payloads to Exogram for evaluation and cryptographic logging, you are the Data Controller and Exogram is the Data Processor. We process Customer Data solely in accordance with your documented instructions and our Terms of Service.

Exogram as Data Controller:

Exogram acts as a Data Controller solely with respect to account administrative data (e.g., account holder name, business email, login credentials, and billing invoices) collected directly from you to manage your commercial account relationship with us.

For enterprise customers requiring a formal Data Processing Addendum (DPA) incorporating European Commission Standard Contractual Clauses (SCCs), please contact [email protected].

3. Absolute Zero Model Training Guarantee

Legally Binding Zero Training Commitment:

Exogram does NOT use Customer Data, autonomous agent execution traces, prompt inputs, tool arguments, vault assertions, database schemas, or cryptographic audit logs to train, retrain, calibrate, or fine-tune public or commercial foundational AI models, including models operated by OpenAI, Anthropic, Google, Meta, or any open-weight LLMs.

Your data, prompts, and execution payloads remain your exclusive property. We do not license, sell, or share customer execution data with AI model laboratories or third-party training pipelines under any circumstance.

4. Information We Collect

We collect only the minimum information necessary to authenticate users, evaluate execution constraints, and maintain high-performance, secure infrastructure:

A. Account & Registration Data:

When creating an account, we collect your full name, email address, company name, authentication credentials (managed via Supabase Auth), and organizational role.

B. Billing & Payment Information:

Payment transactions are processed directly by our PCI-DSS Level 1 certified payment processor (Stripe). Exogram does not store full credit card numbers, CVVs, or bank routing details on our servers; we retain only payment tokens, billing addresses, and invoice histories.

C. Agent Execution Telemetry & Vault Data:

To evaluate execution safety, our runtime receives proposed agent tool invocations, parameter keys, cryptographic state integrity hashes, custom vault rules, assertion criteria, and evaluation outcomes (approved, blocked, or deferred). All vault assertions and execution logs are encrypted at rest using AES-256.

D. Device & Technical Telemetry:

Standard technical logs including IP addresses, browser user-agent strings, operating system, referrer headers, API response latencies, error codes, and Cloudflare Turnstile bot verification tokens used strictly for infrastructure security.

5. Lawful Bases for Processing (GDPR Article 6)

If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following lawful bases:

  • Performance of a Contract: Processing necessary to provide the Service, authenticate access, evaluate agent execution constraints, and fulfill our obligations under our Terms of Service.
  • Legitimate Interests: Processing necessary to secure our infrastructure against malicious attacks, prevent DDoS and bot abuse, detect fraudulent billing, and troubleshoot technical errors.
  • Legal Obligations: Retaining financial, tax, and corporate accounting records in accordance with statutory compliance obligations.
  • Consent: Where you have provided clear, affirmative consent (e.g., subscribing to product updates or research bulletins), which may be withdrawn at any time.

6. How We Use Your Information

We use collected information exclusively to:

  1. Evaluate proposed autonomous agent execution payloads against user-configured constraints in real time (sub-millisecond latency);
  2. Generate tamper-evident, cryptographically chained audit ledgers recording evaluation outcomes;
  3. Authenticate user sessions and issue authorized API keys;
  4. Enforce fair use quotas, rate limits, and compute tier thresholds;
  5. Protect the Service against denial-of-service, credential stuffing, and unauthorized penetration attempts;
  6. Provide technical support, incident recovery, and respond to user inquiries;
  7. Send mandatory service notifications, such as security alerts, billing invoices, and policy updates.

7. Subprocessors & Third-Party Service Providers

We engage a limited number of trusted third-party service providers ("Subprocessors") to assist in providing core platform infrastructure. Each subprocessor is vetted for rigorous security standards and bound by contractual data protection agreements:

Cloud Infrastructure & Compute: Vercel Inc. and Amazon Web Services (AWS) — hosting serverless edge functions, CDN routing, and runtime evaluation nodes.
Database & Authentication: Supabase Inc. — managed PostgreSQL database storage, row-level security policies, and user authentication infrastructure.
Payment Processing: Stripe Inc. — tokenized credit card transactions, invoicing, and subscription billing management.
Edge Security & Bot Mitigation: Cloudflare Inc. — Turnstile bot protection, web application firewall (WAF), and DDoS mitigation.

8. No Sale or Sharing of Personal Data (CCPA/CPRA)

Clear CCPA/CPRA Statement: Exogram does NOT sell your personal information, and has never sold personal information. Exogram does NOT share your personal information with third parties for cross-context behavioral advertising or targeted marketing.

We do not monetize personal data or telemetry. Our revenue is derived strictly from developer subscriptions, enterprise licenses, and infrastructure compute tiers.

9. Cross-Border Data Transfers

Exogram is headquartered in the United States, and your data may be transferred to, stored, and processed in the United States and other jurisdictions where our cloud infrastructure providers maintain operations.

When transferring personal data from the European Union, European Economic Area, Switzerland, or the United Kingdom to countries not deemed to provide an adequate level of data protection, we implement appropriate safeguards, primarily the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, supplemented by technical safeguards including AES-256 encryption at rest and TLS 1.3 encryption in transit.

10. Security & Encryption Safeguards

We maintain industry-leading organizational and technical safeguards designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access:

  • Encryption at Rest: All customer vault assertions, memory records, and execution ledger logs are encrypted at rest using AES-256 encryption.
  • Encryption in Transit: All communication between user agents, client SDKs, CLIs, and Exogram API endpoints is secured using TLS 1.3.
  • Cryptographic State Hashing: Execution events are cryptographically hashed, ensuring that audit logs cannot be modified or forged after recording.
  • Access Control & Least Privilege: Strict role-based access control (RBAC), multi-factor authentication (MFA) on all administrative systems, and zero public access to underlying production databases.
  • Automated Scanning: Continuous dependency scanning, static code analysis, and routine automated vulnerability testing.

11. Data Retention & Erasure Protocols

We retain personal information only for as long as necessary to fulfill the purposes outlined in this Policy, satisfy contractual obligations, or comply with mandatory legal requirements:

Vault Assertions & Rules: Retained for the active duration of your account. Customers can update, modify, or permanently delete vault assertions at any time via the API or dashboard.
Audit Ledger Records: Retained according to your chosen plan tier (e.g., 30 days for Free, 90 days for Pro, or customized retention schedules for Enterprise). Expired logs are systematically purged.
Account & Billing Data: Account registration data is deleted upon account closure; financial invoices and tax transaction logs are retained for seven (7) years to comply with statutory accounting and tax regulations.

12. Your Statutory Data Protection Rights

Depending on your geographical jurisdiction, you possess specific statutory rights regarding your personal data under the GDPR, UK GDPR, CCPA/CPRA, and state privacy statutes:

Right to Know / Access: You have the right to request confirmation of whether we process your data and obtain a copy of the personal information we hold.
Right to Rectification: You have the right to request the correction of inaccurate or incomplete personal data.
Right to Erasure (Right to be Forgotten): You have the right to request the hard deletion of your personal information, subject to statutory retention exceptions.
Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV).
Right to Restrict or Object: You have the right to restrict or object to the processing of your personal data under certain conditions.
Right to Non-Discrimination: We will never discriminate against you (through denied services, degraded response times, or altered pricing) for exercising any statutory privacy rights.

How to Exercise Your Rights: To submit a verified privacy request, email [email protected] with your registered account email and specify the request type. We verify your identity before processing and will respond within thirty (30) days (or statutory deadlines).

13. Cookies & Tracking Technologies

Exogram uses only strictly necessary cookies and similar session tokens essential for authentication, security challenge verification (Cloudflare Turnstile), and session integrity.

We do NOT employ third-party advertising tracking cookies, social media tracking pixels, or cross-site tracking scripts. You can configure your browser to block cookies, but doing so may prevent you from authenticating or accessing dashboard functionality.

14. Children's Privacy (COPPA)

The Service is strictly intended for enterprise software engineers, businesses, and adults aged 18 and older. We do not knowingly solicit or collect personal information from individuals under the age of 18 (or the age of legal majority).

If we become aware that we have inadvertently collected personal data from a child under 18, we will take immediate measures to permanently delete such information from our databases. If you believe a minor has registered an account, contact us at [email protected].

15. Security Incident & Breach Notification Protocol

In the event of a confirmed security incident resulting in the unauthorized destruction, loss, alteration, or disclosure of personal data, Exogram will:

  • Immediately initiate incident response procedures to contain, isolate, and mitigate the vulnerability;
  • Notify affected customers without undue delay (and within 72 hours where required by GDPR) from the time of confirmation;
  • Notify relevant regulatory authorities as required under applicable statutory laws;
  • Provide details regarding the nature of the breach, affected data categories, remedial actions taken, and recommended mitigations for customers.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect evolving architectural enhancements, changes in our data practices, or updates in statutory legal requirements.

When modifications are made, we will revise the "Last Updated" date at the top of this page. For material updates, we will provide advance notice via a prominent dashboard banner or direct notification to your registered account email.

17. Contact Information & Regulatory Inquiries

If you have questions, concerns, or requests regarding this Privacy Policy or our data governance practices, please contact our Privacy Team and Data Protection Officer:

Exogram LLC

Privacy & Data Protection Office — A Washington Limited Liability Company

Privacy Contact: [email protected]

Security Team: [email protected]

Legal Department: [email protected]

Jurisdiction: King County, State of Washington, USA

If you are an EEA or UK resident and believe our processing of your personal data violates applicable data protection laws, you retain the statutory right to lodge a complaint with your local supervisory authority (e.g., the UK Information Commissioner's Office or relevant EU Data Protection Authority).