Privacy Policy
1. Introduction & Foundational Principle
Exogram LLC ("Exogram," "we," "our," or "us"), a Washington limited liability company, provides an Authority Runtime and Governed Autonomy Runtime that evaluates autonomous AI agent execution payloads against customer-configured constraints, generating cryptographic audit proofs.
Our fundamental privacy architecture is built on a straightforward principle: we evaluate agent execution payloads; we do not train on your data.
This Privacy Policy explains how we collect, process, secure, retain, and dispose of information when you access our websites, use our APIs and developer tools, or deploy our runtime infrastructure. It also outlines your statutory privacy rights under global data protection frameworks, including the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and related privacy laws.
2. Controller vs. Processor Roles
Data protection laws distinguish between a "Data Controller" (the entity determining the purposes and means of processing) and a "Data Processor" (or "Service Provider," the entity processing data on behalf of a controller).
Exogram as Data Processor:
When you connect autonomous AI agents, register custom vault assertions, or stream execution payloads to Exogram for evaluation and cryptographic logging, you are the Data Controller and Exogram is the Data Processor. We process Customer Data solely in accordance with your documented instructions and our Terms of Service.
Exogram as Data Controller:
Exogram acts as a Data Controller solely with respect to account administrative data (e.g., account holder name, business email, login credentials, and billing invoices) collected directly from you to manage your commercial account relationship with us.
For enterprise customers requiring a formal Data Processing Addendum (DPA) incorporating European Commission Standard Contractual Clauses (SCCs), please contact [email protected].
3. Absolute Zero Model Training Guarantee
Legally Binding Zero Training Commitment:
Exogram does NOT use Customer Data, autonomous agent execution traces, prompt inputs, tool arguments, vault assertions, database schemas, or cryptographic audit logs to train, retrain, calibrate, or fine-tune public or commercial foundational AI models, including models operated by OpenAI, Anthropic, Google, Meta, or any open-weight LLMs.
Your data, prompts, and execution payloads remain your exclusive property. We do not license, sell, or share customer execution data with AI model laboratories or third-party training pipelines under any circumstance.
4. Information We Collect
We collect only the minimum information necessary to authenticate users, evaluate execution constraints, and maintain high-performance, secure infrastructure:
A. Account & Registration Data:
When creating an account, we collect your full name, email address, company name, authentication credentials (managed via Supabase Auth), and organizational role.
B. Billing & Payment Information:
Payment transactions are processed directly by our PCI-DSS Level 1 certified payment processor (Stripe). Exogram does not store full credit card numbers, CVVs, or bank routing details on our servers; we retain only payment tokens, billing addresses, and invoice histories.
C. Agent Execution Telemetry & Vault Data:
To evaluate execution safety, our runtime receives proposed agent tool invocations, parameter keys, cryptographic state integrity hashes, custom vault rules, assertion criteria, and evaluation outcomes (approved, blocked, or deferred). All vault assertions and execution logs are encrypted at rest using AES-256.
D. Device & Technical Telemetry:
Standard technical logs including IP addresses, browser user-agent strings, operating system, referrer headers, API response latencies, error codes, and Cloudflare Turnstile bot verification tokens used strictly for infrastructure security.
5. Lawful Bases for Processing (GDPR Article 6)
If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following lawful bases:
- Performance of a Contract: Processing necessary to provide the Service, authenticate access, evaluate agent execution constraints, and fulfill our obligations under our Terms of Service.
- Legitimate Interests: Processing necessary to secure our infrastructure against malicious attacks, prevent DDoS and bot abuse, detect fraudulent billing, and troubleshoot technical errors.
- Legal Obligations: Retaining financial, tax, and corporate accounting records in accordance with statutory compliance obligations.
- Consent: Where you have provided clear, affirmative consent (e.g., subscribing to product updates or research bulletins), which may be withdrawn at any time.
6. How We Use Your Information
We use collected information exclusively to:
- Evaluate proposed autonomous agent execution payloads against user-configured constraints in real time (sub-millisecond latency);
- Generate tamper-evident, cryptographically chained audit ledgers recording evaluation outcomes;
- Authenticate user sessions and issue authorized API keys;
- Enforce fair use quotas, rate limits, and compute tier thresholds;
- Protect the Service against denial-of-service, credential stuffing, and unauthorized penetration attempts;
- Provide technical support, incident recovery, and respond to user inquiries;
- Send mandatory service notifications, such as security alerts, billing invoices, and policy updates.
7. Subprocessors & Third-Party Service Providers
We engage a limited number of trusted third-party service providers ("Subprocessors") to assist in providing core platform infrastructure. Each subprocessor is vetted for rigorous security standards and bound by contractual data protection agreements:
8. No Sale or Sharing of Personal Data (CCPA/CPRA)
We do not monetize personal data or telemetry. Our revenue is derived strictly from developer subscriptions, enterprise licenses, and infrastructure compute tiers.
9. Cross-Border Data Transfers
Exogram is headquartered in the United States, and your data may be transferred to, stored, and processed in the United States and other jurisdictions where our cloud infrastructure providers maintain operations.
When transferring personal data from the European Union, European Economic Area, Switzerland, or the United Kingdom to countries not deemed to provide an adequate level of data protection, we implement appropriate safeguards, primarily the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, supplemented by technical safeguards including AES-256 encryption at rest and TLS 1.3 encryption in transit.
10. Security & Encryption Safeguards
We maintain industry-leading organizational and technical safeguards designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access:
- Encryption at Rest: All customer vault assertions, memory records, and execution ledger logs are encrypted at rest using AES-256 encryption.
- Encryption in Transit: All communication between user agents, client SDKs, CLIs, and Exogram API endpoints is secured using TLS 1.3.
- Cryptographic State Hashing: Execution events are cryptographically hashed, ensuring that audit logs cannot be modified or forged after recording.
- Access Control & Least Privilege: Strict role-based access control (RBAC), multi-factor authentication (MFA) on all administrative systems, and zero public access to underlying production databases.
- Automated Scanning: Continuous dependency scanning, static code analysis, and routine automated vulnerability testing.
11. Data Retention & Erasure Protocols
We retain personal information only for as long as necessary to fulfill the purposes outlined in this Policy, satisfy contractual obligations, or comply with mandatory legal requirements:
12. Your Statutory Data Protection Rights
Depending on your geographical jurisdiction, you possess specific statutory rights regarding your personal data under the GDPR, UK GDPR, CCPA/CPRA, and state privacy statutes:
How to Exercise Your Rights: To submit a verified privacy request, email [email protected] with your registered account email and specify the request type. We verify your identity before processing and will respond within thirty (30) days (or statutory deadlines).
14. Children's Privacy (COPPA)
The Service is strictly intended for enterprise software engineers, businesses, and adults aged 18 and older. We do not knowingly solicit or collect personal information from individuals under the age of 18 (or the age of legal majority).
If we become aware that we have inadvertently collected personal data from a child under 18, we will take immediate measures to permanently delete such information from our databases. If you believe a minor has registered an account, contact us at [email protected].
15. Security Incident & Breach Notification Protocol
In the event of a confirmed security incident resulting in the unauthorized destruction, loss, alteration, or disclosure of personal data, Exogram will:
- Immediately initiate incident response procedures to contain, isolate, and mitigate the vulnerability;
- Notify affected customers without undue delay (and within 72 hours where required by GDPR) from the time of confirmation;
- Notify relevant regulatory authorities as required under applicable statutory laws;
- Provide details regarding the nature of the breach, affected data categories, remedial actions taken, and recommended mitigations for customers.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect evolving architectural enhancements, changes in our data practices, or updates in statutory legal requirements.
When modifications are made, we will revise the "Last Updated" date at the top of this page. For material updates, we will provide advance notice via a prominent dashboard banner or direct notification to your registered account email.
17. Contact Information & Regulatory Inquiries
If you have questions, concerns, or requests regarding this Privacy Policy or our data governance practices, please contact our Privacy Team and Data Protection Officer:
Exogram LLC
Privacy & Data Protection Office — A Washington Limited Liability Company
Privacy Contact: [email protected]
Security Team: [email protected]
Legal Department: [email protected]
Jurisdiction: King County, State of Washington, USA
If you are an EEA or UK resident and believe our processing of your personal data violates applicable data protection laws, you retain the statutory right to lodge a complaint with your local supervisory authority (e.g., the UK Information Commissioner's Office or relevant EU Data Protection Authority).