Vault Engine Labs™ ("we", "us", "our") operates certosai.com. This policy describes how we collect, use, and protect your information when you use CertosAI™ and related services.
We do NOT sell your data. We do NOT serve ads. We do NOT use your data for model training.
Anthropic
AI inference — processes prompts for compliance analysis
Vercel
Hosting — serves application, processes requests
Supabase
Database — stores account and compliance data
Stripe
Payments — processes billing information
Google / Microsoft
SSO — authentication only
Each provider is bound by their respective privacy policies and data processing agreements.
We retain account data for the duration of your subscription plus 90 days. Compliance data is retained per your service agreement. You may request deletion at any time.
Exercise your rights by contacting legal@certosai.com
Data may be processed in Canada, the United States, and the European Union through our service providers. Appropriate safeguards are in place.
AES-256 encryption at rest, TLS in transit, row-level security, rate limiting, immutable audit trails. Security rated 10/10 by our internal assessment panel.
We do not knowingly collect information from children under 16.
We will notify you of material changes via email or platform notification.
legal@certosai.com · Vault Engine Labs™ · BC1538454
Last updated: April 5, 2026
© 2026 Vault Engine Labs™. All rights reserved.