Back to Home

Privacy Policy

1. Introduction

Vault Engine Labs™ ("we", "us", "our") operates certosai.com. This policy describes how we collect, use, and protect your information when you use CertosAI™ and related services.

2. Information We Collect

  • Account information: name, email address, job title, company name
  • Usage data: pages visited, features used, timestamps, IP addresses
  • Compliance data: framework selections, agent configurations, compliance scores (processed on behalf of clients)
  • Payment information: processed by Stripe — we do not store card numbers
  • Communications: support requests, feedback

3. How We Use Your Information

  • Provide and improve CertosAI™ services
  • Process transactions via Stripe
  • Send service-related communications
  • Monitor platform security and performance
  • Comply with legal obligations

We do NOT sell your data. We do NOT serve ads. We do NOT use your data for model training.

4. Third-Party Service Providers

Anthropic

AI inference — processes prompts for compliance analysis

Vercel

Hosting — serves application, processes requests

Supabase

Database — stores account and compliance data

Stripe

Payments — processes billing information

Google / Microsoft

SSO — authentication only

Each provider is bound by their respective privacy policies and data processing agreements.

5. Data Retention

We retain account data for the duration of your subscription plus 90 days. Compliance data is retained per your service agreement. You may request deletion at any time.

6. Your Rights

  • GDPR (EU/EEA): Access, rectification, erasure, restriction, portability, objection
  • CCPA (California): Know, delete, opt-out of sale (we don't sell), non-discrimination
  • PIPEDA (Canada): Access, correction, withdrawal of consent

Exercise your rights by contacting legal@certosai.com

7. International Transfers

Data may be processed in Canada, the United States, and the European Union through our service providers. Appropriate safeguards are in place.

8. Security

AES-256 encryption at rest, TLS in transit, row-level security, rate limiting, immutable audit trails. Security rated 10/10 by our internal assessment panel.

9. Children's Privacy

We do not knowingly collect information from children under 16.

10. Changes to This Policy

We will notify you of material changes via email or platform notification.

11. Contact

legal@certosai.com · Vault Engine Labs™ · BC1538454

Last updated: April 5, 2026

© 2026 Vault Engine Labs™. All rights reserved.