Privacy Policy

Last Updated: November 30, 2024

1. Introduction

AIGIS ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cybersecurity platform.

2. Information We Collect

Account Information

  • Email address
  • Encrypted password (we never store plaintext passwords)
  • Account creation date
  • Selected plan (Starter/Pro/Enterprise)

Security Data

  • IP addresses from honeypot attacks
  • Geolocation data of attackers (country-level only)
  • Attack types and timestamps
  • Vulnerability scan results
  • Dark Web breach monitoring queries

Communication Data

  • WhatsApp phone number (only if you enable alerts)
  • Email notification preferences

Usage Analytics

  • Pages visited
  • Features used
  • Time spent on platform
  • Device type and browser information

3. How We Use Your Information

We use the collected information for:

  • Service Provision: To provide security monitoring, threat detection, and alert services
  • Security Alerts: To send real-time notifications via email and WhatsApp
  • Platform Improvement: To analyze usage patterns and improve our features
  • Compliance: To help you meet regulatory requirements (SOC2, HIPAA, GDPR)
  • Support: To respond to your inquiries and provide customer support

4. Data Storage & Security

Where We Store Data

Your data is stored in secure cloud databases (Supabase/PostgreSQL) with encryption at rest. Infrastructure is hosted on AWS/Vercel with enterprise-grade security.

Security Measures

  • End-to-end encryption for sensitive data
  • Bcrypt password hashing (never plaintext storage)
  • Row-Level Security (RLS) to isolate user data
  • Regular security audits and penetration testing
  • SSL/TLS encryption for all data in transit

5. Data Sharing & Disclosure

✓ We DO NOT sell your data

Your security logs, personal information, and usage data are NEVER sold to third parties.

We May Share Data With:

  • Infrastructure Providers: AWS, Vercel, Supabase (to host the service)
  • Analytics Tools: Anonymized usage data for product improvement
  • Law Enforcement: If legally required by court order or subpoena
  • Business Transfers: In case of merger, acquisition, or asset sale

6. Your Rights (GDPR & CCPA)

You Have the Right To:

  • Access: Request a copy of all data we have about you
  • Export: Download your data in machine-readable format (JSON/CSV)
  • Delete: Request permanent deletion of your account and all associated data
  • Correct: Update inaccurate information in your profile
  • Opt-Out: Disable analytics tracking and promotional emails
  • Port: Transfer your data to another service provider

To exercise these rights, email us at privacy@aigis.io

7. Cookies & Tracking

We use the following types of cookies:

  • Essential Cookies: Required for login and session management
  • Analytics Cookies: To understand how you use the platform (you can opt-out)
  • Preference Cookies: To remember your language and theme settings

8. Data Retention

  • Account Data: Retained until you delete your account
  • Security Logs: Stored for 12 months for threat analysis
  • Scan Results: Retained for 6 months
  • Deleted Accounts: Permanently erased within 30 days

9. Third-Party Services

AIGIS integrates with:

  • WhatsApp Business API (for alerts)
  • HaveIBeenPwned API (for breach detection)
  • AWS/GCP/Azure (for cloud integrations)

These services have their own privacy policies. We recommend reviewing them.

10. Children's Privacy

AIGIS is not intended for users under 18 years old. We do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact us immediately.

11. International Data Transfers

Your data may be transferred to and processed in countries outside your residence. We ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses) to protect your data during international transfers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a prominent notice on the platform. Continued use after changes constitutes acceptance.

13. Contact Us

For privacy-related inquiries or to exercise your rights:

Email: privacy@aigis.io

Data Protection Officer: dpo@aigis.io