Privacy & Data Governance Policy
Last Updated: June 28, 2026 | Revision: 1.0.4
Local Threats, Local Inference
No files, prompt text, or workspace contexts are ever sent to external cloud AI engines. Threat analysis runs strictly offline using our managed local Ollama infrastructure.
HMAC-SHA256 Signing
Every packet is cryptographically signed at the agent level using SHA256 hashes. Spoofing device telemetry or impersonating corporate hardware tokens is blocked at the gateway level.
DynamoDB Encrypted Storage
Compliance-oriented telemetry storage utilizing AWS KMS encryption-at-rest. Automatic data pruning removes all telemetry items within 90 days via Time-to-Live (TTL).
1. Scope & Telemetry Collection
The LifecycleZero lightweight workstation agent monitors system-level telemetry. This telemetry strictly includes hardware configuration, active process names (e.g., `ollama.exe`), and access actions for sensitive directories. File contents, code snippets, or user prompt histories are never monitored, read, or stored.
2. Zero-Trust Access Isolation
Admin-initiated containment actions (Device Isolation) execute using DynamoDB atomic `TransactWriteItems` operations. This ensures an absolute state lock and generates an immutable audit custody trail for SOC 2 Type II, ISO 27001, and NIST compliance audits.
3. Third-Party Disclosures
We enforce a strict zero-disclosure policy. No telemetry data, usage metrics, or endpoint reports are shared, sold, or distributed. Since we do not route requests to external cloud model providers (such as OpenAI or AWS Bedrock endpoints), your proprietary information remains inside our private compliance boundary.