Privacy Policy
Last updated: February 2026
1. Introduction
Agent-Shield ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service, including our website, APIs, and related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the Service.
2. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Password (encrypted and hashed)
- Account creation date
- Email verification status
Usage Data
When you use the Service, we automatically collect:
- Agent call logs (timestamps, agent IDs, tool calls, security alerts)
- API key metadata (key names, creation dates, last used dates, revocation status)
- Security policies (policy names, rules, severity levels)
- Monthly usage statistics (number of agent calls and audits per month)
- IP addresses (for security and abuse prevention)
- Browser type and version
- Device information
Agent Interaction Data
To provide security monitoring, we collect:
- Agent prompts and inputs (for security analysis)
- Tool names and function calls
- Security verdicts (allow/block decisions)
- Alert details (when security policies are triggered)
- Agent metadata (agent IDs, names, descriptions)
Note: We do NOT store the actual responses or outputs from your agents — only the security-relevant metadata needed to protect your application.
Security Audit Data
When you run security audits through the Service, we collect and process:
- Agent endpoint URLs submitted for testing
- Audit configuration (selected modules, test parameters)
- Test payloads sent to your agent during security testing (e.g., injection probes, permission escalation attempts)
- Agent responses to audit test payloads (used for vulnerability analysis)
- Vulnerability findings, severity scores, and compliance mappings
- Generated audit reports and PDF exports
Audit data is associated with your account and is not shared with other users. Agent responses collected during audits are used solely for security analysis and scoring — they are not used to train AI models or shared with third parties.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Monitor and analyze agent security in real-time
- Execute security audits including injection testing, permission analysis, PII detection, data flow mapping, and compliance mapping
- Generate vulnerability scores, findings, and audit reports
- Detect and prevent security threats, abuse, and fraud
- Enforce our rate limits, billing tiers, and usage policies
- Send you technical notices, updates, and security alerts
- Respond to your comments, questions, and customer support requests
- Generate analytics and usage reports for your dashboard
- Comply with legal obligations and enforce our Terms of Service
4. AI Processing Disclosure
Agent-Shield uses artificial intelligence and large language models (LLMs) as a core part of the Service. We are transparent about how AI is used to process your data:
Security Analysis
AI models analyze your agent's responses to security test payloads to determine whether vulnerabilities exist. This includes evaluating responses against multiple criteria such as instruction compliance, refusal detection, data leakage, and prompt injection susceptibility.
Compliance Mapping
AI models map audit findings to regulatory frameworks (SOC 2, HIPAA, GDPR, EU AI Act) to generate compliance assessments and recommendations.
Data Handling
Data sent to AI models for analysis is processed in real-time and is not retained by the AI model provider for training purposes. We use enterprise-grade AI APIs with data processing agreements that prohibit the use of your data for model training or improvement.
No Automated Decision-Making
AI-generated findings and scores are informational. The Service does not make automated decisions that produce legal effects or similarly significant effects concerning you. All audit results should be reviewed by qualified security professionals.
5. Data Storage and Security
Where We Store Your Data
Your data is stored securely using enterprise-grade cloud infrastructure, including:
- Authentication: Account credentials and authentication tokens are stored with industry-standard encryption
- Application Data: Agent calls, policies, alerts, audit results, and usage data are stored in managed database services
- Audit Reports: Generated PDF reports are stored in encrypted cloud storage
All data is stored in data centers with enterprise-grade physical security, and all data is encrypted at rest (AES-256) and in transit (TLS 1.3).
Security Measures
We implement industry-standard security measures to protect your data:
- TLS 1.3 encryption for all data transmission
- AES-256 encryption at rest for all stored data
- Encrypted password storage using secure hashing algorithms
- API key encryption and secure key management
- Role-based access controls and security rules to prevent unauthorized access
- Regular security audits and monitoring
- Rate limiting to prevent abuse
Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you via email within 72 hours of becoming aware of the breach, as required by applicable data protection laws.
6. Data Retention
Data retention periods vary based on your subscription tier and the type of data:
Account Data
Retained until you delete your account. After deletion, personal information is removed within 30 days, except where retention is required for legal or regulatory purposes.
Audit Results and Reports
- Free tier: Audit results retained for 30 days
- Pro tier: Audit results retained for 1 year
- Enterprise tier: Custom retention period per your agreement
- One-time audits: Audit results retained for 90 days
Agent Call Logs
Retained for 90 days for analytics and security purposes, regardless of tier.
Other Data
- Security alerts: Retained for 90 days or until manually dismissed
- Usage statistics: Retained for 12 months for billing and analytics
- API keys: Retained until manually revoked
7. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- Infrastructure Providers: We share data with cloud infrastructure providers to provide hosting, storage, database, and computing services necessary to operate the Service.
- AI Model Providers: Audit data is sent to AI model providers for security analysis. These providers operate under data processing agreements that prohibit using your data for model training.
- Payment Processor: Billing and payment information is processed by Stripe. We do not store your full credit card details. See Stripe's privacy policy at stripe.com/privacy for details.
- Legal Requirements: We may disclose your information if required by law, court order, or government regulation, or to protect our rights and safety.
- Business Transfers: If Agent-Shield is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
- With Your Consent: We may share your information for any other purpose with your explicit consent.
8. Your Rights and Choices
You have the following rights regarding your personal information:
Access and Portability
You can access and export your data at any time through your dashboard. Contact us at support@agent-shield.com to request a complete copy of your data.
Correction
You can update your account information (email) through your account settings page.
Deletion
You can delete your account at any time through your settings page or by contacting us. Upon deletion, all your personal data will be removed within 30 days.
Objection and Restriction
You can object to or restrict certain data processing activities by contacting us. However, this may limit your ability to use certain features of the Service.
Opt-Out
You can opt out of marketing emails by clicking the "unsubscribe" link in any email we send. Note that you cannot opt out of essential service-related emails (e.g., security alerts, account notifications).
9. GDPR Compliance (European Users)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
Legal Basis for Processing
We process your personal data based on:
- Consent: You have given explicit consent for us to process your data
- Contract: Processing is necessary to perform our contract with you (Terms of Service)
- Legitimate Interests: Processing is necessary for our legitimate interests (e.g., fraud prevention, security)
Data Processing Agreements
We maintain Data Processing Agreements (DPAs) with all sub-processors who handle personal data on our behalf, including infrastructure providers, AI model providers, and payment processors. Enterprise customers may request a copy of our DPA or execute a custom DPA by contacting privacy@agent-shield.com.
Data Protection Officer
For GDPR-related inquiries, please contact our data protection officer at: privacy@agent-shield.com
Right to Lodge a Complaint
You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.
10. CCPA/CPRA Compliance (California Residents)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
Right to Know
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, our business purpose for collecting it, and the categories of third parties with whom we share it.
Right to Delete
You have the right to request deletion of your personal information, subject to certain exceptions (such as data needed to complete a transaction or comply with legal obligations).
Right to Correct
You have the right to request correction of inaccurate personal information we hold about you.
Right to Opt-Out of Sale or Sharing
We do not sell or share your personal information as defined under the CCPA/CPRA. We do not use your personal information for cross-context behavioral advertising.
Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights. You will not receive different pricing, quality of service, or level of service for exercising your rights.
How to Exercise Your Rights
To exercise any of these rights, contact us at privacy@agent-shield.com or through your account settings. We will verify your identity before processing your request and respond within 45 days.
11. Children's Privacy
Agent-Shield is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use the Service or provide any information to us.
If we learn that we have collected personal information from a child under 13, we will delete that information as quickly as possible. If you believe we have collected information from a child under 13, please contact us at support@agent-shield.com.
12. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to provide and improve the Service:
- Authentication Cookies: To keep you logged in and maintain your session
- Preference Cookies: To remember your settings (e.g., theme, language)
- Analytics: To understand how users interact with the Service (we use privacy-respecting analytics)
- Security: To detect and prevent fraudulent activity
You can control cookies through your browser settings. However, disabling cookies may affect your ability to use certain features of the Service.
13. International Data Transfers
Agent-Shield is based in the United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.
By using the Service, you consent to the transfer of your information to the United States and other countries that may have different data protection laws than your country of residence. We ensure that such transfers comply with applicable data protection laws through appropriate safeguards such as standard contractual clauses.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date at the top of this Privacy Policy
- Sending you an email notification (for material changes)
Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated terms.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Email: support@agent-shield.com
Privacy Inquiries: privacy@agent-shield.com
GDPR/CCPA Inquiries: privacy@agent-shield.com
We will respond to your inquiry within 30 days.