Privacy Policy
Last updated: June 2026
1. Overview
This Privacy Policy explains how Aegis LLC ("Aegis", "we", "us") handles information in connection with the Guardrails service ("Service"). We distinguish between two kinds of data: account information you give us to create and manage your account, and audited content that passes through the Guardrails proxy on your behalf.
2. Account information
When you sign up we collect the information you provide — such as name, company, role, email, phone, mailing address, and the answers to our onboarding questionnaire — together with billing details processed by our payment provider. We use this to create your account, provision the Service, suggest an appropriate plan, generate your installation instructions, and communicate with you.
3. Audited content
When you route an AI call through the Guardrails proxy, we process the request and response in order to create a cryptographic fingerprint and anchor a verification record. The fingerprint (a one-way hash) and signatures are what get committed to the Verilink’ed ledger — the ledger never contains your prompt or response content.
Depending on your plan and configuration, the underlying content may be stored in encrypted form so you can review it later, or you may operate in a hash-only mode in which we retain only the fingerprint. You control which content is sent to us by choosing what to route through the proxy.
4. The Verilink’ed ledger is append-only
Records anchored to the ledger are immutable by design — that is the basis of their evidentiary value. Anchored fingerprints cannot be deleted or altered. Deleting your account removes account information and stored content per Section 7, but on-chain fingerprints persist.
5. Sharing and subprocessors
We do not sell your data. We share information only with service providers that help us run the Service — for example your chosen AI provider (which receives the forwarded request), our payment processor, hosting, and email delivery — and only as needed to provide the Service or comply with law.
6. Security
We use encryption in transit and at rest, signed records, and access controls to protect data. No system is perfectly secure, but protecting the integrity of audit records is the core of what we do.
7. Retention and your rights
We retain account information for as long as your account is active and as needed for legal and accounting purposes. You may request access to, correction of, or deletion of your account information by contacting us. Regulated customers who require a Business Associate Agreement or Data Processing Addendum should contact us before sending regulated data through the Service.
8. Contact
Privacy questions can be sent to support@aegisguardrails.com.
This summary is provided for transparency and is not legal advice. Please review it with your own counsel before sending regulated data through the Service.