Skip to main content

Privacy Policy

Last updated: August 5, 2026

1. Introduction

ProvenanceOS ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our website and services, and it tells you about the rights you have over that data.

2. Information We Collect

We collect information you provide directly to us, such as when you create an account, contact us, join the waitlist, or use our services. This may include:

  • Name and email address
  • Company information
  • Billing information (only when paid engagements begin)
  • Repository metadata (for example, repository URL and provider) — but never source code

We also collect limited technical information automatically when you use the service, including IP address, user agent, and event-level logs needed to operate the platform and respond to security incidents.

3. How We Use Your Information

We use the information we collect to:

  • Provide and maintain our services
  • Process transactions and send invoices for paid engagements
  • Communicate with you about updates, security alerts, and operational notices
  • Improve our platform and develop new features
  • Detect, prevent, and respond to security incidents and abuse

We rely on the following legal bases under the EU GDPR when processing personal data of individuals in the European Economic Area: performance of a contract (providing the service you requested), our legitimate interests (operating, securing, and improving the service), compliance with legal obligations, and — where required — your consent.

4. What We Process and What We Retain

Our data-handling practices are documented in detail on the Security page. The qualitative state today is:

  • Source files are processed transiently to compute provenance signals and are never retained. Archive uploads are SHA-256 hashed for integrity; only the hash is stored.
  • Repository metadata (URL, provider) is retained for the life of the account so job history is queryable, and is deleted on account deletion.
  • Derived signals (for example, dependency resolution and OSV.dev vulnerability matches) are retained with the scan job so results remain queryable and exportable, and are deleted with the job or on account deletion.
  • Reports are customer-controlled. You can delete a report at any time; export retains your copy.
  • Repository-provider credentials are not collected today. Public repository URLs are fetched unauthenticated.

Retention windows for paid tiers will be finalized at general availability and stated on the pricing page. Source content is never used to train models.

5. Data Security

Built to SOC 2 controls — independent audit not yet started. All data is encrypted in transit with TLS 1.3 and encrypted at rest by our infrastructure providers; at-rest keys are managed by the hosting layer. Production access is scoped and audited. A full security disclosure and responsible-disclosure policy is published at /security and /.well-known/security.txt.

6. Subprocessors

We engage a limited set of subprocessors to operate the service. As of the date above, these include:

  • InsForge — managed Postgres database hosting for account, job, and derived-signal records.
  • Railway — application hosting for the ProvenanceOS service.
  • OSV.dev — open-source vulnerability data queried during analysis; only dependency identifiers are sent.
  • GitHub — repository metadata fetched from public repositories for scan jobs that target github.com URLs.
  • GitLab and Bitbucket — repository metadata fetched from public repositories for scan jobs that target gitlab.com or bitbucket.org URLs.
  • Stripe — payment processing and billing management for paid subscriptions.
  • Google — analytics and tag management (Google Analytics / Google Tag Manager), loaded only after you consent.
  • Cloudflare — edge network services and inbound email routing for our contact address.

We will give at least 30 days' notice by email and on this page before adding a new subprocessor that handles personal data. To object to a new subprocessor, contact us at the address below before the change takes effect.

7. International Data Transfers

ProvenanceOS is operated from the United States. If you access the service from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States. Where required by applicable law (for example, the EU GDPR for data of EEA individuals), we rely on appropriate safeguards — such as Standard Contractual Clauses — for transfers from your jurisdiction to ours. Contact us if you require a copy of the relevant safeguards.

8. Your Rights

Depending on where you live, you may have some or all of the following rights over your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — request that we correct inaccurate or incomplete data
  • Deletion — request that we delete your personal data, subject to limited exceptions
  • Portability — receive your data in a commonly used, machine-readable format
  • Restriction or objection — restrict or object to certain processing
  • Withdrawal of consent — where processing is based on consent, withdraw it at any time
  • Opt-out of sale or sharing for cross-context behavioral advertising — ProvenanceOS does not sell personal data and does not engage in cross-context behavioral advertising

To exercise these rights, email support@provenance-os.com with the subject line "Data Subject Request." We will acknowledge your request within 5 business days and respond within 30 calendar days (45 days where extension is permitted by law, with notice of the extension). California residents may also designate an authorized agent to make a request on their behalf.

9. Children

ProvenanceOS is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us so we can delete it.

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or for legal, operational, or security reasons. Material changes will be posted on this page with an updated date. Your continued use of the service after changes take effect constitutes acceptance, except where the law requires additional notice or consent.

11. Contact

Questions about this Privacy Policy, data subject requests, or subprocessors should be sent to support@provenance-os.com.

Last reviewed: August 5, 2026

Related pages:

We value your privacy

We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Learn more