isharpai
Sign inGet protected

Privacy notice

A security company that hoards data is a target. We designed this the other way around.

Last updated 17 August 2026

What we hold about you as a customer

  • Account: email address and sign-in metadata.
  • Company: company name, organisation and VAT number, address, contact person, contact and billing email, phone, website.
  • Subscription and billing: plan, term, price, status, invoice and payment references.
  • Support: the tickets and assistant conversations you start with us.

What the protection core sends us

Signals about security events: what kind of event, how severe, when it happened, and a de-duplication key. It is designed to describe what happened, not who your customers are.

We do not receive your customer database, your order contents, your payment card data or your end users' passwords. The core runs inside your system precisely so that this data never has to leave it.

Free scans

A free external snapshot only looks at what is already publicly visible on the domain you enter. We keep the domain, the email you gave us and the result so we can show it to you again and follow up once. Ask us and we delete it.

The AI Key

The identity layer is built so that we cannot map a person to a business. Directory lookups are country-level, each business derives its own key, and doors are matched by number. There is deliberately no shop-level lookup and no email step-up. We cannot hand over links we do not hold.

Legal basis and purpose

  • Contract: running your subscription, your installation and your support.
  • Legitimate interest: keeping the service secure and improving detection.
  • Legal obligation: invoicing, VAT and bookkeeping records.

We do not sell personal data and we do not use your signals for advertising.

Processors

  • Managed Postgres hosting for the database and authentication.
  • Application hosting and edge delivery for this site and its APIs.
  • A transactional email provider for account and alert mail.
  • An AI gateway for the support assistant and the nightly threat brief.

Each of them is used for the narrow purpose listed and nothing else.

Retention

  • Security signals and daily usage rollups: kept while your subscription runs, then removed on close.
  • Support tickets: kept while your subscription runs, then removed on close.
  • Invoices and VAT records: kept as long as accounting law requires.
  • Free scan results: removed on request, or when they go stale.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it where no legal duty requires us to keep it. Ask in your account — the request reaches us directly and we act on it.

Questions about this page? Ask the assistant inside your account, or open a ticket there — it reaches us directly.