X
Xtrom
ProductSecurityAboutBlogCareersConsole ↗← Home
Legal

Privacy Policy

Last updated: September 26, 2026

Xtrom, Inc. ("Xtrom", "we", "us") provides a deterministic runtime firewall and non-human-identity governance plane for AI agents. This policy explains what data we handle, how we use it, and the choices you have. Our guiding principle is data minimization: your agents and their data stay in your environment.

1. The most important thing

Your agent data never leaves your account. The Xtrom enforcement plane runs inside your own cloud (VPC). Agent prompts, tool inputs/outputs, secrets, and the content agents process are evaluated locally and are not transmitted to or stored by Xtrom. We receive only privacy-scrubbed operational metadata (see §3).

2. Information you provide

3. Information we collect automatically (privacy-scrubbed telemetry)

To operate the service and improve detection, our control plane receives metadata only — never raw customer data:

Scrubbing: sensitive values (secrets, prompts, arguments, document contents) are stripped or hashed before anything leaves your environment. Threat-intelligence learning uses aggregated, de-identified patterns only.

4. How we use information

We do not sell personal information, and we do not use your data to train models that benefit other customers except as aggregated, de-identified threat intelligence.

5. Legal bases (GDPR)

Where GDPR applies, we process personal data under: performance of a contract, our legitimate interests (securing and improving the service), your consent (where required), and compliance with legal obligations.

6. Sharing & sub-processors

We share limited data with vetted sub-processors who help us run the service (e.g., cloud infrastructure, analytics, communications). Each is bound by confidentiality and data-protection terms. A current sub-processor list is available on request, and material changes are communicated in advance where required.

7. Data retention

DataRetention
Account & configurationFor the life of your account, then deleted within 90 days of termination.
Decision/audit metadataPer your configured retention (immutable WORM logs live in your environment).
Product/usage logsTypically 12 months.

8. Security

We apply encryption in transit and at rest, per-tenant customer-managed keys (KMS), least-privilege access controls, and continuous monitoring. See our Trust & Security page for details, and report vulnerabilities to security@xtrom.ai.

9. International transfers

Where data is transferred across borders, we rely on appropriate safeguards (e.g., Standard Contractual Clauses). In-VPC deployment lets you keep processing within your chosen region.

10. Your rights

Depending on your location, you may have rights to access, correct, delete, port, or object to processing of your personal data, and to withdraw consent. To exercise these, contact hello@xtrom.ai. We respond within the timeframe required by applicable law.

11. Cookies

Our website uses essential cookies and privacy-respecting analytics. You can control cookies through your browser settings.

12. Changes

We'll update this policy as the product and law evolve, and revise the "last updated" date. Material changes will be communicated through the service or by email.

13. Contact

Questions about privacy: hello@xtrom.ai. Security matters: security@xtrom.ai.