Last Updated: July 21, 2026
Aevesa ("we," "our," or "us") protects the privacy and security of information entrusted to us by customers, evaluators, and visitors. This Privacy Policy describes how we collect, use, retain, and safeguard information when you use our agentic evidence platform, verification portal, and related websites.
Depending on how you interact with Aevesa, we may process:
gateway_decision_id and cryptographic hashes), ledger anchors, and export-pack metadata used to produce audit evidence.The public verification portal is designed for privacy-preserving audit checks:
?receipt_id= or similar share features, we load the receipt data necessary to display verification results.Aevesa is built to support evidence-grade governance without exporting raw prompts or tool payloads to public verifiers by default. We prioritize cryptographic digests, policy references, ledger anchors, and redacted receipt fields for audit workflows. Customer-configured exports may include additional fields according to your tier and settings.
Customer data is not used to train third-party foundation models. Processing is scoped to providing the Service for your tenant.
We maintain security and operational logs to protect accounts and detect abuse, including authentication events, failed access attempts, MFA events, API usage, and suspicious patterns. Governance ledger entries and signed receipts are designed to be tamper-evident for compliance review.
We use industry-standard safeguards, including TLS 1.2+ in transit and AES-256 encryption at rest where applicable. No method of transmission or storage is completely secure; we continuously improve our controls as the Service evolves.
We use established subprocessors to operate the Service, including:
We retain information for as long as needed to provide the Service, meet contractual retention settings for your tier, resolve disputes, and comply with legal obligations. Sandbox and evaluation data may be deleted on a shorter schedule. Enterprise customers may have custom retention and deletion terms in an order form.
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing. California residents may also have rights to know, delete, correct, and opt out of sale/sharing as defined under CCPA/CPRA. Aevesa does not sell personal information.
To exercise privacy rights, contact team@aevesa.com. We will respond within the timeframe required by applicable law (typically 30-45 days).
California residents may request disclosure of categories of personal information collected, sources, purposes, and recipients, and may request deletion or correction subject to legal exceptions. Submit requests to the contact address above.
Aevesa is headquartered in the United States. If you access the Service from other regions, your information may be processed in the U.S. or other locations where we or our subprocessors operate, with appropriate safeguards where required.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the Last Updated date above.