← Back to Aevesa

Privacy Policy

Last Updated: July 21, 2026

Aevesa ("we," "our," or "us") protects the privacy and security of information entrusted to us by customers, evaluators, and visitors. This Privacy Policy describes how we collect, use, retain, and safeguard information when you use our agentic evidence platform, verification portal, and related websites.

1. Data We Collect

Depending on how you interact with Aevesa, we may process:

2. Verification Portal (verify.aevesa.com)

The public verification portal is designed for privacy-preserving audit checks:

3. Data Minimization and Verification Design

Aevesa is built to support evidence-grade governance without exporting raw prompts or tool payloads to public verifiers by default. We prioritize cryptographic digests, policy references, ledger anchors, and redacted receipt fields for audit workflows. Customer-configured exports may include additional fields according to your tier and settings.

Customer data is not used to train third-party foundation models. Processing is scoped to providing the Service for your tenant.

4. Security Logs and Audit Trail

We maintain security and operational logs to protect accounts and detect abuse, including authentication events, failed access attempts, MFA events, API usage, and suspicious patterns. Governance ledger entries and signed receipts are designed to be tamper-evident for compliance review.

5. Data Security

We use industry-standard safeguards, including TLS 1.2+ in transit and AES-256 encryption at rest where applicable. No method of transmission or storage is completely secure; we continuously improve our controls as the Service evolves.

6. Third-Party Processors and Integrations

We use established subprocessors to operate the Service, including:

7. Data Retention

We retain information for as long as needed to provide the Service, meet contractual retention settings for your tier, resolve disputes, and comply with legal obligations. Sandbox and evaluation data may be deleted on a shorter schedule. Enterprise customers may have custom retention and deletion terms in an order form.

8. Your Rights (GDPR / UK GDPR / CCPA)

Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing. California residents may also have rights to know, delete, correct, and opt out of sale/sharing as defined under CCPA/CPRA. Aevesa does not sell personal information.

To exercise privacy rights, contact team@aevesa.com. We will respond within the timeframe required by applicable law (typically 30-45 days).

California Privacy Rights (CCPA/CPRA)

California residents may request disclosure of categories of personal information collected, sources, purposes, and recipients, and may request deletion or correction subject to legal exceptions. Submit requests to the contact address above.

9. International Transfers

Aevesa is headquartered in the United States. If you access the Service from other regions, your information may be processed in the U.S. or other locations where we or our subprocessors operate, with appropriate safeguards where required.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the Last Updated date above.