This policy describes how Igris handles data. It describes the system as it is built today, including its current limitations. Where a protection is optional or not yet implemented, we say so rather than implying otherwise.
1. Who We Are
Igris ("we", "us") provides AI governance tooling: a runtime proxy for LLM and MCP traffic, EU AI Act compliance documentation, and security reporting.
The operating entity is [ENTITY TBD]. This section will name the registered entity, its registered address, and its data protection contact once incorporation completes. Until then, reach us at support@igrisecurity.com.
2. Our Two Roles
We handle two distinct categories of data, under two different legal roles.
We act as a controller for data about our own customers and site visitors: account details, billing information, contact form submissions, and marketing site content. We decide why and how this data is processed.
We act as a processor for everything that flows through the Igris proxy: prompts, responses, tool calls, and the audit records generated from them. This data belongs to our customers and, often, to their end users. We process it only to deliver the service, according to the policies our customers configure.
If you are an end user whose data reached us through a customer's Igris deployment, that customer is your controller. Direct access and deletion requests to them.
3. Data We Collect as Controller
Account data. Name, email address, company name, and job title, collected when you create an account, request a demo, or contact us.
Billing data. Subscription and payment identity, handled through our payments provider. We do not store card numbers.
Contact form submissions. Your name, email, subject, and full message, which are emailed to our support address and stored in our database.
Anti-abuse data. When you submit a form or sign up, your IP address is sent to Cloudflare Turnstile for bot detection.
We rely on contract performance for account and billing data, legitimate interests for anti-abuse and service communications, and consent for marketing email. We do not run product analytics, advertising trackers, or third-party error tracking on our sites.
4. Data We Process on Your Behalf
This section describes what the proxy records when a customer routes traffic through it. Read it carefully — the defaults matter.
Always recorded
For every proxied request we store metadata: the provider and model, token counts, cost, latency, the tool name invoked, the policy decision applied, and timestamps.
Tool arguments are stored in plain text. When traffic passes through the MCP proxy, the full JSON arguments of each tool call are recorded to the audit log without encryption and without truncation. They are redacted only when a policy rule matches and its action is redact — denied calls, tool listings, and other protocol methods are recorded exactly as received. If your tool calls carry personal data, that data is stored in plain text unless a redaction rule covers it. Configure your policies accordingly.
Detector findings include short excerpts. When a content detector matches and the policy action is alert or deny, we store a raw excerpt of up to 40 characters surrounding the match, in plain text, so the finding can be reviewed. When the action is redact, the excerpt is masked instead.
Request and response bodies
Full prompt and response bodies are disabled by default. They are recorded only when a customer enables content logging on a connection, or when a matching policy rule turns it on.
When enabled, bodies are encrypted at rest with AES-256-GCM using a unique initialisation vector per field. They are write-only: no part of the product decrypts or displays them, and no export path exists. They are retained for the configured period and then permanently deleted.
Redaction is a policy setting, not a baseline. Content is redacted before storage and before forwarding only when a policy rule matches and its action is redact. Without a matching redaction rule, the complete prompt and response are stored as sent. Streamed responses are stored without redaction in all cases; post-stream inspection raises alerts but does not alter what was recorded.
5. How Long We Keep It
Request and response bodies are retained for 30 days by default. Customers may configure any period from 1 to 1095 days per connection, subject to their plan's maximum: 10 days on Starter, 30 on Growth, 90 on Scale, and 365 on Enterprise. An automated job runs hourly and permanently deletes bodies past their expiry.
Audit events are retained in the live database and then archived to Amazon S3 as compressed files. Archived events retain the plain text tool arguments and detector excerpts described above.
Account and billing records are kept for the life of the account and for as long as tax and accounting law requires afterwards.
6. Where Your Data Lives
All Igris infrastructure runs in Amazon Web Services us-east-2 (Ohio, United States). Our database, audit archives, and application servers are located there.
We do not currently offer EU or UK data residency. If you are in the European Economic Area, the United Kingdom, or another jurisdiction restricting international transfers, your data is transferred to and processed in the United States. We rely on Standard Contractual Clauses for these transfers. If your obligations require regional residency, Igris does not meet that requirement today.
7. Who Else Touches Your Data
We use these subprocessors:
| Provider | Purpose | What it receives |
|---|---|---|
| Neon | Managed PostgreSQL database | All stored data |
| Upstash | Redis cache | Rate limit and quota counters, cached policies. No message content |
| Amazon S3 | Audit archive storage | Archived audit events, including plain text tool arguments |
| Dodo Payments | Subscriptions and billing | Billing identity and organisation metadata |
| Our email provider | Transactional email | Email addresses, contact form contents |
| Cloudflare Turnstile | Bot protection | CAPTCHA token and visitor IP address |
Separately, the proxy forwards data to destinations you choose: the LLM provider your connection points at, your upstream MCP servers, your alert webhooks (which receive metadata only), and any custom content-guard webhook you configure (which receives request text). We are not the controller of these onward transfers; your agreements with those providers govern them.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
8. Your Rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and complain to a supervisory authority.
Under the GDPR and UK GDPR, EEA and UK residents hold all of the above. Your supervisory authority is the data protection body in your country of residence.
Under the CCPA and CPRA, California residents may request disclosure of the categories and specific pieces of personal information collected, request deletion or correction, and opt out of sale or sharing. As stated above, we do not sell or share personal information, and we do not discriminate against you for exercising these rights.
Under India's Digital Personal Data Protection Act (DPDP), data principals may access, correct, and erase their personal data, nominate another person to act on their behalf, and raise grievances with us.
How to exercise them. Email support@igrisecurity.com. We currently handle these requests manually — there is no self-service export or deletion tool in the product — and we respond within 30 days. If your data reached us through a customer's deployment, we will refer you to that customer, who is your controller.
9. Health Data and HIPAA
Igris can be configured to process protected health information (PHI) subject to the U.S. Health Insurance Portability and Accountability Act (HIPAA), but a Business Associate Agreement must be signed before any PHI is sent through the platform.
If you process PHI, note that the plain text storage of tool arguments and detector excerpts described in Section 4 applies to that traffic as well, and that enabling body logging stores PHI in encrypted form for your configured retention period. Configure redaction policies and retention deliberately.
10. How We Protect It
Request and response bodies are encrypted at rest with AES-256-GCM. Credentials and webhook URLs are encrypted with the same scheme. Encryption keys are held in the application environment, not in the database.
Encryption keys are not currently rotated. A single key protects stored bodies, and key rotation is not yet implemented.
Each customer organisation is isolated in its own database schema, with row level security applied on top. Deleting an organisation drops that schema and everything in it — bodies, audit events, connections, and policies.
Deleting an organisation does not delete its S3 audit archives. Archived events persist after deletion. Email us to have archives purged.
11. Changes to This Policy
We will update this policy as the product changes. The version and date at the top reflect the current revision, and the full history of this document is tracked in our source repository. Material changes will be announced to account holders by email.
12. Contact
Questions, requests, and complaints: support@igrisecurity.com.
The registered entity and its data protection contact will be named here once incorporation completes.