Trust · Your Data

Privacy

Last Updated: 10 July 2026

LLM Vault exists to govern how organisations use AI — and governing a request means seeing it. This page explains, in plain English, what personal data we touch, why, and the engineering that keeps it minimised and under your control.

We Do

  • Classify every request on arrival, from Public to Restricted, so personal data is recognised rather than passed through unnoticed.
  • Minimise before we retain — the least data that still proves the decision.
  • Answer data-subject requests — access, correction, deletion — by email, during beta.
  • Keep this website cookie-free: no trackers, no analytics scripts, standard server logs only.

We Never

  • Train models on your records or content — platform learning uses anonymised telemetry: metadata like risk classifications, never the content itself.
  • Sell your data, or share it for value.
  • Keep a secret — credentials are stripped before anything is written.
  • Let one workspace see another’s data, policies or audit trail.
  • Take a client’s word for what it is sending.

What Personal Data Do We Touch?

Two kinds. Your account details — the minimum needed to run a workspace: who you are, how to reach you, and your access tier. And the content of the AI requests your organisation chooses to govern through the platform, which may contain personal data. That second kind is the whole point: it is classified the moment it arrives so that personal and regulated data is treated as what it is.

Why Do We Process It At All?

Because you cannot govern a request you cannot see. Classification, DPIA triage and residency checks all require reading the request — the deliberate trade at the heart of the product. When classification finds personal or regulated data, the request is automatically queued for a DPIA assessment. What happens to a call, step by step, lives on the Data Usagepage — this page is about your side of it.

What Choices Do You Control?

The clearest example is the AI Builder Coach, which can watch real coding sessions on a developer’s own machine. It is forward-only by default: enabling it today tells it nothing about yesterday. Reaching back into history is a separate, explicit opt-in — without that consent, backfill simply refuses to run. And whatever the local agent sends, the platform still verifies for itself before accepting (that doctrine has its own page). For anything you want accessed, corrected or deleted, write to john@cybereq.io — a person answers, during beta.

How Little Do We Keep?

Retention happens in layers, and the layers run before anything is written:

RedactAnonymiseGateEncrypt & Hash

The strictest protection applies at the highest sensitivity tier. What survives the layers is what an evidence record needs to prove a decision — not your raw content. The record’s exact contents are itemised on the Data Usage page.

Who Can See Your Data?

Your workspace, and only your workspace — isolation is how the system is built, and inside it, what a person can see follows their role tier. The stores sit in the EU by default, with residency policy deciding where data may live and be processed; the hosting detail is on Data Usage, and the access model on Security.

What About This Website?

This site is static marketing pages: no cookies, no third-party trackers, no analytics scripts as shipped. The links that leave it for the product app are clearly marked — the app is a separate, gated surface with its own controls.

Next: Data Usage follows one request through the pipeline, and Security explains the doctrine that guards it.

This page was written from the engineering, not from a policy template — it describes LLM Vault during beta, and formal legal notices will arrive with general availability. Privacy questions: john@cybereq.io.