[ LEGAL ]
Privacy Policy
What we collect, why, who processes it, and how long we keep it. Section 04 is the one security teams ask about first: we do not retain model weights, we do not retain access tokens, and we do not train on your assessment data. Section 06 tells you exactly which external services receive your probe transcripts, and on which testing paths.
Last updated 5 August 2026 · Effective 5 August 2026
[ 01 ]
WHO WE ARE
Who we are
SichGate Inc. (“SichGate,” “we,” “us”) operates sichgate.com and app.sichgate.com, an adversarial testing platform for small language models.
For the purposes of the EU and UK General Data Protection Regulation, SichGate is the data controller for personal data described in this policy, except where we process customer data on your behalf as a processor under our Terms of Use and any applicable data processing agreement.
A data processing agreement, incorporating the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, is available on request. Email legal at sichgate dot com.
Registered address: SichGate Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States.
Privacy contact: privacy at sichgate dot com — this is the fastest route for any question about your data, and the address to use for the rights described in section 10.
[ 02 ]
SCOPE
Scope
This policy covers personal data we process through our website, our web application, our API, and our managed assessment service. It does not cover third-party sites we link to, or your own use of models and services you connect to SichGate.
[ 03 ]
WHAT WE COLLECT
What we collect
- —Account data. Name, email address, and authentication metadata, collected and stored through our identity provider, Clerk. We do not store passwords.
- —Billing data. Plan, subscription status, credit balance, and transaction history. Payment card details are collected and processed by Stripe and are never transmitted to or stored on SichGate systems.
- —Model access credentials. Where you provide a Hugging Face access token, an NVIDIA NIM API key, or an authorization header for a custom endpoint, that credential is held in memory for the duration of the assessment run and is never written to disk. It is not retained after the run completes.
- —Assessment inputs. The model identifier, source path, and configuration parameters you supply when starting an assessment.
- —Assessment outputs. Probe results, severity classifications, category scores, certification tiers, drift measurements, and the prompt-and-response sequences generated during testing. Adversarial probes are authored by SichGate; the responses are generated by the model you tested. Where you purchase an Evidence Bundle, the bundle is generated from these outputs and stored with your assessment records.
- —Managed assessment submissions. Name, email, organisation, model description, deployment context, and any free-text detail you provide.
- —Partnership applications. Company and contact details, partnership preferences, use cases, and any business context you provide through the partnership form.
- —Contact messages. Name, email, organisation, topic, and the message you send through the contact form. We use these to answer you, and for nothing else.
- —Usage and technical data. IP address, browser and device metadata, request paths, timestamps, and error and performance logs, collected through our hosting and infrastructure providers. We also collect aggregate, cookieless page performance data through Vercel Speed Insights.
- —Communications. Correspondence you send us, including security reports sent to security at sichgate dot com.
[ 04 ]
WHAT WE DO NOT
What we do not collect or retain
We want these stated explicitly because they are the questions security teams ask first.
- —We do not retain model weights. Weights loaded for an assessment exist only in ephemeral compute for the duration of the run and are destroyed when it ends.
- —We do not retain access tokens. Tokens are held in memory only and never written to disk. Error messages and logs are scrubbed of credential patterns before storage.
- —We do not use your assessment data to train or fine-tune models. Your results, your model’s outputs, and your configuration are not used to train or fine-tune any model of ours, and are not shared with any other customer. We do derive aggregated, non-identifying statistics — for example, how often a probe category elicits a failure across all assessments — that do not reveal your models, your results, or your identity.
- —We do not publish your results without your action. Results appear in the public model registry only where you choose to publish them, or where the assessment was run against a public model under our own research programme.
- —We do not sell personal data, and we do not share it for cross-context behavioural advertising as those terms are defined under California law.
- —We do not run advertising or behavioural analytics on our website. We set no non-essential cookies. See section 11.
[ 05 ]
WHY & LEGAL BASIS
Why we process it, and our legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide the platform and run assessments | Account, model access, assessment inputs and outputs | Performance of a contract (6(1)(b)) |
| Billing and collections | Billing data | Performance of a contract (6(1)(b)) |
| Respond to enquiries and applications | Contact messages, managed assessment and partnership submissions | Legitimate interests (6(1)(f)); pre-contractual steps (6(1)(b)) |
| Security, abuse prevention, and service integrity | Usage and technical data | Legitimate interests (6(1)(f)) |
| Diagnose errors and maintain reliability | Error logs, exception context, cookieless performance data | Legitimate interests (6(1)(f)) |
| Improve the product in aggregate | Aggregated, non-identifying usage data | Legitimate interests (6(1)(f)) |
| Marketing communications | Email address | Consent (6(1)(a)), withdrawable at any time |
| Comply with legal obligations | As required | Legal obligation (6(1)(c)) |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights. You may object at any time — see section 10.
[ 06 ]
SUBPROCESSORS
Subprocessors
We use the following subprocessors. Each is bound by a written agreement requiring appropriate confidentiality and security measures.
| Subprocessor | Function | Data processed | Location |
|---|---|---|---|
| Clerk | Authentication and identity | Account data, authentication metadata | United States |
| Stripe | Payments and subscription billing | Billing data, payment details | United States |
| Modal | GPU compute for assessment execution | Model artefacts and probe traffic during a run (ephemeral) | United States |
| Railway | Application and API hosting | Assessment records, application data, logs | United States |
| Vercel | Website and application hosting, cookieless page-view analytics | Request logs, usage and technical data, cookieless page performance and page-view data | United States |
| Supabase | Database for assessment records and website form submissions | Assessment results and transcripts, contact messages, managed assessment requests, partnership application details | United States |
| Resend | Transactional email delivery | Contents of form submissions and scheduled assessment notifications; recipient addresses and schedule metadata | United States |
| Hugging Face | Model weight downloads and model metadata | Model identifiers and your access token | United States / EU |
| Sentry | Error monitoring | Exception context, request metadata, run and model identifiers | United States |
Personal identifiable information capture is disabled in our Sentry configuration, and exception values, request URLs, and scope data are scrubbed of credential patterns before transmission.
Where your probe transcripts go, by testing path
Probe prompts and model responses are the most sensitive data we handle, so we set out exactly which services receive them depending on how you run an assessment:
- —Downloaded weights (a model pulled from Hugging Face and executed on our GPU compute, including the quantization comparison path): transcripts are processed only by Modal, Railway, and Supabase. Hugging Face receives the model identifier and your access token in order to serve the weights, but does not receive probe traffic.
- —NVIDIA NIM or a custom endpoint you supply: transcripts are sent to the endpoint you name, because that endpoint is the model under test.
Targets you name are not our subprocessors
Where you point SichGate at NVIDIA NIM or at your own inference endpoint, that service receives your probe prompts and your model’s responses. It is not a subprocessor of ours: it is the subject of the assessment, chosen by you, reached with credentials you supply, and governed by that provider’s terms rather than by an agreement between us. See Terms of Use section 12.
We will update this list before adding or replacing a subprocessor. Customers on a written agreement may request notice of changes.
[ 07 ]
TRANSFERS
International transfers
We are based in the United States and our subprocessors are primarily in the United States. Where personal data of individuals in the EEA, the UK, or Switzerland is transferred outside those regions, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum where applicable, and, where a provider is certified, the EU-US Data Privacy Framework. Copies of the relevant transfer mechanism are available on request.
[ 08 ]
RETENTION
Retention
- —Account data: for the life of the account, then deleted or anonymised within 30 days of a deletion request following closure.
- —Assessment results, transcripts, and Evidence Bundles: retained while your account is active, so that you can run comparisons across model versions. There is no automatic time limit — deletion is under your control. You can delete individual assessment records at any time from the application. If you close your account and want remaining records removed, email privacy at sichgate dot com and we will delete them within 30 days.
- —Audit trail records: where your plan generates an audit trail (currently Business and Enterprise plans), audit events are retained on a plan-scaled schedule: Starter 90 days, Team 180 days, Business 365 days, Enterprise until you delete them. Plans without a recognised tier fall back to 30 days. This schedule governs the audit event chain only, not your assessment records, which are covered by the line above.
- —Model weights and access tokens: not retained. Destroyed at the end of the run.
- —Billing records: retained as required by tax and accounting law, typically 7 years.
- —Enquiry and application submissions: retained for 24 months from last contact.
- —Security, access, and error logs: retained by our hosting and monitoring providers for [CONFIRM RETENTION].
[ 09 ]
SECURITY
Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit, access controls and least-privilege provisioning, tenant isolation of assessment data, ephemeral execution environments for model loading, credential scrubbing in logs and error reports, and cryptographic signing of exported findings.
No system is perfectly secure, and we do not claim otherwise. We operate a responsible disclosure programme at sichgate.com/security and welcome good-faith reports.
Where we act as a controller, if a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and notify affected individuals without undue delay where the risk is high.
Where we act as a processor on your behalf, we will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information you reasonably need to meet your own notification obligations. The decision to notify a supervisory authority or affected individuals in that case is yours.
[ 10 ]
YOUR RIGHTS
Your rights
Depending on where you are, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, withdraw consent, and not be subject to solely automated decisions with legal or similarly significant effects.
Under California law you additionally have the right to know what we collect and why, to request deletion or correction, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising these rights.
To exercise any of these, email privacy at sichgate dot com. We will respond within one month, extendable by two further months for complex requests. We may need to verify your identity first.
If you are in the EEA or UK and believe we have handled your data improperly, you may lodge a complaint with your local supervisory authority. We would appreciate the chance to address it first.
[ 11 ]
COOKIES
Cookies
We set only cookies that are strictly necessary to operate the service: authentication session cookies set by Clerk, and security cookies set by Stripe on payment pages. These cannot be turned off without breaking the service.
We do not use advertising cookies, behavioural analytics, or third-party trackers. We do not run Google Analytics or any equivalent. Because we set no non-essential cookies, there is no consent banner and nothing for you to opt out of.
We collect aggregate page performance data through Vercel Speed Insights, which is cookieless and does not identify individual visitors.
[ 12 ]
CHILDREN
Children
SichGate is a business tool and is not directed at anyone under 18, and we do not permit under-18s to create an account. We do not knowingly collect personal data from children. If you believe a child has provided us data, email privacy at sichgate dot com and we will delete it.
[ 13 ]
AUTOMATED DECISIONS
Automated decision-making
Certification tiers are computed automatically from assessment results. This is a technical assessment of a software artefact, not of a person, and does not produce legal or similarly significant effects on any individual within the meaning of GDPR Article 22.
[ 14 ]
CHANGES
Changes
We will post any material change to this policy here and update the date at the top. Where the change materially affects how we handle your personal data, we will notify account holders by email before it takes effect.
[ 15 ]
CONTACT
Contact
Privacy: privacy at sichgate dot com
Security: security at sichgate dot com
Legal and notices: legal at sichgate dot com
SichGate Inc. See also our Terms of Use.