Triage Sec, Inc. ("Triage," "we," "us," or "our") provides software that helps organizations evaluate, steer, and secure AI systems. This policy explains how we handle personal information through our website, business relationships, and services.
1. Our role
We are responsible for personal information we use to operate our website, administer accounts, communicate with you, and manage our business. Where applicable, we act as the controller or business for that information.
We also process information submitted to, accessed by, or generated through our services on an organization's behalf ("Customer Data"). When we process personal information on a customer's instructions, we act as its processor or service provider, or as a subprocessor where appropriate. The customer agreement and any applicable data processing addendum govern that processing. This policy does not give us additional rights to Customer Data.
If your information is part of an organization's use of Triage, contact that organization about its practices and your rights. We assist customers with requests as required by our agreements and applicable law. Recruiting is covered by our Applicant Privacy Notice.
2. Information we handle
The information involved depends on your interaction with us and your organization's use and configuration of the services:
- Contact and communications: name, work email, organization, role, demo inquiries, meeting details, support messages, and feedback you provide.
- Account and access information: user and organization identifiers, sign-in information received from identity providers, membership, permissions, account settings, and administrative activity.
- Commercial records: contract and subscription details, billing contacts, invoices, usage charges, and payment status associated with our business relationship.
- Technical and usage information: IP addresses, browser and device information, requests, timestamps, feature usage, diagnostic information, and security events.
- Customer Data: prompts, instructions, policies, conversation history, model outputs, retrieved context, tool arguments and results, code and configuration, session records, evaluations, corrections, feedback, uploaded datasets, and materials used for customer-specific adaptation. Connected services may also require API keys or other integration credentials.
We receive information from you, from your organization and its authorized users, from identity providers and integrations you connect, and through operation of the website and services. Customer Data may include information about people who do not have a Triage account. Please provide only information appropriate for the service and your authorized use.
3. How we use information
We use personal information to:
- Provide the services, authenticate users, administer permissions, and carry out customer instructions.
- Respond to inquiries, schedule meetings, provide support, and communicate about accounts and service changes.
- Manage contracts, billing, usage accounting, and business records.
- Maintain and improve service reliability and usability, diagnose problems, prevent abuse, and protect our systems.
- Send relevant business communications where permitted, subject to your choices.
- Meet legal obligations, resolve disputes, and protect legal rights.
These purposes do not expand the permitted uses of Customer Data described below.
Where a legal basis is required, we rely on our legitimate interests in operating and securing our business and serving organizational customers, subject to your rights; performance of a contract where you are personally a party; compliance with law; or consent where required. You can contact us about the basis for a particular use. Without information needed to provide a service or respond to a request, we may be unable to do so.
4. Customer Data and adaptation
We process Customer Data to provide, secure, and support the services in accordance with the applicable customer agreement and instructions. Integrity evaluates AI activity and can recommend or apply corrections within the connected workflow. This can involve processing content through the models and providers configured for that service.
Where authorized, customer-specific evaluation, calibration, and adaptation can use retained examples, customer feedback, and uploaded datasets. This may include generating additional examples, preparing training datasets, and training and evaluating customer-specific versions of Triage components. The available workflow and customer configuration determine which activities are performed.
Permissions for model training and other uses of Customer Data are governed by the customer agreement and documented instructions. This policy is not an authorization to use Customer Data for unrelated model training or cross-customer reuse. Customer-selected model providers may have their own data-use terms; the applicable provider arrangements also matter.
Hosted and customer-managed deployments have different processing boundaries. The agreed deployment and configuration determine where runtime, inference, storage, and adaptation take place, including any configured external connections.
5. When information is disclosed
We disclose information as needed for the purposes above to:
- Service providers that support hosting, storage, authentication, model processing, communications, and other business operations. Processing of Customer Data remains subject to the applicable customer agreement.
- Your organization and authorized users, according to their permissions and the services it uses.
- Connected services when you or your organization directs us to use a model provider, repository, or other integration. Separate terms may govern that provider's own processing.
- Professional advisers, such as lawyers, accountants, and auditors, where needed for their work.
- Other recipients when reasonably necessary to comply with law or valid legal process, protect rights and safety, investigate abuse, or handle a merger, acquisition, financing, or similar business transaction, subject to applicable confidentiality and data protection obligations.
We may also disclose information at your direction or with your consent. Contact info@triage-sec.com for information about service providers relevant to your deployment.
7. Retention
We retain personal information according to its purpose, the nature of the information, our relationship with you, and applicable legal and contractual requirements:
- Account and business records: for account and relationship administration, and afterward where needed for recordkeeping, disputes, or legal obligations.
- Inquiries and support communications: for handling the request and relevant follow-up, maintaining support history, and resolving related issues.
- Technical and security records: for service operation, troubleshooting, misuse prevention, and investigation under the retention settings applicable to those records.
- Customer Data and adaptation materials: under the applicable agreement, customer instructions, and supported retention settings.
Different records may have different retention periods. Removing content from the application does not necessarily remove it immediately from backups, connected providers, or retained adaptation artifacts. Return, deletion, and any continuing retention of Customer Data are governed by the applicable agreement and law. Contact us for retention information or a deletion request.
8. International processing
Triage is based in the United States. Information may be processed in the United States and other countries where the providers involved in the relevant service operate. Processing locations for Customer Data depend on the agreed deployment and provider arrangements.
Privacy laws may differ between countries. International processing is subject to applicable data protection requirements and the relevant customer and provider agreements. Contact us for information about processing locations, the safeguards applicable to your information, and how to obtain a copy of those safeguards.
9. Your rights and choices
Depending on your location, our role, and applicable law, you may have rights to access or obtain a copy of your personal information, correct it, request deletion, restrict or object to processing, withdraw consent, or receive portable information. Applicable law may also provide rights concerning sale, targeted advertising, sensitive information, and certain automated decisions. These rights are subject to conditions and exceptions.
Email info@triage-sec.com with the subject Privacy request. Tell us what you are requesting and enough information to locate the relevant relationship or account. Please do not send passwords, API keys, or identity documents in your initial message. We may request proportionate information to verify identity or authority where needed. Authorized agents may make requests where permitted by law.
We respond as required by applicable law. If a right of appeal applies, reply to our response with the subject Privacy appeal. You may also complain to the relevant privacy regulator. We do not unlawfully discriminate or retaliate against people who exercise their rights.
Objections and marketing choices: Where applicable, you may object to processing based on legitimate interests, including direct marketing. Contact us to exercise that right. You can also opt out of marketing communications through an unsubscribe option in the message. Necessary account and service communications may continue.
Withdrawing consent does not affect earlier lawful processing. For information processed on an organization's behalf, direct your request to that organization; we can help route it.
10. Security and intended use
We use technical and organizational measures to protect information, including access controls and encryption for stored credentials and retained session content. No system is completely secure. Our Security page describes our approach and how to contact us.
The services are intended for business use by adults, not for children. If you believe a child has provided personal information directly to Triage, contact us. Information about children within Customer Data remains subject to the customer's instructions and applicable law.
Our services evaluate AI activity and can affect how an integrated workflow continues. Customers determine their use of those capabilities and are responsible for the notices, authorizations, and safeguards required for decisions they make about people.
11. Updates and contact
We may update this policy as our practices or legal requirements change. We will update the date above and provide additional notice or obtain consent where required. A policy update does not expand our contractual rights to Customer Data.
For questions or privacy requests, contact Triage Sec, Inc. at info@triage-sec.com.