Privacy Policy
Summary policy for the RavenSec preview. A full legal version is provided to customers at contract.
Overview
This policy explains what RavenSec (Kortana Labs) collects, why, and how it is protected. It applies to the RavenSec platform and marketing site.
What we collect
Account details (name, email), organisation data you connect for scanning, and operational telemetry. Connector access tokens are encrypted at rest; the private signing key never leaves the auth service.
How we use it
To operate the platform, run scans, generate and validate remediations, and improve our first-party models. Personally identifiable information is scrubbed before any data enters the training corpus.
Data protection
Data is isolated per organisation and protected with strong authentication (RS256 JWT + MFA), org-scoped RBAC, mutual TLS between services, and an append-only audit trail.
Your rights
You can request access to, correction of, or deletion of your data. Contact us and we will respond within a reasonable period consistent with applicable law.
Contact
Questions about this policy can be sent to privacy@ravensec.co.