Privacy Policy

Summary policy for the RavenSec preview. A full legal version is provided to customers at contract.

Overview

This policy explains what RavenSec (Kortana Labs) collects, why, and how it is protected. It applies to the RavenSec platform and marketing site.

What we collect

Account details (name, email), organisation data you connect for scanning, and operational telemetry. Connector access tokens are encrypted at rest; the private signing key never leaves the auth service.

How we use it

To operate the platform, run scans, generate and validate remediations, and improve our first-party models. Personally identifiable information is scrubbed before any data enters the training corpus.

Data protection

Data is isolated per organisation and protected with strong authentication (RS256 JWT + MFA), org-scoped RBAC, mutual TLS between services, and an append-only audit trail.

Your rights

You can request access to, correction of, or deletion of your data. Contact us and we will respond within a reasonable period consistent with applicable law.

Contact

Questions about this policy can be sent to privacy@ravensec.co.