Privacy Policy
Last updated: June 23, 2026
This Privacy Policy explains how AegisMonkey (the "Service", "we", "us") collects, uses, and shares information when you use it.
Information we collect
- Account data: your name, email address, and authentication credentials.
- Agent data you submit: agent names, descriptions, system prompts, endpoint URLs, request templates, and headers used to run tests.
- Test results: the attack payloads, agent responses, scores, and run metadata generated when you run a test.
- Billing data: handled by Stripe; we store a Stripe customer/subscription identifier and your plan, not your full card number.
- Operational data: logs and error reports used to keep the Service running and secure.
How we use it
We use this information to provide and operate the Service (running tests, producing scorecards), to manage billing, to secure and improve the Service, and to communicate with you about your account. We do not sell your personal information.
Ephemeral handling of sensitive inputs
By default, the sensitive inputs you submit for a test — system prompts, endpoint headers, and request body templates — are purged after 24 hours unless you explicitly opt in to retain them. Test results and scores are retained as part of your run history. Snapshots of an agent's configuration captured at the time of a run are kept with that run's history.
Subprocessors
We share data with the following service providers strictly to operate the Service:
- Anthropic — attack and evaluation models. Prompts and agent responses are sent to Anthropic's API to run tests.
- Supabase — database, authentication, and storage.
- Railway — application and worker hosting.
- Stripe — payment processing and subscription management.
- Sentry — error monitoring and diagnostics.
For agents you configure as external HTTP endpoints, test traffic is sent to the endpoint URL you provide. You are responsible for that destination.
Data retention
We retain account and run-history data for as long as your account is active. Ephemeral inputs are purged as described above. You can request deletion of your account and associated personal data at any time (see below).
Your rights
Depending on your location (e.g. the EEA/UK under GDPR, or California under the CCPA), you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the email below. We will not discriminate against you for exercising them.
Security
We use row-level access controls, encrypted transport, server-only handling of secrets, and masking of sensitive credentials. No method of transmission or storage is perfectly secure, but we work to protect your data and to limit who can access it.
International transfers
Our subprocessors may process data in the United States and other countries. Where required, we rely on appropriate safeguards for such transfers.
Changes & contact
We may update this policy; material changes will be communicated through the Service or by email. Questions or requests: acehugh@proton.me.