Privacy Policy

Last updated: March 11, 2026

1. Information We Collect

Account Information: When you create an account, we collect your name, email address, and company name. If you sign in via OAuth (Google, GitHub, Microsoft), we receive your public profile information from those providers.

Usage Data: We collect information about how you interact with the platform, including pages visited, features used, API scan counts, and assessment progress.

Compliance Data: When you use the AI compliance firewall, we process API request metadata (prompt hashes, risk classifications, detected entities). We never store raw prompt content in plaintext — quarantined items are encrypted with AES-256.

Payment Information: Payment processing is handled entirely by Stripe. We do not store credit card numbers. We retain Stripe customer IDs and subscription status.

2. How We Use Your Information

  • Provide and maintain the HoundShield platform
  • Process CMMC/compliance assessments and generate reports
  • Detect and classify sensitive data in AI API traffic
  • Process payments and manage subscriptions
  • Send service-related notifications (security alerts, billing)
  • Improve the platform through anonymized analytics

3. Data Security

We implement industry-standard security measures including:

  • AES-256 encryption for quarantined content at rest
  • SHA-256 cryptographic audit trail for all compliance events
  • TLS 1.3 encryption for all data in transit
  • Row Level Security (RLS) in our database
  • Regular security audits and dependency scanning

4. Data Sharing

We do not sell your data. We share information only with the sub-processors below. This list is generated from the same source of truth the DPA uses, so the two documents can never disagree:

  • Vercel: Application hosting, edge delivery and build pipeline
  • Supabase: Authentication, Postgres database and session storage
  • Stripe: Payment processing and checkout for the assessment report
  • Resend: Transactional email — receipts, password reset, notifications
  • PostHog: Product analytics. Loaded only after cookie consent is granted.
  • Sentry: Error monitoring and stack traces
  • Cloudflare: Turnstile CAPTCHA on authentication endpoints
  • OpenRouter: Routes Brain AI questions to commercial LLM providers. NOT FedRAMP-authorized and NOT covered by a BAA — never submit CUI or PHI to Brain AI.
  • Bytez: Model inference endpoint referenced by the application CSP
  • Amazon CloudFront: Media delivery for site video assets

Full detail, including data categories and processing region, is on the sub-processors page.

We may disclose information if required by law or to protect the rights, safety, or property of HoundShield or its users.

5. Data Retention

We retain your account record and compliance event metadata for as long as your account is open, and we delete it on request. We do not currently run an automatic purge, and we would rather tell you that than publish a schedule we do not keep: this product exists to produce audit evidence, and silently shredding a customer's assessor-review evidence on a timer would be the wrong default.

To request deletion, email us and we will confirm when it is done. In Mode B (self-hosted) the question mostly does not arise — prompt content never reaches us, so there is nothing on our side to delete beyond your account record.

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access, correct, or delete your personal data
  • Export your data in a portable format
  • Opt out of marketing communications
  • Withdraw consent for data processing
  • Opt out of any sale or sharing of personal information — see below

Residents of California, Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws have these rights under their state statute. We extend them to every user regardless of residence rather than checking where you live first. Email us to exercise any of them; we will not charge you or degrade your service for asking.

7. Cookies

We use essential cookies for authentication and session management. We use anonymous analytics cookies only after you opt in via our cookie consent banner. You can control cookie preferences through the banner or your browser settings.

Every item we store in your browser — its name, who sets it, what it is for and how long it lasts — is listed in our Cookie Policy. ePrivacy Art. 5(3) requires that detail, not just the category.

8. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to:

  • Know what personal information we collect, use, and disclose
  • Request access to, or deletion of, your personal information
  • Correct inaccurate personal information
  • Opt out of the “sale” or “sharing” of personal information
  • Not receive discriminatory treatment for exercising these rights

We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. To exercise any of these rights, contact us at the address below; we will verify your request and respond within the timelines required by law. You may use an authorized agent to submit a request on your behalf.

9. We Do Not Sell or Share Your Personal Information

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA/CPRA. We run no advertising, retargeting or data-broker integrations, so there is no opt-out to offer — the answer is simply no. The complete list of third parties that process data on our behalf, and what each one receives, is published on our Sub-processors page.

10. Children's Privacy

HoundShield is a business tool sold to organisations. It is not directed to children, and we do not knowingly collect personal information from anyone under 13 (COPPA) or knowingly process the data of a minor where state law sets a higher age. If you believe a child has provided us information, email us and we will delete it.

11. Security Incident Notification

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of your personal information, we will notify affected customers without undue delay, with what we know and what we are doing about it. Where we act as a processor for a customer, we notify that customer so they can meet their own notification deadlines — the specifics are in our Data Processing Agreement.

We will not wait for certainty before telling you something happened.

12. Contact & Data Controller

HoundShield is operated by an independent sole proprietor. A registered legal entity and postal address will be published here before general availability. For any privacy, data-protection or legal request in the meantime, contact legal@houndshield.com — requests are answered within the statutory time limits regardless of entity status.

The operator described above is the data controller for the personal information described in this policy.

For privacy requests or questions, contact legal@houndshield.com.