Legal

Privacy principles for enterprise assurance infrastructure.

AAI should process only the data required to operate assurance, control and evidence workflows, with deployment and retention determined by customer requirements.

Minimization

Collect what is needed

Production integrations should scope telemetry, payload content and retained evidence to the customer’s policy.

Retention

Customer-controlled lifecycle

Retention and deletion policies should be configurable for evidence, traces and incidents.

Security

Protect sensitive evidence

Credentials and secrets should never be placed in public client surfaces; private deployment supports customer-controlled boundaries.

Contact

Questions

For a production engagement, customers should review the final data-processing and retention terms before connecting sensitive systems.