Back to Home

Privacy Policy

Last updated: February 21, 2026

VaultFill is a compliance automation platform. We take data privacy seriously and engineer our systems to minimize data collection while maximizing compliance value.

1. Introduction & Scope

VaultFill Inc. ("we," "our," or "us"), a Delaware corporation, respects your privacy and is committed to protecting it through compliance with this Privacy Policy. This policy describes the types of information we may collect from you or that you may provide when you access the VaultFill website (vaultfill.com), use our compliance automation platform, interact with our APIs, or engage with any related services (collectively, the "Service"), and our practices for collecting, using, maintaining, protecting, and disclosing that information.

This Privacy Policy applies to information we collect:

  • On or through the VaultFill website and platform.
  • Through our evidence collection connectors (AWS, GitHub, Vanta, Microsoft Purview, and other integrations).
  • In email, chat, and other electronic communications between you and VaultFill.
  • Through API integrations and webhook communications.
  • When you interact with our advertising, support, or marketing channels.

This Privacy Policy does not apply to information collected by third parties, including any third-party application or content that may link to or be accessible from the Service. We encourage you to read the privacy policies of every website and service you visit or use.

2. Information We Collect

We collect several categories of information from and about users of our Service:

A. Account Information

Name, email address, company name, job title, phone number, billing address, and payment information (processed by our payment processor, Stripe). We also collect authentication data including OAuth tokens and MFA configuration.

B. Infrastructure Metadata

When you authorize VaultFill to integrate with your cloud infrastructure (e.g., AWS, GCP, Azure, Microsoft 365), we collect metadata regarding your environment, including:

  • Cloud configuration settings and security group rules
  • IAM policies, roles, and permission boundaries
  • Resource tags, inventory, and architecture metadata
  • Access logs, CloudTrail events, and audit records
  • CI/CD pipeline configurations and deployment metadata
  • Vulnerability scan results and patch status

We explicitly engineer our systems to avoid ingesting underlying user databases, transaction records, customer PII, production data, or application-level content.

C. Evidence & Compliance Documents

Documentation, screenshots, SOC reports, vendor assessments, security policies, incident response plans, and other artifacts you upload into the Evidence Vault for cryptographic signing, cataloging, and storage. All uploaded evidence is SHA-256 hashed and stored in an immutable audit ledger.

D. Questionnaire & AI Interaction Data

Questions and responses from security questionnaire automation, AI-generated policy content, remediation scripts, risk assessments, and confidence scoring metadata. This includes prompts sent to AI models and the resulting outputs.

E. Automated Telemetry

IP addresses, browser type and version, operating system, device information, referring URLs, page views, click patterns, session duration, feature usage analytics, error logs, and platform interaction data collected via cookies and similar tracking technologies.

3. How We Collect Information

We collect information through the following methods:

  • Directly from you when you create an account, upload evidence, configure integrations, submit support requests, or communicate with us.
  • Automatically through evidence collection connectors that you authorize to access your cloud infrastructure.
  • Through automated telemetry as you navigate through and interact with the platform, including cookies, web beacons, and analytics services.
  • From third-party sources such as identity providers (OAuth/SSO), payment processors (Stripe), and analytics services.

4. How We Use Your Information

We use information that we collect about you or that you provide to us for the following purposes:

  • Deliver the Service, including automated compliance scanning, policy generation, evidence collection, and questionnaire automation.
  • Calculate and display risk scores, compliance coverage percentages, and drift detection metrics across connected frameworks.
  • Generate cryptographic hashes (SHA-256) for tamper-evident audit evidence.
  • Power the Pele AI engine, including Legal-to-Logic compilation, remediation code generation, and confidence scoring for questionnaire responses.
  • Process payments, manage subscriptions, and send billing and administrative notices.
  • Provide customer support and respond to your requests, questions, and feedback.
  • Improve, test, and enhance the security, reliability, and performance of the platform.
  • Develop new features, products, and services based on aggregated and anonymized usage patterns.
  • Notify you about changes to the Service, including new features and security updates.
  • Detect, prevent, and address fraud, security incidents, and technical issues.
  • Comply with legal and regulatory obligations, including responding to lawful requests from public authorities.

5. AI Processing & Sub-Processors

To provide autonomous compliance capabilities, VaultFill transmits specific metadata and prompts to trusted third-party Large Language Model (LLM) providers via secure, encrypted APIs. Our AI processing architecture is designed with the following safeguards:

Zero Data Retention (ZDR)
All AI sub-processors operate under Enterprise-tier agreements that enforce Zero Data Retention. Your data is processed in memory and never persisted by the sub-processor.
No Training on Your Data
Your infrastructure metadata, policies, evidence, and outputs are never used to train general-purpose or public AI models.
Transparency
A current list of AI sub-processors is available upon request at legal@vaultfill.com. We provide 30 days' notice before adding new sub-processors.

6. Disclosure of Your Information

We do not sell your personal data.

We may disclose aggregated, anonymized information about our users without restriction. We may disclose personal information that we collect or you provide in the following circumstances:

  • Service Providers: To contractors, service providers, and third parties we use to support our business, including cloud hosting (AWS), payment processing (Stripe), analytics, customer support, and AI sub-processors. These providers are contractually obligated to keep your data confidential.
  • Business Transfers: To a buyer or successor in the event of a merger, acquisition, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of VaultFill's assets.
  • Legal Compliance: To comply with any court order, law, or legal process, including to respond to any government or regulatory request.
  • Protection of Rights: If we believe disclosure is necessary or appropriate to protect the rights, property, safety, or security of VaultFill, our customers, or others, including to detect, prevent, or address fraud, security, or technical issues.
  • With Your Consent: For any other purpose disclosed at the time you provide the information or with your express consent.

7. Data Storage & Security

We have implemented rigorous, enterprise-grade security measures designed to protect your information from accidental loss and from unauthorized access, use, alteration, and disclosure:

  • Encryption at rest: AES-256 encryption for all stored data.
  • Encryption in transit: TLS 1.3 or higher for all data in transit.
  • Evidence integrity: SHA-256 cryptographic hashing for all evidence artifacts with immutable audit trails.
  • Access controls: Role-based access control (RBAC), multi-factor authentication (MFA), and principle of least privilege across all infrastructure.
  • Infrastructure: Hosted on SOC 2 Type II compliant cloud infrastructure with regular security audits and penetration testing.
  • Monitoring: 24/7 security monitoring, intrusion detection, and automated incident response.

The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password or access token for access to the Service, you are responsible for keeping this information confidential.

8. Data Retention & Deletion

We retain your information only for as long as reasonably necessary to provide the Service to you, comply with our legal obligations, resolve disputes, and enforce our agreements:

  • Account data: Retained while your account is active and for up to 30 days after account closure to allow for data export.
  • Evidence and audit data: Retained for the duration of your subscription plus any legally required retention period (typically 7 years for audit-relevant evidence).
  • Telemetry and analytics data: Retained for up to 24 months in identifiable form, then anonymized.
  • AI processing logs: Retained for up to 90 days for debugging and quality assurance, then permanently deleted.
  • Billing records: Retained for up to 7 years as required by tax and financial regulations.

You may request deletion of your data at any time by contacting privacy@vaultfill.com. We will process deletion requests within 30 days, subject to legal retention obligations.

9. International Data Transfers

VaultFill is headquartered in the United States. If you access the Service from outside the United States, your information may be transferred to, stored in, and processed in the United States or other countries where we or our service providers maintain facilities. These countries may have data protection laws that are different from the laws of your country.

Where we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical and organizational measures where appropriate. A copy of the SCCs is available upon request at legal@vaultfill.com.

10. Your Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have certain rights under the General Data Protection Regulation (GDPR) and equivalent local laws. These include the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete personal data.
  • Erasure: Request deletion of your personal data ("right to be forgotten").
  • Restriction: Request restriction of processing of your personal data.
  • Portability: Receive your personal data in a structured, machine-readable format.
  • Objection: Object to processing of your personal data based on legitimate interests.
  • Automated Decision-Making: Not be subject to a decision based solely on automated processing that produces legal or significant effects (note: our AI outputs are advisory and require human review).

To exercise any of these rights, submit a Data Subject Access Request (DSAR) to privacy@vaultfill.com. We will respond within 30 days. Our lawful basis for processing your personal data includes: performance of a contract, legitimate interests, compliance with legal obligations, and consent where applicable.

11. Your Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information. These include:

  • Right to Know: The categories and specific pieces of personal information we have collected about you.
  • Right to Delete: Request deletion of personal information we have collected.
  • Right to Opt-Out: Opt out of the sale or sharing of personal information. Note: We do not sell your personal information.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Limit Use: Limit the use and disclosure of sensitive personal information.
  • Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

To submit a request, contact us at privacy@vaultfill.com or call us at the number listed on our website. We will verify your identity before processing your request and respond within 45 days.

12. Cookies & Tracking Technologies

We use cookies and similar tracking technologies (including web beacons, pixel tags, and local storage) to collect and track usage information and to improve and analyze the Service. Types of cookies we use include:

  • Essential Cookies: Required for the Service to function properly (authentication, session management, security).
  • Analytics Cookies: Help us understand how users interact with the Service (e.g., page views, feature usage).
  • Preference Cookies: Remember your settings and preferences (e.g., dashboard layout, theme).

You can set your browser to refuse all or some cookies, or to alert you when cookies are being sent. If you disable cookies, some parts of the Service may become inaccessible or not function properly. We do not use advertising or marketing cookies on the VaultFill platform.

13. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn we have collected or received personal information from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 18, please contact us at privacy@vaultfill.com.

14. Third-Party Links & Services

The Service may contain links to third-party websites, services, or applications (e.g., cloud provider consoles, identity providers, compliance databases). These third-party services have their own privacy policies, which we encourage you to review. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party services. Linking to a third-party site does not constitute an endorsement by VaultFill.

15. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email to the primary email address associated with your account, through a prominent notice on our Service dashboard, or as otherwise required by applicable law. The date this Privacy Policy was last revised is identified at the top of the page. You are responsible for periodically reviewing this Privacy Policy. Your continued use of the Service after notice of changes constitutes your acceptance of the updated Privacy Policy.

16. Contact Information & DPO

To ask questions or submit requests regarding this Privacy Policy and our privacy practices:

VaultFill Inc.

Data Protection Officer

Privacy Requests
privacy@vaultfill.com
Legal Department
legal@vaultfill.com
Security Incidents
security@vaultfill.com