Privacy Policy

Your privacy is fundamental to everything we build.

Effective: March 28, 2026• Updated: October 5, 2026

1. Information We Collect

Account Information: When you create an EchelonGraph account, we collect your name, email address, organization name, and role, and an optional answer to how you found us, if you give one. That answer is only what you select or type, and we use it only to understand, in aggregate, how people find us. If you sign up via SSO (SAML, OIDC, or LDAP), we receive the identity attributes your Identity Provider shares.

Cloud Configuration Data: When you connect cloud accounts (AWS, GCP, Azure), EchelonGraph scans resource configurations, IAM policies, network topology, and security group rules. We do NOT access, read, or store the contents of your databases, S3 objects, storage blobs, or application data.

Vulnerability & Compliance Data: We process CVE metadata, compliance check results, risk scores, and remediation states. This data is derived from your cloud infrastructure configuration and public vulnerability databases (NVD).

Usage Data: Within the authenticated product, our own servers record how the platform is used — features used, API calls made, and performance metrics — to operate, secure, and improve the Service. This is first-party, server-side telemetry only; we do not use third-party analytics, advertising, or cross-site trackers (see Section 6).

Device & Log Data: IP addresses, browser type, operating system, referrer URLs, and access timestamps are collected for security monitoring and abuse prevention.

2. How We Use Your Information

Service Delivery: To provide, maintain, and improve EchelonGraph's cloud security platform, including vulnerability scanning, compliance scoring, attack path analysis, and alerting.

Security & Fraud Prevention: To detect and prevent unauthorized access, monitor for abuse, and protect the integrity of our platform and your data.

Communication: To send you service notifications, security alerts, product updates, and (with your consent) marketing communications. You can unsubscribe from marketing emails at any time.

Analytics & Improvement: To understand usage patterns and improve product features, performance, and reliability. We use aggregated, anonymized data for this purpose.

Legal Compliance: To comply with applicable laws, regulations, legal processes, and government requests.

3. Data Storage & Retention

Infrastructure: The hosted service runs on Google Cloud Platform (GCP). Where its databases, backups and operational logs are stored is set out in Section 10. All data is encrypted at rest using AES-256-GCM and in transit using TLS 1.3.

Tenant Isolation: Every customer's data is logically isolated using PostgreSQL Row-Level Security (RLS), Neo4j label-based isolation, and ClickHouse partition isolation. No customer can access another customer's data.

Retention Periods: Scan and finding data are retained according to your plan — 90 days (Free), 365 days (Pro), and 730 days (Enterprise). Compliance scores are retained for 2 years, audit logs for 1 year, and encrypted backups for 30 days. Account data is retained for the duration of your subscription plus 30 days.

Deletion: Upon account termination, all customer data is permanently deleted within 30 days. You can request immediate deletion by contacting [email protected].

4. Data Sharing & Third Parties

We do NOT sell your data. EchelonGraph never sells, rents, or trades personal information or customer cloud configuration data to third parties.

Sub-processors: We use a limited, vetted set of sub-processors: Google Cloud Platform (infrastructure hosting), Cloudflare (DNS, WAF, and DDoS protection), Stripe (payment processing), SendGrid/Twilio (transactional email), and, for the AI copilot and AI remediation features of the hosted service, Anthropic (Claude models; data at rest in the United States, and inference may run in any geography Anthropic makes available) and the Google Gemini API (Gemini models; prompts and responses may be stored transiently or cached in any country where Google or its agents maintain facilities). The current list — with each processor's purpose, location, and Standard Contractual Clauses status — is maintained in our Data Processing Agreement, and we notify customers at least 30 days before adding a new sub-processor.

Legal Requirements: We may disclose data if required by law, subpoena, or court order, or if we believe disclosure is necessary to prevent harm or protect rights.

Business Transfers: In the event of a merger, acquisition, or asset sale, customer data may be transferred. We will provide notice before data is transferred and becomes subject to a different privacy policy.

5. Your Rights

GDPR (EU/EEA): You have the right to access, rectify, erase, restrict processing, data portability, and object to processing. You may also withdraw consent at any time. Contact our DPO at [email protected].

CCPA (California): You have the right to know, delete, and opt-out of the sale of personal information. We do not sell personal information. To exercise your rights, contact [email protected].

DPDP Act (India): As a Data Fiduciary, we process your data based on consent and legitimate purposes. You have the right to access, correct, erase, and nominate. Contact [email protected].

Response Time: We respond to all data subject requests within 30 days. Complex requests may take up to 60 days with prior notification.

6. Cookies, Local Storage & Tracking

Strictly-necessary cookies only. EchelonGraph sets a small number of essential cookies — for authentication, session management, a device fingerprint used to protect your account, and CSRF protection. They are set HttpOnly, Secure, and SameSite=Strict, are required to sign in and use the platform, and cannot be disabled.

Browser local storage. The application stores your session tokens and your own interface preferences (such as theme, language, notification settings, and saved dashboard layouts) in your browser's local storage. This data stays on your device, is used only to make the product work for you, and is never used for cross-site or behavioural tracking.

No analytics, advertising, or third-party tracking. We do NOT use Google Analytics, advertising pixels, marketing fingerprinting, cross-site trackers, or any third-party tracking cookies — and we never sell or share your data with advertising networks. As a security company, choosing not to track you is a deliberate part of how we earn your trust.

Why you won't see a cookie-consent banner. Because we use only strictly-necessary cookies — which are exempt from consent requirements under the EU ePrivacy Directive and GDPR — there is nothing non-essential to consent to. If we ever introduce analytics or marketing cookies, we will publish a genuine consent banner, with prior opt-in and a real reject option, before any such cookie is set.

Global Privacy Control & Do-Not-Track: We honour Global Privacy Control (GPC) and Do-Not-Track browser signals. Because we operate no advertising or cross-site tracking, there is nothing for these signals to switch off — but we will never override them.

7. Shadow AI Radar — Endpoint Access Record

What this is. Our Shadow AI Radar publishes AI services that are reachable on the public internet without authentication. The category, country, product, discovery source and status of each observation are open to everyone. The hosting provider is published only in aggregate (the most common providers across all observations), never for an individual observation. The exact address — IP and port — and the probe detail that confirms a service answers without a password are locked, because they describe third-party infrastructure and, published together, amount to a targeting list. Unlocking one requires reading and accepting a short access agreement. That unlock creates a record. Nothing else on this website does.

What we store. The date and time of the unlock; your IP address stored as a keyed one-way hash (an HMAC computed with a secret we hold, so we can recognise repeat access from the same address without keeping the address itself); the version of the access agreement you accepted; and a count of how many endpoints you unlocked on that pass. We do not store the raw IP address, a browser fingerprint, a user-agent profile, a persistent identifier, or which specific endpoints you looked at beyond the count.

Why we store it. One purpose only: detecting and stopping abuse of this feature — for example, a single source attempting to unlock endpoints at industrial scale. Under GDPR our lawful basis is legitimate interest (Article 6(1)(f)): protecting third parties whose infrastructure is listed, and protecting the feature from being turned into a bulk export. We recognise that an IP address is personal data, which is precisely why we hash it.

How long we keep it. 90 days, after which the record is deleted by an automated job. Not "90 days as a policy intention" — a scheduled deletion that actually runs.

What we never do with it. It is never used for analytics, advertising, profiling, marketing, lead generation, scoring, or product personalisation. It is never joined to your account, to sales or marketing records, to Surface Scanner results, or to any other dataset we hold. It is never sold, rented or shared, and it leaves our infrastructure only if we are legally compelled to disclose it.

No cookie, no cross-site tracking. The pass that keeps endpoints unlocked is held in your browser tab's session storage and disappears when you close the tab. We do not set a cookie for it and it cannot follow you to another site or another session. This is consistent with — not an exception to — our commitment in Section 6: we still operate no analytics, no advertising pixels and no third-party trackers anywhere on this site.

If you do not unlock anything, nothing is recorded. Browsing the Shadow AI Radar, reading the statistics, filtering the table and reading the risk categories create no record at all. The record exists only because you chose to take an action with real-world consequences for someone else's systems.

Your rights. Because the IP is stored only as a keyed hash, we cannot search these records by IP address on request, and we cannot link one to you — the hash is deliberately not reversible. If you believe a record relating to you should be erased, contact [email protected] and we will explain exactly what can and cannot be identified, rather than pretending to a capability we do not have.

8. Security Measures

EchelonGraph implements industry-standard security measures including: AES-256-GCM encryption at rest, TLS 1.3 encryption in transit, RS256 JWT with token rotation, TOTP MFA with recovery codes, RBAC with 5 roles and 18 permissions, audit logging of all administrative actions, and automated vulnerability scanning of our own infrastructure.

We are actively working toward SOC 2 Type II certification (Security and Confidentiality trust-service criteria) and align our information-security practices with ISO 27001:2022, with formal certification planned. See our Security page for our current certification status and live platform posture.

9. Children's Privacy

EchelonGraph is not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete it promptly.

10. International Data Transfers

If you are located outside the United States, your data will be transferred to and processed in the US, and, where Section 4 says so, by our sub-processors in the locations stated there (for the AI copilot and AI remediation features, Anthropic and the Google Gemini API may process it outside the US). We rely on Standard Contractual Clauses (SCCs) approved by the European Commission and additional technical and organizational measures to ensure adequate protection.

On the hosted service, databases run in Google Cloud's us-central1 region (Iowa, United States); database backups are stored in Google Cloud's US multi-region, which is in the United States but not limited to one region; and operational logs, which can include IP addresses and email addresses, are stored by Google Cloud Logging in its global location, which is not limited to the United States. EU and APAC data residency is planned but not yet available on any plan.

11. MCP Server and Hosted MCP Endpoint

What this covers. EchelonGraph publishes an MCP (Model Context Protocol) server that lets AI assistants and agents look up public vulnerability data. It comes two ways: the npm package echelongraph-mcp, which runs on your own machine, and a hosted endpoint at https://mcp.echelongraph.io/mcp, which we run for you. Neither needs an account or an API key, and neither sets a cookie. See EchelonGraph MCP for how to connect.

What the hosted endpoint receives. Everything your MCP client sends it, in the body of an HTTPS request: the name of each tool or prompt it calls, and that call's arguments. Some arguments are files, documents and labels, and the hosted endpoint receives them whole: an SBOM document (CycloneDX or SPDX JSON) passed to check_sbom or to the sbom_review prompt, or a project's manifests and lockfiles (such as requirements.txt, go.mod or package-lock.json) passed to scan_manifest, up to 6 MiB, and, as tools that take them are added, the package-database text of a container image, and the labels you give your workloads. Every other request is limited to 64 KiB. Like any HTTPS request, it also arrives from your network address and with your client's User-Agent.

Processed in memory, not logged and not stored. The hosted endpoint reads tool arguments, and every file, document and label among them, in memory and only to answer that call. From an SBOM it takes the package URLs (purls) and sends only those on to our public API, which looks them up and logs how many it received, not which. The hosted endpoint does not log or store tool arguments: they are not logged and not stored, and once the answer is sent it keeps nothing of them. The only thing it keeps between requests is a count of requests per network address, in memory, for its per-minute limit; it is not written anywhere and is lost when the server instance stops.

What the access line records. For each request the hosted endpoint writes one access line, which records: the HTTP method, the path and the response status; the JSON-RPC method and, for a tool call or a prompt, the tool or prompt name; the MCP protocol version; whether an Origin header was sent; the first word of your client's User-Agent (the part before its first slash or space, such as curl in curl/8.5.0), not the rest of it; the size of the request body in bytes; how long the request took, how long it waited for a place and how many requests were being served at once; whether your network address is public; whether your client closed the connection early; and whether the request was throttled or refused, and why. It never records tool arguments, a request body or a query string. Its other log lines carry no request content: an error is logged by its type name, a cause label from a fixed list and, for a protocol error, its numeric error code, never by its message, and a request turned away because the server is busy by the server's own limits and counts. When a client passes the per-minute request limit, that line records its network address (for IPv6, the /64 network it is in).

Who else sees a request. To answer a tool call, the hosted endpoint calls our API and passes it your public network address in a request header, so that the API's rate limit counts you rather than the hosted endpoint. The API writes an access line for each of those calls under your network address (for IPv6, the /64 network it is in), with the call's URL path, its status and how long it took. For a lookup of one CVE, CWE or vendor advisory, the URL path holds what you looked up (the ID, and the vendor or page that goes with it), so that line records it next to your address. The API's access line does not record the query string or any other part of a tool's arguments: the search terms, products, versions and package names that tools send in request headers are not logged, a CVE search is recorded only by whether a search term was given, its length and whether it was matched as a phrase, never the term itself, and of the package URLs from an SBOM it records how many it received, not which. Google Cloud, which runs the hosted endpoint and our API (Section 4), keeps its own log of each request it receives, with the URL, as it does for every request to our hosted services: for a request to the hosted endpoint, with your network address and full User-Agent; for the hosted endpoint's call to our API, with the URL's path and query string, from the hosted endpoint's address rather than yours. Section 10 says where operational logs are stored. Google Cloud's request log does not hold the request body.

The npm package runs on your machine. If you run the npm package instead, it runs on your own machine and calls our public API only when a tool needs an answer. An SBOM, manifest or other file you pass it is read on your machine: only the package URLs in it are sent to the API, and the file itself stays with you. So to keep a file off our servers, use the npm package, or pass check_sbom the package URLs instead of the document.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on our website at least 30 days before the changes take effect.

Your continued use of EchelonGraph after the changes take effect constitutes acceptance of the updated policy.

Change note, September 24, 2026 (corrections). We corrected two statements about where the hosted service stores data. First, until September 24, 2026 Section 10 said that we offer “regional deployment options (EU, APAC)” on our Enterprise plan. No such option existed, and that sentence was removed. Second, the sentence that replaced it the same day said that all customer data on the hosted service is stored in the United States (Google Cloud us-central1 region), and Section 3 said the same. That was also inaccurate: database backups are stored in Google Cloud's US multi-region, and operational logs are stored in Google Cloud Logging's global location, which is not limited to the United States. Section 10 now states where databases, backups and operational logs are stored, Section 3 refers to it, and the Google Cloud row of the sub-processor table in our Data Processing Agreement was corrected the same way. These edits correct how the policy describes storage; no data is handled differently because of them. We have therefore treated them as corrections rather than material changes, and they took effect when published.

Change note, September 24, 2026 (sub-processors). We corrected the list of sub-processors in Section 4 and in our Data Processing Agreement. Since April 15, 2026 for the Google Gemini API, and since June 30, 2026 for Anthropic, the AI copilot and AI remediation features of the hosted service have sent these providers what they need to answer whenever the features were used: your questions and the earlier turns of the conversation, and details of your findings and assets, such as resource identifiers, asset names, severities, attack paths and compliance scores. Neither list named either provider. Both lists now do, with their locations. Section 4 and the Data Processing Agreement promise at least 30 days' notice before a new sub-processor is added. Because neither provider was listed, that notice was never given, so the promise was not met for these two. This edit corrects how the policy and the agreement describe processing; no data is handled differently because of it.

Change note, September 27, 2026 (correction). We corrected one statement in Section 7 about what our Shadow AI Radar publishes. It said that the hosting provider of each observation was open to everyone. That was inaccurate: the observations we publish do not include a hosting provider. The hosting provider is published only in aggregate, as the most common providers across all observations, and Section 7 now says so. This edit corrects how the policy describes the Radar; it does not change what the Radar publishes or what we collect. We have therefore treated it as a correction rather than a material change, and it took effect when published.

Change note, September 28, 2026 (signup question). Our signup form now asks an optional question about how you found us, and Section 1 now lists your answer, if you give one, among the account information we collect. Answering is optional, and leaving it blank does not affect your signup. The answer is only what you select or type: the question does not record the page you came from, your search terms, or any campaign parameter. This applies only to people who answer it from now on; it changes nothing about data we already hold.

Change note, October 5, 2026 (MCP server). We added Section 11, which describes our MCP server and its hosted endpoint at mcp.echelongraph.io: what the hosted endpoint receives, including whole SBOM documents and, as tools that take them are added, manifests, lockfiles, package-database text and workload labels; that it processes them in memory and neither logs nor stores them; what its access line records; what our API logs of the calls it makes for you; and that the npm package runs on your own machine. Since the hosted endpoint launched in October 2026, this policy did not describe it. This edit describes processing that was already happening; no data is handled differently because of it, and it took effect when published.

13. Contact Us

Data Protection Officer: [email protected]

Privacy Inquiries: [email protected]

General Support: [email protected]

Mailing Address: EchelonGraph, Inc. • Privacy Team • Susaek, Eunpyeong-gu, Seoul, South Korea