Draft — pending legal review

Privacy Policy

This is a working draft written to be directionally accurate about how the architecture handles data, not a signed legal document. Have counsel review it before it's published as binding.


The short version

TenantSage is designed to process less than most systems, on purpose.

Because enforcement can sit close to a customer's own systems, TenantSage's design goal is to need as little of the underlying content as possible — governance decisions run on metadata, authority state, and policy, not on a copy of everything being governed.


What's processed

Categories of data involved in a governed request.

CategoryExamplesPurpose
Identity claimsVerified OIDC token contents, principal ID, roleResolving authority for the request
Scope & policy metadataTenant, family, classification, retention flagsComputing the eligible evidence boundary
Evidence referencesSource and chunk identifiers, not necessarily full contentProving what was retrieved without duplicating it
Decision & receipt dataAllow/deny outcome, stage, hashes, timestampsThe audit ledger itself

What TenantSage avoids storing

Deliberate non-goals.

A duplicate copy of your entire document store Content from denied requests beyond the decision record Data sold or shared with third parties for advertising

Where a customer's enforcement point runs close to their own systems, TenantSage's ledger can hold references and hashes rather than full content — enough to prove a decision was made correctly, without becoming a second copy of everything it governs.


Retention & legal hold

The ledger respects the same holds it enforces.

Evidence and decision records tied to a legal hold are retained under that hold's terms, not TenantSage's default retention schedule — the system that enforces holds against retrieval is bound by them for its own audit trail too.


Your rights, and how to reach us

Access, correction, and deletion requests.

During the pilot phase, requests about personal data processed by TenantSage should go through your organization's designated pilot contact, who will route them appropriately. A dedicated privacy contact address will be published here once the pilot program concludes.

Note: this page will be replaced with a finalized, counsel-reviewed policy — including applicable jurisdiction, data processing agreements, and a named contact — before general availability.