AgentVault

Twitter

Legal

Privacy Policy

Effective May 1, 2025. This policy explains how AgentVault manages the information you provide and how we protect the secrets entrusted to the platform.

Data Collection

We collect the minimum amount of information required to operate AgentVault and keep your organization secure. This includes account details you provide, audit activity metadata, and operational diagnostics that help us maintain reliability.

Secrets and credentials that you store in AgentVault are encrypted client-side and never persisted in plaintext.

Use of Information

Collected information is used to provide, maintain, and enhance the AgentVault platform. We leverage aggregated product usage analytics to improve ergonomics and to prioritize new capabilities.

We never sell personal information, and we only share data with subprocessors required to deliver the service — each bound by strict security and confidentiality obligations.

Data Security

AgentVault employs layered, defense-in-depth controls. Secrets are encrypted with AES-256-GCM, access is gated by scoped authentication, and all operations are logged for auditability.

We continuously monitor for vulnerabilities and remediate issues promptly. Customers are notified of security incidents that impact their data.

Your Rights

You can request access to, correction of, or deletion of your personal information at any time. Administrators can manage data retention policies within the product UI or via the API.

For any data subject requests, we respond within applicable regulatory timelines and confirm once the request is fulfilled.

Contact Us

Questions about this policy or your data privacy rights? Reach out to our security team at hello@agentvault.co.