Privacy

Last updated 7 August 2026.

This describes what we collect, what we do with it, and when we delete it. It is short because we collect very little.

The commitment that matters

Your inventory is deleted on delivery of your report. We can promise this because a report is reproducible from its recorded snapshot version and assessment date — we do not need to keep your data in order to stand behind our findings.

What we collect

What we do not do

The contract check page

One page, /check, has a search box on it. It is the only page with any script at all, and the script is ours — not a third party’s.

What you type there is sent to USAspending.gov, the US government’s public award database, directly from your browser. It does not reach us. We do not receive it, log it, or store it, and we could not see it if we wanted to. We hold no list of companies and ship none to your browser — the answer comes from the public record, live, each time.

That request goes to a US government service and is subject to their handling, not ours. Nothing else on the page loads from anywhere else.

If you run it yourself

On the self-run route, we receive nothing at all unless you choose to send us the finished report. That route exists precisely because many organizations cannot release an asset inventory — for a defense contractor it is often CUI, and DFARS 252.204-7012 requires CUI to remain in systems meeting NIST SP 800-171.

If you do send a finished report back for a second read, note that it names certificate numbers and affected systems rather than every version of everything you run — materially less detail than the inventory it came from.

How long we keep things

What we may say publicly

Nothing, unless you tell us otherwise in writing. We do not name customers, quote them, or describe their estates. If we ever want to say that a finding was found — never who, never any detail — we will ask first, and refusing changes nothing about what you receive.

Mutual NDA

A mutual non-disclosure agreement is built into our terms and is in force from the moment you accept them — before you send us anything, with nothing to sign. This page describes our practice; that section is what binds us to it.

Your rights

Ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted — by email, and we will act on it. We will not ask you why.

Security

We hold as little as possible for as short a time as possible, which is the only security control that never fails. Anything you send us is held encrypted and is not shared outside AGILICRYPT.

Contact

AGILICRYPT
502 W 7th St, Ste 100, Erie, PA 16502, USA (registered office) · mail: 620 Allendale Rd, Ste 60522, King of Prussia, PA 19406
support@agilicrypt.com

Our full mailing address is on every invoice, and in the footer of anything we send you. Ask and we will give it to you.