Privacy
Last updated 7 August 2026.
This describes what we collect, what we do with it, and when we delete it. It is short because we collect very little.
The commitment that matters
What we collect
- Whatever you put in an email to us. There is no form on this site — contact is a plain email address, so nothing is collected before you choose to write.
- An asset inventory, only if you choose to send one. Software package names and version numbers. We ask you not to send host names — labels such as
system-01group the findings just as well, and we never learn the key. We ask for nothing else, and we do not want configuration files, keys, credentials, network addresses or personal data. If you send those by accident, tell us and we will delete them immediately.
What we do not do
- We do not scan your network. No agents, no credentials, no connections into your environment. Ever.
- We do not sell, share or rent your data. There is no third party involved in producing your report.
- We do not run advertising or analytics trackers on this site. No cookies are set, and there are no third-party scripts anywhere on it.
- We do not use your data to train anything.
The contract check page
One page, /check, has a search box on it. It is the only page with any script at all, and the script is ours — not a third party’s.
What you type there is sent to USAspending.gov, the US government’s public award database, directly from your browser. It does not reach us. We do not receive it, log it, or store it, and we could not see it if we wanted to. We hold no list of companies and ship none to your browser — the answer comes from the public record, live, each time.
That request goes to a US government service and is subject to their handling, not ours. Nothing else on the page loads from anywhere else.
If you run it yourself
On the self-run route, we receive nothing at all unless you choose to send us the finished report. That route exists precisely because many organizations cannot release an asset inventory — for a defense contractor it is often CUI, and DFARS 252.204-7012 requires CUI to remain in systems meeting NIST SP 800-171.
If you do send a finished report back for a second read, note that it names certificate numbers and affected systems rather than every version of everything you run — materially less detail than the inventory it came from.
How long we keep things
- Inventories: deleted on delivery of your report.
- The report itself: we keep a copy only for as long as you want us available to discuss it, and we delete it on request.
- Contact details: kept until you ask us to remove them.
What we may say publicly
Nothing, unless you tell us otherwise in writing. We do not name customers, quote them, or describe their estates. If we ever want to say that a finding was found — never who, never any detail — we will ask first, and refusing changes nothing about what you receive.
Mutual NDA
A mutual non-disclosure agreement is built into our terms and is in force from the moment you accept them — before you send us anything, with nothing to sign. This page describes our practice; that section is what binds us to it.
Your rights
Ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted — by email, and we will act on it. We will not ask you why.
Security
We hold as little as possible for as short a time as possible, which is the only security control that never fails. Anything you send us is held encrypted and is not shared outside AGILICRYPT.
Contact
AGILICRYPT
502 W 7th St, Ste 100, Erie, PA 16502, USA (registered office) · mail: 620 Allendale Rd, Ste 60522, King of Prussia, PA 19406
support@agilicrypt.com
Our full mailing address is on every invoice, and in the footer of anything we send you. Ask and we will give it to you.