Back to Home

    Data Usage Policy

    Last updated: April 2026

    1. Overview

    This Data Usage Policy describes how Tebrim, Inc. ("Tebrim") processes, handles, and protects data that flows through the Tebrim AI Security Orchestration Platform ("Platform"). This policy applies to all customers, users, and organizations that access or use the Platform under a valid subscription or pilot agreement. This policy should be read alongside our Privacy Policy and Terms of Service. In the event of any conflict between this policy and the Terms of Service, the Terms of Service shall govern.

    2. Categories of Data We Process

    Tebrim processes the following categories of data in the course of providing the Platform: • Customer Account Data: Organization name, billing contact, user profiles, authentication credentials, and subscription details. • Infrastructure Metadata: Cloud provider account identifiers, Kubernetes cluster names, API endpoint URIs, and network topology data collected through read-only discovery connectors. No workload data or application code is accessed. • AI Agent Inventory Data: Discovered AI agent names, model identifiers, deployment locations, invocation frequency, associated IAM roles, and policy bindings. • Security Telemetry: Event logs, request/response metadata (excluding sensitive payload content unless explicitly configured), behavioral anomaly signals, policy enforcement records, and threat detection alerts. • Audit and Compliance Records: Timestamped records of user actions, policy changes, agent orchestration events, and configuration modifications within the Platform. • Performance and Diagnostics: Aggregated Platform usage metrics, error rates, latency data, and feature adoption telemetry used solely for service improvement.

    3. How We Use Your Data

    Tebrim uses data exclusively to: • Deliver and operate the Platform, including real-time agent discovery, monitoring, threat detection, and orchestration services. • Generate security insights, compliance reports, and audit trails for your organization. • Enforce security policies, segmentation rules, and cost budgets configured by your administrators. • Provide customer support, diagnose technical issues, and respond to incident reports. • Improve Platform reliability, accuracy of threat detection models, and feature functionality using anonymized, aggregated signals. • Comply with applicable legal obligations. Tebrim does not use your Customer Data or security telemetry to train external AI models, sell to data brokers, or share with third parties for advertising purposes.

    4. Data Minimization and Least Privilege

    Tebrim is designed with data minimization as a core principle: • Discovery connectors operate with read-only, least-privilege IAM permissions. Tebrim never requires write access to your cloud infrastructure. • Payload content from AI agent calls is not collected or stored by default. Customers may opt in to selective payload logging for forensic purposes, subject to data classification controls. • Tebrim does not access, read, or store raw credentials, secrets, or private keys. Cloud provider credentials provided for integration are encrypted at rest and never logged. • Retention of security telemetry is bounded by your subscription tier and configurable data retention policies.

    5. Data Residency and Storage

    Tebrim stores Customer Data in cloud infrastructure hosted within your selected region. Available regions include US East, US West, EU West (Frankfurt), and APAC (Singapore), subject to subscription tier. Data at rest is encrypted using AES-256. Data in transit is encrypted using TLS 1.2 or higher. Encryption key management is handled via dedicated key management services with hardware security module (HSM) backing. Customers on Enterprise plans may request data residency attestations and infrastructure-specific SOC 2 reports.

    6. Data Retention

    Default retention periods by data category: • Security event logs and discovery snapshots: 12 months (hot), with optional archival up to 7 years for compliance-driven customers. • Audit trails: 12 months on Growth plans; configurable on Enterprise plans. • Account and billing data: 7 years, as required by financial regulations. • Diagnostic and performance telemetry: 90 days. Upon account termination, Customer Data is purged within 90 days, unless a longer retention period is required by law or agreed in writing. Customers may request earlier deletion by contacting contact@tebrim.com.

    7. Third-Party Sub-processors

    Tebrim engages vetted sub-processors to support Platform operations. All sub-processors are bound by data processing agreements (DPAs) that restrict their use of Customer Data to the purposes defined herein. Current sub-processor categories include: • Cloud Infrastructure: Hosting, storage, and compute (AWS, Azure, GCP depending on region). • Payment Processing: PCI-DSS Level 1 compliant payment processors. Raw card data is never stored by Tebrim. • Observability and Monitoring: Aggregated, anonymized infrastructure performance data only. • Customer Support: Ticketing and communication platforms, with access limited to support-relevant data. An up-to-date list of sub-processors is available upon request at contact@tebrim.com. Customers on Enterprise plans will be notified of material sub-processor changes with at least 30 days' notice.

    8. Access Controls and Internal Governance

    Access to Customer Data within Tebrim is governed by strict internal controls: • All employee access to production systems requires MFA and is subject to audit logging. • Access is granted on a need-to-know basis, reviewed quarterly, and revoked immediately upon role change or departure. • Customer-facing support personnel access data only when required to resolve a specific support ticket, and only with the minimum scope necessary. • All access to Customer Data by Tebrim personnel is logged and reviewable upon request by Enterprise customers.

    9. Your Data Rights

    Customers retain ownership of all Customer Data. You may at any time: • Request an export of your organization's data in a structured, machine-readable format. • Request deletion of your Customer Data, subject to legal retention obligations. • Configure data retention windows and classification policies within the Platform. • Terminate your subscription and request confirmation of data purge. To exercise these rights, contact contact@tebrim.com. Enterprise customers may also exercise data rights through their designated Customer Success Manager.

    10. Contact

    For questions about this Data Usage Policy, data processing agreements, or to exercise your data rights, contact: Data Protection Officer Tebrim, Inc. Email: contact@tebrim.com Privacy inquiries: contact@tebrim.com