Last updated: April 2026
Tebrim, Inc. ("Tebrim," "we," "us," or "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you access or use our AI Security Orchestration Platform (the "Platform"), including our website, SaaS application, APIs, and any related services (collectively, the "Services"). By using the Services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Services immediately.
We collect information you voluntarily provide when registering for an account, configuring the Platform, or contacting us. This includes: full name, email address, job title, organization name, billing information (processed via PCI-compliant payment providers), and support communications.
When you interact with the Services, we automatically collect: IP address, browser type and version, device identifiers, operating system, pages visited and time spent, feature usage telemetry, API request metadata (timestamps, endpoints, response codes), and session identifiers.
In the course of operating the Platform for your organization, we process: AI agent inventory and discovery metadata, security event logs and audit trails, policy configurations and enforcement records, behavioral analytics data derived from agent activity, and integration configuration details (cloud provider credentials are stored encrypted and are never logged in plaintext).
We may receive information about you from identity providers (e.g., Okta, Azure AD) when you authenticate via SSO, from cloud providers when you authorize read-only discovery connectors, and from payment processors for billing verification.
We use collected information to: • Provision, operate, and maintain the Platform and all associated Services. • Authenticate users and enforce role-based access control (RBAC) within your tenant. • Deliver security insights, threat detection alerts, compliance reports, and audit logs. • Process billing transactions and manage subscription lifecycle. • Respond to support requests, bug reports, and account inquiries. • Monitor Platform performance, diagnose technical issues, and improve reliability. • Conduct product analytics to understand feature adoption and improve user experience. • Send transactional communications (account notifications, security alerts, billing receipts). • Send product updates and marketing communications where you have opted in, with clear unsubscribe options. • Comply with legal obligations and enforce our policies.
If you are located in the European Economic Area (EEA) or United Kingdom, our legal bases for processing personal data are: • Performance of a Contract: Processing necessary to provide you with the Services you have subscribed to. • Legitimate Interests: Product improvement, fraud prevention, security operations, and service optimization, where these interests are not overridden by your rights. • Legal Obligation: Compliance with applicable laws, regulations, and lawful government requests. • Consent: Where we rely on consent (e.g., marketing emails), you may withdraw consent at any time without affecting the lawfulness of prior processing.
We do not sell, rent, or trade your personal information. We may share information only in the following circumstances: • Service Providers: With vetted third-party vendors who process data on our behalf (e.g., cloud infrastructure, payment processors, analytics tools). All vendors are bound by data processing agreements that restrict their use of your data. • Business Transfers: In connection with a merger, acquisition, financing, or sale of all or a portion of our assets, your information may be transferred, subject to standard confidentiality obligations. • Legal Requirements: Where required by law, subpoena, court order, or to protect the rights, property, or safety of Tebrim, our users, or the public. • With Your Consent: For any other purpose with your explicit consent.
We employ a defense-in-depth security posture to protect your information: • Encryption in Transit: All data transmitted between clients and our Platform is encrypted using TLS 1.2 or higher. • Encryption at Rest: All persistent data is encrypted using AES-256 encryption. Secrets and credentials are managed via dedicated secrets management systems. • Access Controls: Strict least-privilege access controls govern internal access to customer data. Privileged access requires MFA and is subject to audit logging. • Infrastructure Security: The Platform is hosted on SOC 2 Type II certified cloud infrastructure. Regular penetration testing and vulnerability assessments are conducted by independent third parties. • Incident Response: We maintain a documented incident response plan. In the event of a confirmed breach affecting your data, we will notify you as required by applicable law. No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
We retain your personal information for as long as your account is active or as necessary to provide the Services. Retention periods for specific data types: • Account data: Retained for the duration of your subscription plus 90 days following termination, to allow account recovery. • Security event logs and audit trails: Retained for up to 12 months in hot storage, with archival options available for compliance-driven customers. • Billing records: Retained for 7 years as required by financial regulations. • Support communications: Retained for 3 years. Upon request, we will delete or anonymize your personal information unless retention is required by law or for legitimate business purposes such as resolving disputes.
Depending on your jurisdiction, you may have the following rights: • Access: Request a copy of the personal data we hold about you. • Correction: Request correction of inaccurate or incomplete personal data. • Deletion: Request deletion of your personal data, subject to legal retention obligations. • Portability: Receive your personal data in a structured, machine-readable format. • Objection: Object to certain types of processing, including direct marketing. • Restriction: Request that we restrict processing of your personal data in certain circumstances. • Withdraw Consent: Where processing is based on consent, withdraw it at any time. To exercise any of these rights, contact us at contact@tebrim.com. We will respond within 30 days. Identity verification may be required before fulfilling requests.
Tebrim operates primarily in the United States. If you are located outside the United States, your information may be transferred to and processed in the United States or other countries where our service providers operate. For transfers from the EEA, United Kingdom, or Switzerland, we use Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms, to ensure your data receives appropriate protection.
We use cookies and similar tracking technologies to: • Maintain authenticated sessions and remember your preferences. • Analyze usage patterns and Platform performance through first-party analytics. • Support security features such as CSRF protection. We do not use third-party advertising cookies. You can control cookie behavior through your browser settings. Disabling certain cookies may affect Platform functionality.
The Services are intended for use by business professionals and are not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete that information promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice within the Platform at least 30 days before changes take effect. Continued use of the Services after the effective date constitutes your acceptance of the updated policy.
For privacy-related inquiries, requests, or complaints: Email: contact@tebrim.com Mailing Address: Tebrim, Inc., Attn: Privacy Team, [Address], United States If you are located in the EEA, you also have the right to lodge a complaint with your local data protection supervisory authority.