Draft template. This document is a working draft prepared for the AICOMBase MVP. It has not been reviewed by counsel and must be reviewed and completed by a qualified lawyer before the service is offered publicly.

Privacy Policy

Draft last updated September 2026

1. What we store

Account data (name, email, hashed password, second-factor settings); organization and membership data; per-site connection data (domain, public key, versions, connection state); operational metadata about what AICOM did (sessions, actions, results); monitoring results (availability, response time, SSL); audit results and the evidence needed to explain each finding; and an audit log of control events.

2. What we do not store

We do not receive or store your WordPress password, private keys of your sites, or the content of your database. Passwords, private keys and raw authorization tokens are never written to logs.

3. Audit evidence

Audits fetch public pages of your site and, when you allow it, a limited internal inspection from AICOM. Evidence is kept for the retention period of your plan and then removed.

4. How we use data

To operate the service, show you your sites, send the notifications you choose, protect against abuse and improve reliability. Telemetry choices are available in Settings.

5. Sharing and processors

The list of sub-processors (hosting, email delivery, AI-assisted analysis) and international transfer mechanisms is to be completed by counsel before launch.

6. Your rights

You can request access to, export of, or removal of your account and its data from Settings, Data & Privacy. Legal bases, retention schedules and the controller contact are to be defined by counsel.

7. Security

Secrets are encrypted at rest, connections use signed requests with short-lived authorizations, and control events are recorded in an immutable audit log.