Privacy Policy & Data Protection Addendum
Last updated: October 2026 • Compliant with GDPR (EU 2016/679) & CCPA/CPRA
1. Our Commitment to Data Minimization
At TKOResearch Inc. ("SentinelNHI"), we design our cybersecurity platform around the core principle of Data Minimization. We collect and process only the strictly necessary metadata required to identify non-human identity security vulnerabilities, calculate vector scope risk, and fulfill regulatory compliance attestations.
2. Express Zero-Secret-Storage Architecture
SentinelNHI never collects, decrypts, or stores plaintext API keys, Personal Access Tokens (PATs), SSH private keys, or client secrets. Our discovery engine inspects read-only platform metadata (e.g., application identifiers, assigned permission strings, creation timestamps, and sponsor email addresses).
3. Information We Collect
We process the following categories of data solely to provide the Services:
- Customer Account Data: Name, work email address, organization name, and billing details (managed securely by Stripe).
- SaaS Integration Metadata: Application names, service account identifiers, assigned OAuth scope lists, and token expiration timestamps.
- Sponsor Identity Attribution: Email address and active/deactivated employment status of the human user who granted or authorized the integration.
- Platform Audit Telemetry: Log timestamps of discovery scans, autopilot quarantine actions, and user console interactions.
4. Third-Party Subprocessors
We utilize a strictly vetted group of infrastructure and service providers to operate SentinelNHI:
| Subprocessor | Role | Data Location |
|---|---|---|
| Neon Inc. | Serverless PostgreSQL with pgvector | United States (AWS) |
| Upstash Inc. | Serverless Redis Task Queuing | United States |
| Cloudflare Inc. | R2 Cryptographic Object Storage & Edge CDN | Global Edge |
| Resend Inc. | Transactional Email & CISO Incident Digests | United States |
| Stripe Inc. | PCI-DSS Level 1 Billing & Subscription Management | United States |
5. Data Retention & Cryptographic Evidence
Audit events and remediation logs are retained for the duration of Customer's active subscription. Compliance evidence packages generated for DORA and NIS2 are stored in Cloudflare R2 for up to 365 days or until Customer requests deletion. Upon account termination, customer database records are purged within thirty (30) days.
6. Exercising Your Rights (GDPR & CCPA)
You have the right to access, rectify, restrict processing, or request deletion of your personal data. To exercise any data protection rights, or to request a Data Protection Agreement (DPA), contact our Data Protection Officer at: