DATA PROTECTION & PRIVACY

Privacy Policy & Data Protection Addendum

Last updated: October 2026 • Compliant with GDPR (EU 2016/679) & CCPA/CPRA

1. Our Commitment to Data Minimization

At TKOResearch Inc. ("SentinelNHI"), we design our cybersecurity platform around the core principle of Data Minimization. We collect and process only the strictly necessary metadata required to identify non-human identity security vulnerabilities, calculate vector scope risk, and fulfill regulatory compliance attestations.

2. Express Zero-Secret-Storage Architecture

Zero Collection of Plaintext Secrets

SentinelNHI never collects, decrypts, or stores plaintext API keys, Personal Access Tokens (PATs), SSH private keys, or client secrets. Our discovery engine inspects read-only platform metadata (e.g., application identifiers, assigned permission strings, creation timestamps, and sponsor email addresses).

3. Information We Collect

We process the following categories of data solely to provide the Services:

  • Customer Account Data: Name, work email address, organization name, and billing details (managed securely by Stripe).
  • SaaS Integration Metadata: Application names, service account identifiers, assigned OAuth scope lists, and token expiration timestamps.
  • Sponsor Identity Attribution: Email address and active/deactivated employment status of the human user who granted or authorized the integration.
  • Platform Audit Telemetry: Log timestamps of discovery scans, autopilot quarantine actions, and user console interactions.

4. Third-Party Subprocessors

We utilize a strictly vetted group of infrastructure and service providers to operate SentinelNHI:

SubprocessorRoleData Location
Neon Inc.Serverless PostgreSQL with pgvectorUnited States (AWS)
Upstash Inc.Serverless Redis Task QueuingUnited States
Cloudflare Inc.R2 Cryptographic Object Storage & Edge CDNGlobal Edge
Resend Inc.Transactional Email & CISO Incident DigestsUnited States
Stripe Inc.PCI-DSS Level 1 Billing & Subscription ManagementUnited States

5. Data Retention & Cryptographic Evidence

Audit events and remediation logs are retained for the duration of Customer's active subscription. Compliance evidence packages generated for DORA and NIS2 are stored in Cloudflare R2 for up to 365 days or until Customer requests deletion. Upon account termination, customer database records are purged within thirty (30) days.

6. Exercising Your Rights (GDPR & CCPA)

You have the right to access, rectify, restrict processing, or request deletion of your personal data. To exercise any data protection rights, or to request a Data Protection Agreement (DPA), contact our Data Protection Officer at:

privacy@tkoresearch.com