1. Who we are
FactPattern Systems LLC (“FactPattern”, “we”, “us”) provides an AI investigation analyst for security operations teams. This policy explains how we handle personal data and security telemetry processed through factpattern.site and the FactPattern platform.
2. Data we process
- Account data — name, work email, organization, role, authentication identifiers (OAuth subject, hashed passwords). Used to authenticate users and enforce role-based access.
- Security telemetry — alerts, detections, audit events, identity events, cloud control-plane logs, EDR process metadata, DNS metadata. Forwarded by integrations you connect.
- Investigation artifacts — analyst notes, decisions, approvals, generated briefs and exported records.
- Product telemetry — request logs, error traces, feature-usage counters. Used to operate and secure the service. Stripped of payload contents.
- Marketing site data — form submissions, IP-derived country, basic anonymized analytics. No third-party advertising trackers or cross-site identifiers.
3. Why we process it (legal basis)
We process customer data to perform our contract with the customer organization (GDPR Art. 6(1)(b)), to comply with legal obligations (Art. 6(1)(c)), and to pursue legitimate interests in operating, securing and improving the service (Art. 6(1)(f)). Marketing communications rely on consent (Art. 6(1)(a)).
4. AI processing and model providers
FactPattern uses OpenAI GPT-4o via the Azure OpenAI Service to draft reads of signals, investigation summaries and analyst-reviewed briefs.
- Customer-data training uses a zero-retention policy.
- Customer signals are not used to train the foundation model.
- All AI outputs are surfaced as drafts that an analyst can edit, approve or reject. AI never executes containment or response actions without named human approval.
- Customers can disable live AI inference per workspace; FactPattern then falls back to its deterministic evidence engine.
5. Service providers
Customer data is hosted on Amazon Web Services in the us-east-1 region, and model inference is performed by OpenAI GPT-4o via the Azure OpenAI Service. A current list of service providers is available on request at [email protected].
6. International data transfers
Customer data is stored and processed in the United States (AWS us-east-1). For transfers of personal data out of the EEA or UK, we rely on Standard Contractual Clauses (SCCs). SCCs are a transfer mechanism, not a certification.
7. Retention
Retention periods are agreed with the customer organization and configured per workspace. Audit logs of evidence modifications and review approvals are immutable. Deletion requests can be filed by a workspace admin.
8. Your rights
Individuals whose personal data is processed by FactPattern have the right to access, rectify, erase, restrict, port and object to processing. Most rights are exercised through the customer organization that controls the workspace (the data controller). You can also contact us directly.
9. Security
FactPattern is built read-only by default. Containment and identity actions require human approval. We run continuous vulnerability scanning, enforce SSO and MFA on all production systems, and publish a coordinated vulnerability disclosure program.
10. Children
FactPattern is a B2B product. We do not knowingly collect personal data from anyone under 16.
11. Changes
We will update this policy as the product and legal landscape evolve. Material changes are announced in-product and via email to workspace owners at least 30 days before they take effect.
12. Contact
[email protected] · Data Protection Officer reachable at the same address.