Privacy Policy

What we collect, why we collect it, and what we never do with it.

Last updated January 12, 2024 · Effective January 12, 2024

Minimum data, by design

We ingest only the alert and telemetry fields needed to investigate, correlate and produce evidence. We do not collect raw email bodies, file contents or full packet captures unless explicitly forwarded by an integration you configure.

Encryption everywhere

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Customer secrets and integration credentials are stored in an isolated, key-rotated secrets vault — never in application logs or backups.

Data residency

Customer data is stored and processed in AWS us-east-1 (Northern Virginia).

No training on your data

Customer signals are not used to train the foundation model. Customer-data training uses a zero-retention policy.

1. Who we are

FactPattern Systems LLC (“FactPattern”, “we”, “us”) provides an AI investigation analyst for security operations teams. This policy explains how we handle personal data and security telemetry processed through factpattern.site and the FactPattern platform.

2. Data we process

  • Account data — name, work email, organization, role, authentication identifiers (OAuth subject, hashed passwords). Used to authenticate users and enforce role-based access.
  • Security telemetry — alerts, detections, audit events, identity events, cloud control-plane logs, EDR process metadata, DNS metadata. Forwarded by integrations you connect.
  • Investigation artifacts — analyst notes, decisions, approvals, generated briefs and exported records.
  • Product telemetry — request logs, error traces, feature-usage counters. Used to operate and secure the service. Stripped of payload contents.
  • Marketing site data — form submissions, IP-derived country, basic anonymized analytics. No third-party advertising trackers or cross-site identifiers.

3. Why we process it (legal basis)

We process customer data to perform our contract with the customer organization (GDPR Art. 6(1)(b)), to comply with legal obligations (Art. 6(1)(c)), and to pursue legitimate interests in operating, securing and improving the service (Art. 6(1)(f)). Marketing communications rely on consent (Art. 6(1)(a)).

4. AI processing and model providers

FactPattern uses OpenAI GPT-4o via the Azure OpenAI Service to draft reads of signals, investigation summaries and analyst-reviewed briefs.

  • Customer-data training uses a zero-retention policy.
  • Customer signals are not used to train the foundation model.
  • All AI outputs are surfaced as drafts that an analyst can edit, approve or reject. AI never executes containment or response actions without named human approval.
  • Customers can disable live AI inference per workspace; FactPattern then falls back to its deterministic evidence engine.

5. Service providers

Customer data is hosted on Amazon Web Services in the us-east-1 region, and model inference is performed by OpenAI GPT-4o via the Azure OpenAI Service. A current list of service providers is available on request at [email protected].

6. International data transfers

Customer data is stored and processed in the United States (AWS us-east-1). For transfers of personal data out of the EEA or UK, we rely on Standard Contractual Clauses (SCCs). SCCs are a transfer mechanism, not a certification.

7. Retention

Retention periods are agreed with the customer organization and configured per workspace. Audit logs of evidence modifications and review approvals are immutable. Deletion requests can be filed by a workspace admin.

8. Your rights

Individuals whose personal data is processed by FactPattern have the right to access, rectify, erase, restrict, port and object to processing. Most rights are exercised through the customer organization that controls the workspace (the data controller). You can also contact us directly.

9. Security

FactPattern is built read-only by default. Containment and identity actions require human approval. We run continuous vulnerability scanning, enforce SSO and MFA on all production systems, and publish a coordinated vulnerability disclosure program.

10. Children

FactPattern is a B2B product. We do not knowingly collect personal data from anyone under 16.

11. Changes

We will update this policy as the product and legal landscape evolve. Material changes are announced in-product and via email to workspace owners at least 30 days before they take effect.

12. Contact

[email protected] · Data Protection Officer reachable at the same address.