Trust

Privacy Policy

How Armorer Labs, Inc. handles data when you visit this website, use the Armorer Console and API, run a hosted scan, or install Armorer Guard.

Effective: September 18, 2026

Who we are

Armorer Labs, Inc. is a Delaware corporation (Armorer, we, us). We sell continuous security verification for AI agents: a hosted service that scans a customer repository and returns evidence and a draft pull request, and Armorer Guard, a runtime enforcement binary that customers install on their own hosts. This policy describes what data those services and this website process, why, who else receives it, how long we keep it, and how to reach us.

Customers who have signed a Cloud Service Agreement and Data Protection Agreement with us are governed by those documents for the customer data we process on their behalf. Where they differ from this page, the signed agreement controls. See our Terms.

The hosted platform is not intended to process payment card, health or other special-category data.

What this policy covers

  • This website, armorerlabs.com, including the threat-intel email subscription and Book a call links.
  • The Armorer Console at console.armorerlabs.com and the API at api.armorerlabs.com.
  • Hosted scanning of customer repositories through the Armorer GitHub App.
  • Telemetry received from Armorer Guard binaries that customers install.

The data we process

Customer source code, during opt-in hosted scans

A hosted scan reads a repository through the read-only Armorer GitHub App, using a token that is short-lived and scoped to that one repository, and clones the repository at a pinned commit into an ephemeral task. The working copy is destroyed when the task ends. Outside the two exceptions below, source code is not written to durable storage, and it is never copied to a laptop, a shared document, a work item or a chat message.

During an opt-in hosted scan, the customer source being scanned and the findings derived from it are sent to the model provider named in our subprocessor list, under that provider's API terms. The provider's published business terms restrict training use absent explicit agreement. Account-specific retention settings and any zero-data-retention approval have not yet been independently confirmed.

Source code is kept beyond the scan task in only two cases: when a customer approves retention for an open support case, and when a copy is kept for only as long as it takes to reproduce a reported defect and is then deleted. These are the only exceptions.

Agent traces and checkpoints are off by default, are enabled only at a customer's request, and are kept for 30 days.

Scan artifacts and evidence bundles

The result of a scan is an evidence bundle and a draft pull request on the customer's repository. Evidence bundles exclude source code by schema. They are stored in production object storage under a prefix for that tenant, encrypted with keys we manage in AWS Key Management Service. The draft pull request stays in the customer's repository under the customer's control; Armorer never merges it.

Armorer Guard telemetry

Guard runs on hosts that the customer operates; Armorer does not operate those hosts. Guard sends decision telemetry, licensing data and coverage data to the hosted platform. The telemetry is designed to be content-free: it reports the decisions Guard made, not the content those decisions were about.

Account and contact data

Sign-in to the Console is handled by WorkOS AuthKit. We hold your business email address and user and session identifiers. We do not store customer passwords. When your organization installs the Armorer GitHub App, we receive the installation and repository identifiers needed to request short-lived, single-repository tokens. We also hold the contact details and correspondence you send to support@armorerlabs.com or security@armorerlabs.com, and we send account and service notices by transactional email through Resend.

Website data

When you subscribe to threat-intel email, we store the email address you enter, the page it came from and the time, together with SHA-256 hashes of your network address and browser user agent. The hashes are used to rate-limit submissions and detect abuse; we do not store the raw address. Cloudflare provides the subscription endpoint, D1 storage and Turnstile bot protection. Resend sends the subscription and update messages.

Book a call links send you to Cal.com. Cal.com receives the contact and scheduling details you submit there under its own terms and privacy policy. We may record business contact details, relationship history and call notes in HubSpot for sales and relationship follow-up. Neither Cal.com nor HubSpot has access to customer source code or the hosted production service.

We use Google Analytics 4 to measure how the site is used. It loads only on armorerlabs.com, records page paths and titles, keeps only the ref and utm_ campaign parameters from URLs, and records referrer and outbound link URLs without query strings or fragments. Google Analytics sets cookies to distinguish visits. We do not send the email address entered in the subscription form to Google Analytics.

How we use data

  • To provide and operate the services, authenticate users and keep tenants separate.
  • To run the scans a customer requests and return the evidence and the draft pull request.
  • To issue and check Guard licenses and record coverage.
  • To secure the services, prevent abuse, investigate incidents and keep audit records.
  • To send account, service and security notices, including notice of subprocessor changes.
  • To respond to requests sent to support@armorerlabs.com and security@armorerlabs.com.
  • To comply with law and enforce our agreements.
  • To measure how this website is used and follow up on meeting and product inquiries.

We do not sell personal information and do not use it for cross-context behavioral advertising.

Who receives data

We rely on a small number of providers to run the services. The current list, with what each provider can reach and the date it was last checked, is published on our Security page. Where a customer agreement requires notice of subprocessor changes, we update the list in the same change that adds the provider and email the customer's account contact at least 30 days before the new provider begins processing customer data.

We also disclose data to the administrators of your organization for data they control; when required by law, or to protect rights, safety and security; and as part of a merger, financing, acquisition or sale of assets, subject to appropriate protections.

Where data is processed

The hosted service runs on Amazon Web Services in the United States. The primary region is us-east-1 (Northern Virginia). us-west-2 (Oregon) is permitted and is used only for a second threat-detection deployment. Data is processed and stored in the United States, by us and by our providers. If you use the services or this website from outside the United States, you consent to the transfer of your data to the United States.

How long we keep data

Retention periods are set in our data retention policy. Some are enforced by infrastructure; others are commitments we carry out by hand until they are automated.

Retention periods by data type
DataHow long we keep it
Customer source code cloned for a hosted scanLife of the ephemeral scan task, subject to the two exceptions described above
Customer repository access tokensLife of the task; short-lived and scoped to one repository
Customer-derived scan artifactsNo artifact class is held beyond 90 days
Evidence bundles (source-code-free)Engagement term plus 12 months
Agent traces and checkpoints (off by default)30 days
User identity and session recordsAccount life plus 30 days after termination
Guard telemetry (content-free)90 days
Guard licensing and coverage recordsTerm plus 12 months
Application and platform logs90 days
Audit trail of our own AWS organization90 days
Threat-intel subscription recordsUntil unsubscribe, then deleted within 30 days
Sales and relationship contact records24 months from last contact

Deleting a record does not purge it at once. Point-in-time recovery on our tables and object versioning on our buckets keep recoverable copies for a period after deletion, and disposal is complete only when those copies have aged out.

Deletion when a customer leaves

When a customer terminates, deletion completes within 30 days. The GitHub App installation is removed, Guard licenses are deactivated, and the customer's artifacts, evidence bundles, agent traces, telemetry and identity records are deleted, noncurrent versions included. Where the customer's data sits under its own encryption key, that key is scheduled for deletion. We send written confirmation naming what was deleted and what necessarily remains: entries in our own audit trail, which cannot be altered for 90 days and then expire, and the customer's copies of draft pull requests, which we do not control.

Security

The hosted service runs on AWS with federated, short-lived access and no long-lived credentials. Data is encrypted in transit with TLS 1.2 or higher and at rest with AWS KMS, with customer-managed keys on most production tables. Every production change reaches the default branch through a pull request with automated review, and an organization-wide audit trail is kept for 90 days. A SOC 2 Type 1 examination is in preparation; we do not currently hold a SOC 2 report. The controls, and the limitations we know about, are described on our Security page. No method of transmission or storage is completely secure, and you are responsible for the credentials you use to reach the Console.

Your rights and choices

Depending on where you live and on your relationship with the customer that controls your workspace, you may have the right to ask for access to, correction, export, restriction or deletion of your personal information, or to object to its processing. Email support@armorerlabs.com. We verify a request by matching the details you give us with the records we hold. Where we process data on behalf of a customer, we refer the request to that customer or act on its instructions. If we refuse a request, you can appeal by replying to our response.

You can unsubscribe from threat intel email with the link in any message, and you can stop Google Analytics on this site by blocking its cookies or scripts in your browser.

Children

Our services are for businesses and their personnel and are not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact support@armorerlabs.com.

Third-party links

This site links to sites we do not operate. Their privacy practices are their own.

Changes to this policy

We may update this policy when the services, our providers or the law change. We will change the effective date above and, for material changes, notify customer account contacts by email.

Contact

Privacy questions and requests: support@armorerlabs.com. Security reports: security@armorerlabs.com. Armorer Labs, Inc. is a Delaware corporation; we operate remotely and do not publish a street address. Postal correspondence can be arranged by email.