Legal
Attestari Privacy Policy
Effective 2026-09-23
Attestari (attestari.ai, app.attestari.ai, the Attestari device app, the lookup API and the Attestari MCP server) is a service of The Elite360 Corporation ("we", "us"). This page explains what Attestari collects, why, who processes it, and how long it is kept. It supplements the Elite360 Privacy Policy, which covers your rights, cookies in general, international transfers and how to reach us. Where the two differ on Attestari, this page governs.
The short version
- Attestari examines public software packages. The grades we publish are about packages, not people.
- The device app sends package names, versions and configuration hashes. It never reads your API keys, tokens, environment secrets, prompts, chat history or file contents.
- We never sell personal information and never use it for advertising.
- Code you send us for a private examination is analysed by our AI provider, Anthropic, which does not train its models on it.
- Card details go to Stripe and never reach our servers.
What we collect, and why
| What | From where | Why |
|---|---|---|
| Account: name, email, company, sign-in method (magic link, Google, or your company's SSO) | You, your identity provider | To create and secure your account |
| Billing: plan, seats, billing address, tax ID if given, payment status, last four digits of the card | Stripe | To charge you and keep tax records. Stripe holds the full card details |
| Device inventory: device name you choose, operating system, and for each agent tool found, its name, version, source (npm, PyPI, local path or URL) and a hash of its configuration; agent clients installed and their versions | The device app | To show your tools with their grades and to enforce your policy |
| Protect records: when a tool was allowed or blocked, the rule that applied, and hashes of the tool list a server presented | The device app | To enforce policy and keep the audit log your plan includes |
| Policy and admin actions: rules, exceptions, who requested and granted them | You, your admins | To run the policy your organisation sets |
| Lookups: API key used, package and version asked about, time, response code | The lookup API and MCP server | Billing per lookup, rate limiting, abuse prevention |
| Private artifacts: packages or skill files you ask us to examine privately (private audits, pre-publish checks, "examine this" in the device app) | You | To examine them and produce your report |
| Package claims: the registry account you use to prove you publish a package | You, the registry | To verify ownership before showing a publisher their full report |
| Waitlist: email address, time of sign-up, browser user agent | You, on attestari.ai | To tell you when Attestari opens to you |
| Messages: emails and appeals you send us | You | To answer you and resolve disputes |
| Service logs: IP address, user agent, request times, errors, device-app crash reports | Our servers, the device app | Security, reliability and debugging |
The device app finds tools by reading the configuration files of agent clients on your machine (for example Claude Desktop, Claude Code, Cursor, VS Code). A skill file you wrote yourself is sent to us only when you click "examine this". Local files are never uploaded silently.
What is public
Result pages show a package's name, version, grade, date examined and a brief summary. The lookup counter on a result page shows a total count only; it never shows who looked. Nothing about your account, your devices or your lookups is ever published.
AI analysis
Attestari uses Anthropic's Claude models to examine packages. When you send a private artifact, its contents are sent to Anthropic for that analysis. Under Anthropic's commercial terms your content is not used to train its models, and Anthropic keeps API data only for a limited period for safety and abuse monitoring. Your device inventory, account and billing data are never sent to an AI provider.
Who processes data for us
We use a small set of providers, listed with their purpose and location at attestari.ai/subprocessors. We update that page at least 30 days before adding a provider that handles customer personal data.
How long we keep it
| Data | Kept for |
|---|---|
| Account data | While your account is open, then deleted within 30 days of closing it |
| Device inventory and protect records | As long as your plan's history allows (90 days on Small business, unlimited on Enterprise, current state plus 90 days on Personal), then deleted; all of it within 30 days of closing the account |
| Lookup records | 13 months, for billing and abuse prevention |
| Private artifacts | Deleted within 30 days after the report is delivered. The report is kept as long as your plan's history allows |
| Billing and tax records | 7 years, as tax law requires |
| Service logs and crash reports | 30 days |
| Waitlist sign-ups | Until you are invited or ask to be removed |
| Messages and appeals | 24 months after the matter is closed |
Security
Traffic is encrypted in transit (TLS) and data is encrypted at rest. API keys are shown once and stored only as hashes. Secrets are held in a managed secret store, never in code. Access to customer data is limited to the Attestari engineers, through audited, access-controlled tools. Device-app releases are signed, and the app is examined under our own methodology every week.
Business accounts
When a company uses Attestari to manage its people's devices, the company controls that data and we process it on its behalf under the Data Processing Agreement, which forms part of the Attestari Terms for Small business and Enterprise accounts.
Your rights
You can see, export, correct or delete your data from the web app, or by emailing contact@elite360.ai. We answer within 30 days. If you are in the EU, UK or a US state with a privacy law, you also have the rights the Elite360 Privacy Policy describes, including the right to complain to your data protection authority. We do not sell personal information or share it for cross-context behavioural advertising.
Cookies
Attestari uses only the cookies needed to sign you in, keep your session secure and process payments (Stripe sets its own for fraud prevention at checkout). No advertising or cross-site tracking cookies.
Children
Attestari is a professional tool and is not directed at anyone under 16.
Changes
We post changes here with a new effective date. If a change materially affects how we use your data, we tell account holders by email at least 30 days before it takes effect.
Contact
The Elite360 Corporation, contact@elite360.ai.