Legal

Attestari Privacy Policy

Effective 2026-09-23

Attestari (attestari.ai, app.attestari.ai, the Attestari device app, the lookup API and the Attestari MCP server) is a service of The Elite360 Corporation ("we", "us"). This page explains what Attestari collects, why, who processes it, and how long it is kept. It supplements the Elite360 Privacy Policy, which covers your rights, cookies in general, international transfers and how to reach us. Where the two differ on Attestari, this page governs.

The short version

  • Attestari examines public software packages. The grades we publish are about packages, not people.
  • The device app sends package names, versions and configuration hashes. It never reads your API keys, tokens, environment secrets, prompts, chat history or file contents.
  • We never sell personal information and never use it for advertising.
  • Code you send us for a private examination is analysed by our AI provider, Anthropic, which does not train its models on it.
  • Card details go to Stripe and never reach our servers.

What we collect, and why

What From where Why
Account: name, email, company, sign-in method (magic link, Google, or your company's SSO) You, your identity provider To create and secure your account
Billing: plan, seats, billing address, tax ID if given, payment status, last four digits of the card Stripe To charge you and keep tax records. Stripe holds the full card details
Device inventory: device name you choose, operating system, and for each agent tool found, its name, version, source (npm, PyPI, local path or URL) and a hash of its configuration; agent clients installed and their versions The device app To show your tools with their grades and to enforce your policy
Protect records: when a tool was allowed or blocked, the rule that applied, and hashes of the tool list a server presented The device app To enforce policy and keep the audit log your plan includes
Policy and admin actions: rules, exceptions, who requested and granted them You, your admins To run the policy your organisation sets
Lookups: API key used, package and version asked about, time, response code The lookup API and MCP server Billing per lookup, rate limiting, abuse prevention
Private artifacts: packages or skill files you ask us to examine privately (private audits, pre-publish checks, "examine this" in the device app) You To examine them and produce your report
Package claims: the registry account you use to prove you publish a package You, the registry To verify ownership before showing a publisher their full report
Waitlist: email address, time of sign-up, browser user agent You, on attestari.ai To tell you when Attestari opens to you
Messages: emails and appeals you send us You To answer you and resolve disputes
Service logs: IP address, user agent, request times, errors, device-app crash reports Our servers, the device app Security, reliability and debugging

The device app finds tools by reading the configuration files of agent clients on your machine (for example Claude Desktop, Claude Code, Cursor, VS Code). A skill file you wrote yourself is sent to us only when you click "examine this". Local files are never uploaded silently.

What is public

Result pages show a package's name, version, grade, date examined and a brief summary. The lookup counter on a result page shows a total count only; it never shows who looked. Nothing about your account, your devices or your lookups is ever published.

AI analysis

Attestari uses Anthropic's Claude models to examine packages. When you send a private artifact, its contents are sent to Anthropic for that analysis. Under Anthropic's commercial terms your content is not used to train its models, and Anthropic keeps API data only for a limited period for safety and abuse monitoring. Your device inventory, account and billing data are never sent to an AI provider.

Who processes data for us

We use a small set of providers, listed with their purpose and location at attestari.ai/subprocessors. We update that page at least 30 days before adding a provider that handles customer personal data.

How long we keep it

Data Kept for
Account data While your account is open, then deleted within 30 days of closing it
Device inventory and protect records As long as your plan's history allows (90 days on Small business, unlimited on Enterprise, current state plus 90 days on Personal), then deleted; all of it within 30 days of closing the account
Lookup records 13 months, for billing and abuse prevention
Private artifacts Deleted within 30 days after the report is delivered. The report is kept as long as your plan's history allows
Billing and tax records 7 years, as tax law requires
Service logs and crash reports 30 days
Waitlist sign-ups Until you are invited or ask to be removed
Messages and appeals 24 months after the matter is closed

Security

Traffic is encrypted in transit (TLS) and data is encrypted at rest. API keys are shown once and stored only as hashes. Secrets are held in a managed secret store, never in code. Access to customer data is limited to the Attestari engineers, through audited, access-controlled tools. Device-app releases are signed, and the app is examined under our own methodology every week.

Business accounts

When a company uses Attestari to manage its people's devices, the company controls that data and we process it on its behalf under the Data Processing Agreement, which forms part of the Attestari Terms for Small business and Enterprise accounts.

Your rights

You can see, export, correct or delete your data from the web app, or by emailing contact@elite360.ai. We answer within 30 days. If you are in the EU, UK or a US state with a privacy law, you also have the rights the Elite360 Privacy Policy describes, including the right to complain to your data protection authority. We do not sell personal information or share it for cross-context behavioural advertising.

Cookies

Attestari uses only the cookies needed to sign you in, keep your session secure and process payments (Stripe sets its own for fraud prevention at checkout). No advertising or cross-site tracking cookies.

Children

Attestari is a professional tool and is not directed at anyone under 16.

Changes

We post changes here with a new effective date. If a change materially affects how we use your data, we tell account holders by email at least 30 days before it takes effect.

Contact

The Elite360 Corporation, contact@elite360.ai.