Skip to main content
Last Update: July 9, 2026 Flint AI Platform helps you understand and secure AI agents in your organization. This page explains what data we collect, how we protect it, and how you can manage it. Legal agreements: For GDPR compliance details, see our Data Protection Addendum.

What data we collect

Account and authentication data

When you create an account, we collect:
  • User information - Names, email addresses, user IDs
  • Authentication credentials - API keys (encrypted), session tokens
  • Organization details - Organization name, team membership

Code and repository data

When you connect a code repository:
  • Repository metadata - Repository URLs, branch names, file paths
  • Code snippets - Small excerpts (typically 100-500 characters) showing where agents are used
  • Commit information - Author names/emails, timestamps, commit messages (from git history)
What we don’t collect: We don’t capture your entire codebase - only snippets showing where agents are used. However, depending on your repository structure and agent implementation patterns, these snippets may occasionally be larger than 500 characters to provide sufficient context for security analysis.

Agent session data

When you monitor runtime agent sessions:
  • Agent prompts - Input prompts sent to LLM models
  • LLM responses - Model outputs and completions
  • Model metadata - Model identifiers (for example, “claude-3-5-sonnet”), timestamps
  • Policy violations - Guardrail policy IDs and enforcement actions

System metadata

To operate the service, we collect:
  • IP addresses - For security monitoring and access control
  • Session IDs - To track user sessions and API requests
  • Trace IDs - For debugging and performance monitoring
Prohibited Data. We collect ordinary Personal Data as described above (names, emails, code metadata). However, you must not submit Prohibited Data (as defined in our End User License Agreement Section 7(c)), including:
  • Secrets - Passwords, API keys, private keys, tokens in code or prompts
  • Sensitive categories - Health records, financial accounts, government IDs, biometric data, data revealing racial/ethnic origin, political opinions, religious beliefs
The Personal Data we collect is necessary to operate the service and is not Prohibited Data.

How we protect your data

Encryption

  • In transit: All data transmitted to Flint AI uses TLS 1.2 or higher (HTTPS)
  • At rest: All stored data is encrypted using AES-256 or equivalent industry-standard encryption
  • API keys: Your authentication credentials are encrypted before storage

Access controls

  • Principle of least privilege: Only authorized SandboxAQ personnel can access customer data, and only when necessary for support or operations
  • Role-based access control (RBAC): Internal access is restricted by job function
  • Multi-factor authentication (MFA): Required for all personnel accessing production systems

Network security

  • Firewall protection: Production infrastructure is protected by firewalls and network segmentation
  • Intrusion detection: Automated monitoring for unauthorized access attempts
  • DDoS protection: Distributed denial-of-service mitigation

Monitoring and incident response

  • Security monitoring: 24/7 automated monitoring for security events
  • Incident response plan: Defined procedures to detect, contain, and remediate security incidents
  • Breach notification: We’ll notify you within 72 hours if a data breach affects your data (see our DPA for details)

Compliance and audits

  • Vulnerability management: Regular vulnerability assessments and penetration testing
  • Security training: All employees receive data security and privacy training
  • Third-party audits: We undergo regular security audits and assessments
Certifications: We are pursuing industry-standard security certifications including SOC 2 Type II and ISO 27001. Contact privacy@sandboxaq.com for our current compliance status and available audit reports.

Data retention

We retain data only as long as necessary to provide the service or as required by law.

Retention periods by data type

Retention tiers:
  • Very short: Up to 14 days
  • Short: Up to 2 months
  • Medium: Up to 6 months
  • Long: Up to 1 year
  • Very long: Up to 5 years

After you cancel

When you terminate your subscription:
  • Within 30 days: We delete all Personal Data (as defined in our DPA)
  • Exception: Data required by law to retain (for example, audit logs for regulatory compliance)
  • Usage Data: Anonymized/aggregated analytics may be retained per Agreement Section 7(b)
Return your data before deletion: Request a data export within 30 days of cancellation by contacting privacy@sandboxaq.com.

Sub-processors

We engage the following third-party sub-processors to help provide Flint AI Platform: Changes to sub-processors: We’ll notify you at least 30 days in advance before adding or replacing any sub-processor. If you object on reasonable data protection grounds, contact us within 15 days at privacy@sandboxaq.com. Stay informed: Contact us to receive email notifications when we update this list.

International data transfers

Where we process data

Personal data may be processed in:
  • United States (primary infrastructure location)
  • European Union (if you select EU region, when available)
Processing locations depend on where our sub-processors maintain facilities (see Sub-processors above).

EU and UK transfers

For customers in the European Economic Area (EEA) or United Kingdom, transfers to countries without an adequacy decision are protected by Standard Contractual Clauses (SCCs). Legal framework: For full details, see our Data Protection Addendum.

Managing your data

Access your data

You can view and export your data through the Flint AI Platform dashboard:
  • Account settings: View and update user information
  • Repository connections: See which repositories are connected
  • Session history: View agent session logs and policy violations
Export your data: Contact privacy@sandboxaq.com to request a complete data export.

Delete your data

You have the right to request deletion of your Personal Data:
  • Account deletion: Delete your account from Settings, then Account
  • Specific data deletion: Contact privacy@sandboxaq.com with your request
We’ll delete your data within 30 days unless retention is required by law.

Data subject rights (EU/UK)

If you’re in the EEA or UK, you have additional rights under GDPR:
  • Right to access - Request a copy of your Personal Data
  • Right to rectification - Correct inaccurate data
  • Right to erasure - Request deletion (“right to be forgotten”)
  • Right to restriction - Limit how we process your data
  • Right to portability - Receive your data in a machine-readable format
  • Right to object - Object to processing based on legitimate interests
To exercise these rights, contact privacy@sandboxaq.com.

Third-party integrations

Flint AI Platform integrates with:
  • GitHub - To discover agents in your code repositories
  • LLM providers - When you use runtime monitoring, we observe interactions with your configured LLM providers (but don’t control their data handling)
Your responsibility: When you authorize these integrations, data sharing is governed by:
  1. Your agreement with the third-party provider (for example, GitHub Terms)
  2. Our End User License Agreement
  3. Our internal security protocols
We ensure third-party providers adhere to appropriate security standards before integration.

Data compaction and storage tiers

Automatic data optimization

To manage data efficiently while maintaining security: Data compaction: For certain ID-based data, such as inventory records, we retain only the most current version once older versions have been processed. This reduces redundancy and ensures data integrity. Tiered storage: Older data is automatically moved to long-term storage tiers with appropriate security controls. This balances performance (fast access to recent data) with cost-effectiveness (cheaper storage for historical data). Example: A 6-month-old agent session might be moved to archival storage, but remains accessible if you need it for compliance reporting.

Privacy policy

This page describes how we handle data when acting as a Processor on your behalf (that is, processing data you control). For information about data we collect when acting as a Controller (for example, website analytics, product usage), see our Privacy Policy.

Data Protection Addendum (DPA)

If you’re subject to GDPR or other data protection laws, see our Data Protection Addendum for:
  • Legal roles (Controller vs. Processor)
  • GDPR Article 28 compliance details
  • Standard Contractual Clauses (SCCs)
  • Audit rights and breach notification procedures

End User License Agreement

For general terms about Customer Data, see our End User License Agreement Section 7(c):
  • What constitutes Customer Data
  • Prohibited Data (what not to submit)
  • Usage Data (anonymized analytics)

Contact us

For data handling questions:
Email: privacy@sandboxaq.com
For technical support:
Email: support@sandboxaq.com
For security issues:
Email: security@sandboxaq.com