> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flintai.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Data handling

> How Flint AI Platform handles and protects your data

**Last Update:** July 9, 2026

Flint AI Platform helps you understand and secure AI agents in your organization. This page explains what data we collect, how we protect it, and how you can manage it.

**Legal agreements:** For GDPR compliance details, see our [Data Protection Addendum](/flintai/platform/resources/dpa).

## What data we collect

### Account and authentication data

When you create an account, we collect:

* **User information** - Names, email addresses, user IDs
* **Authentication credentials** - API keys (encrypted), session tokens
* **Organization details** - Organization name, team membership

### Code and repository data

When you connect a code repository:

* **Repository metadata** - Repository URLs, branch names, file paths
* **Code snippets** - Small excerpts (typically 100-500 characters) showing where agents are used
* **Commit information** - Author names/emails, timestamps, commit messages (from git history)

**What we don't collect:** We don't capture your entire codebase - only snippets showing where agents are used. However, depending on your repository structure and agent implementation patterns, these snippets may occasionally be larger than 500 characters to provide sufficient context for security analysis.

### Agent session data

When you monitor runtime agent sessions:

* **Agent prompts** - Input prompts sent to LLM models
* **LLM responses** - Model outputs and completions
* **Model metadata** - Model identifiers (for example, "claude-3-5-sonnet"), timestamps
* **Policy violations** - Guardrail policy IDs and enforcement actions

### System metadata

To operate the service, we collect:

* **IP addresses** - For security monitoring and access control
* **Session IDs** - To track user sessions and API requests
* **Trace IDs** - For debugging and performance monitoring

<Warning>
  **Prohibited Data.** We collect ordinary Personal Data as described above (names, emails, code metadata). However, you must not submit **Prohibited Data** (as defined in our End User License Agreement Section 7(c)), including:

  * **Secrets** - Passwords, API keys, private keys, tokens in code or prompts
  * **Sensitive categories** - Health records, financial accounts, government IDs, biometric data, data revealing racial/ethnic origin, political opinions, religious beliefs

  The Personal Data we collect is necessary to operate the service and is not Prohibited Data.
</Warning>

***

## How we protect your data

### Encryption

* **In transit:** All data transmitted to Flint AI uses **TLS 1.2 or higher** (HTTPS)
* **At rest:** All stored data is encrypted using **AES-256** or equivalent industry-standard encryption
* **API keys:** Your authentication credentials are encrypted before storage

### Access controls

* **Principle of least privilege:** Only authorized SandboxAQ personnel can access customer data, and only when necessary for support or operations
* **Role-based access control (RBAC):** Internal access is restricted by job function
* **Multi-factor authentication (MFA):** Required for all personnel accessing production systems

### Network security

* **Firewall protection:** Production infrastructure is protected by firewalls and network segmentation
* **Intrusion detection:** Automated monitoring for unauthorized access attempts
* **DDoS protection:** Distributed denial-of-service mitigation

### Monitoring and incident response

* **Security monitoring:** 24/7 automated monitoring for security events
* **Incident response plan:** Defined procedures to detect, contain, and remediate security incidents
* **Breach notification:** We'll notify you within **72 hours** if a data breach affects your data (see our [DPA](/flintai/platform/resources/dpa) for details)

### Compliance and audits

* **Vulnerability management:** Regular vulnerability assessments and penetration testing
* **Security training:** All employees receive data security and privacy training
* **Third-party audits:** We undergo regular security audits and assessments

**Certifications:**

We are pursuing industry-standard security certifications including SOC 2 Type II and ISO 27001. Contact [privacy@sandboxaq.com](mailto:privacy@sandboxaq.com) for our current compliance status and available audit reports.

***

<h2 id="retention">
  Data retention
</h2>

We retain data only as long as necessary to provide the service or as required by law.

### Retention periods by data type

| Data Type                       | Retention Period                 | Why                                            |
| ------------------------------- | -------------------------------- | ---------------------------------------------- |
| **Account information**         | Until account deletion + 30 days | User management, support                       |
| **Code snippets**               | Up to 6 months (medium)          | Historical analysis, audit trails              |
| **Agent session data**          | Up to 6 months (medium)          | Compliance reporting, trend analysis           |
| **LLM prompts/responses**       | Up to 6 months (medium)          | Policy enforcement, analytics                  |
| **System events (high-volume)** | Up to 4 days                     | System fault recovery, debugging               |
| **Aggregated analytics**        | Up to 1 year (long)              | Product improvement (anonymized)               |
| **Audit logs**                  | Up to 5 years (very long)        | Regulatory compliance, security investigations |

**Retention tiers:**

* **Very short:** Up to 14 days
* **Short:** Up to 2 months
* **Medium:** Up to 6 months
* **Long:** Up to 1 year
* **Very long:** Up to 5 years

### After you cancel

When you terminate your subscription:

* **Within 30 days:** We delete all Personal Data (as defined in our [DPA](/flintai/platform/resources/dpa))
* **Exception:** Data required by law to retain (for example, audit logs for regulatory compliance)
* **Usage Data:** Anonymized/aggregated analytics may be retained per Agreement Section 7(b)

**Return your data before deletion:** Request a data export within 30 days of cancellation by contacting [privacy@sandboxaq.com](mailto:privacy@sandboxaq.com).

***

<h2 id="sub-processors">
  Sub-processors
</h2>

We engage the following third-party sub-processors to help provide Flint AI Platform:

| Sub-processor               | Service Provided              | Location(s)                   | Privacy Policy                                                     |
| --------------------------- | ----------------------------- | ----------------------------- | ------------------------------------------------------------------ |
| Amazon Web Services (AWS)   | Cloud infrastructure, storage | United States, European Union | [AWS Privacy](https://aws.amazon.com/privacy/)                     |
| Google Cloud Platform (GCP) | Cloud infrastructure, storage | United States, European Union | [GCP Privacy](https://cloud.google.com/terms/cloud-privacy-notice) |

**Changes to sub-processors:** We'll notify you at least **30 days in advance** before adding or replacing any sub-processor. If you object on reasonable data protection grounds, contact us within 15 days at [privacy@sandboxaq.com](mailto:privacy@sandboxaq.com).

**Stay informed:** [Contact us](mailto:privacy@sandboxaq.com) to receive email notifications when we update this list.

***

<h2 id="transfers">
  International data transfers
</h2>

### Where we process data

Personal data may be processed in:

* **United States** (primary infrastructure location)
* **European Union** (if you select EU region, when available)

Processing locations depend on where our sub-processors maintain facilities (see [Sub-processors](#sub-processors) above).

### EU and UK transfers

For customers in the European Economic Area (EEA) or United Kingdom, transfers to countries without an adequacy decision are protected by **Standard Contractual Clauses (SCCs)**.

**Legal framework:**

* **EU transfers:** [EU Standard Contractual Clauses (2021)](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en) - Module 2 (Controller to Processor)
* **UK transfers:** [UK International Data Transfer Addendum (IDTA)](https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/international-data-transfer-agreement-and-guidance/)

For full details, see our [Data Protection Addendum](/flintai/platform/resources/dpa).

***

## Managing your data

### Access your data

You can view and export your data through the Flint AI Platform dashboard:

* **Account settings:** View and update user information
* **Repository connections:** See which repositories are connected
* **Session history:** View agent session logs and policy violations

**Export your data:** Contact [privacy@sandboxaq.com](mailto:privacy@sandboxaq.com) to request a complete data export.

### Delete your data

You have the right to request deletion of your Personal Data:

* **Account deletion:** Delete your account from **Settings**, then **Account**
* **Specific data deletion:** Contact [privacy@sandboxaq.com](mailto:privacy@sandboxaq.com) with your request

We'll delete your data within **30 days** unless retention is required by law.

### Data subject rights (EU/UK)

If you're in the EEA or UK, you have additional rights under GDPR:

* **Right to access** - Request a copy of your Personal Data
* **Right to rectification** - Correct inaccurate data
* **Right to erasure** - Request deletion ("right to be forgotten")
* **Right to restriction** - Limit how we process your data
* **Right to portability** - Receive your data in a machine-readable format
* **Right to object** - Object to processing based on legitimate interests

To exercise these rights, contact [privacy@sandboxaq.com](mailto:privacy@sandboxaq.com).

***

## Third-party integrations

Flint AI Platform integrates with:

* **GitHub** - To discover agents in your code repositories
* **LLM providers** - When you use runtime monitoring, we observe interactions with your configured LLM providers (but don't control their data handling)

**Your responsibility:** When you authorize these integrations, data sharing is governed by:

1. Your agreement with the third-party provider (for example, GitHub Terms)
2. Our [End User License Agreement](https://www.sandboxaq.com/legal/eula)
3. Our internal security protocols

We ensure third-party providers adhere to appropriate security standards before integration.

***

## Data compaction and storage tiers

### Automatic data optimization

To manage data efficiently while maintaining security:

**Data compaction:** For certain ID-based data, such as inventory records, we retain only the most current version once older versions have been processed. This reduces redundancy and ensures data integrity.

**Tiered storage:** Older data is automatically moved to long-term storage tiers with appropriate security controls. This balances performance (fast access to recent data) with cost-effectiveness (cheaper storage for historical data).

**Example:** A 6-month-old agent session might be moved to archival storage, but remains accessible if you need it for compliance reporting.

***

## Privacy and legal

### Privacy policy

This page describes how we handle data **when acting as a Processor on your behalf** (that is, processing data you control).

For information about data we collect when **acting as a Controller** (for example, website analytics, product usage), see our [Privacy Policy](https://www.sandboxaq.com/legal/privacy-policy).

### Data Protection Addendum (DPA)

If you're subject to GDPR or other data protection laws, see our [Data Protection Addendum](/flintai/platform/resources/dpa) for:

* Legal roles (Controller vs. Processor)
* GDPR Article 28 compliance details
* Standard Contractual Clauses (SCCs)
* Audit rights and breach notification procedures

### End User License Agreement

For general terms about Customer Data, see our [End User License Agreement](https://www.sandboxaq.com/legal/eula) Section 7(c):

* What constitutes Customer Data
* Prohibited Data (what not to submit)
* Usage Data (anonymized analytics)

***

## Contact us

**For data handling questions:**\
Email: [privacy@sandboxaq.com](mailto:privacy@sandboxaq.com)

**For technical support:**\
Email: [support@sandboxaq.com](mailto:support@sandboxaq.com)

**For security issues:**\
Email: [security@sandboxaq.com](mailto:security@sandboxaq.com)
