Privacy Policy
The short version: your cloud credentials never leave your machine, and we never see the resources you scan.
Last updated: June 23, 2026
Your credentials never leave your machine. The AgentSentry CLI (nhi-audit) makes every cloud API call locally, using credentials that stay on your own infrastructure. We never receive, store, or transmit your AWS, Azure, GCP, GitHub, or Kubernetes credentials, and we never see the identities, policies, or resources a scan finds.
1. Who we are
AgentSentry (“we”, “us”) is an open-source security tool and the hosted account service available at agentsentry.org. This policy explains what data the hosted service collects. The CLI is open source (AGPL-3.0) and you can audit exactly what it does at any time.
2. What we collect
We collect the minimum needed to run accounts, licensing, and billing:
- Account data, your email address, used for passwordless (magic-link) sign-in.
- License data, your license key/tier and activation timestamps, so the CLI can verify your plan.
- Billing data, handled by Stripe. We store a customer reference and subscription status, never your card details.
- Basic web logs, standard request metadata (IP, user agent, timestamps) for security and abuse prevention.
3. What we do NOT collect
- Your cloud credentials or API keys.
- The contents of any scan, the identities, roles, policies, secrets, or resources AgentSentry finds.
- Any secret values. The CLI flags risky secrets locally; it never transmits them.
Scan results live only on your machine (printed to your terminal, or written to the output file you choose). If you use the optional automation/scheduled-scan add-on, only the summary fields you explicitly opt into emailing are sent, never raw findings.
4. How we use your data
- To authenticate you and operate your account.
- To validate your license tier when the CLI activates or checks your subscription.
- To process payments and manage subscriptions (via Stripe).
- To detect and prevent abuse, fraud, and security incidents.
We do not sell your data, and we do not use it for advertising.
5. Consent & data handling
We ask for your explicit consent at the two points where you start using AgentSentry, and we record it so both you and we have a clear, dated record of what you agreed to.
- At sign-up (web), before your account is created, you must actively agree to the Terms of Service and this Privacy Policy in a confirmation dialog. You cannot create an account without granting this consent.
- At CLI activation, the
agentsentry activatecommand shows the same terms and requires explicit acceptance before the tool is activated on your machine.
When you consent, we record only what is needed to prove that consent: the type of consent (sign-up or CLI activation), which documents and version you agreed to, the time, and the IP address the request came from. We do not collect any additional profile information as part of this, no name, company, phone number, or job title is required or stored.
If we materially change the Terms or this Policy, we update the version and may ask you to consent again. You can withdraw consent at any time by deleting your account (see the “Your rights” section below); note that some features cannot operate without it.
6. Subprocessors
We rely on a small set of trusted providers to run the hosted service:
| Provider | Purpose | Data shared |
|---|---|---|
| Vercel | Web hosting & API | Account email, request logs |
| Stripe | Payments & subscriptions | Email, billing details |
| Resend | Transactional email (magic links) | Account email |
7. Data retention
We keep account, license, and billing data for as long as your account is active. Request logs are retained for a limited period for security purposes and then rotated out. When you delete your account, we remove your personal data within 30 days, except where we are required to retain records (e.g. tax/billing) by law.
8. Your rights
You can request access to, correction of, or deletion of your personal data at any time. If you are in the EU/UK, you have rights under the GDPR including access, rectification, erasure, and portability. To exercise any of these, email privacy@agentsentry.org.
9. Changes to this policy
We’ll update this page when our practices change and revise the “last updated” date above. Material changes affecting account holders will be communicated by email.
10. Contact
Questions about privacy? Email privacy@agentsentry.org. For security issues, see our Security Policy.