What we process
Reported emails: message body, headers, attachments, URLs. Processed inside your tenant's deployment (cloud or on-prem VM) for verdict scoring, campaign correlation, and remediation.
Metadata: analyst identity, verdict decisions, timestamps, IP addresses for authentication — used for the audit trail and nothing else.
Contact form + demo request data: name, work email, mailbox size band, message text. Used to reply to your request. Never sold, never shared.
What crosses the boundary
Only cryptographic file hashes (SHA-256) may leave your tenant for external reputation lookups (URLhaus, PhishTank, AbuseIPDB, Google Safe Browsing). Message bodies, attachments, and identities never do.
Aggregate telemetry (verdict counts, uptime, deployment health) is sent to us in anonymised form; you can opt out.
Cross-tenant boundary
Nothing from one customer's tenant trains a model that touches another customer's tenant. Ever. Model updates ship to your deployment as versioned artefacts — you decide when they roll out.
Data retention
Reported email content: retained for the case duration + your configured retention window (default 90 days). Verdict metadata retained for the length of your contract for the audit trail.
Contact form data: 24 months. Delete request honoured within 30 days — email privacy@eyriedefender.com.
Compliance
SOC 2 Type II (in progress), GDPR data processor, CCPA compliant. DPA available on request; ping legal@eyriedefender.com.
