Legal
Privacy Policy
What personal and account data Ironhide collects, how it is stored and protected, and what leaves Ironhide and what never does. What Ironhide keeps from a run — the scrubbed environment, never your agent's trajectory — is detailed in Terms & Data Rights.
Beta terms · Applies to the hosted Ironhide evaluation service. The practices below are what the system enforces today.
01
What we collect
To register and run evaluations, Ironhide collects:
- Account details: an agent name and, optionally, a contact email for report links.
- Connection details: the agent registration and the API key it authenticates with (see section 2).
- Evaluation runs: what your agent did in each episode and the verdict, saved as labeled records (see Terms & Data Rights).
Ironhide runs your agent through hand-authored, synthetic attack episodes. The attacks are staged; Ironhide does not scan your production systems and does not collect data from them.
02
What we hold
Ironhide runs one way: your agent runs where it already lives, inside your own CI/CD.
- Your agent stays with you. Its code, weights, and prompts never leave your infrastructure. The episode runs in your pipeline; Ironhide never receives your agent itself.
- Only results flow inbound. Ironhide receives the record of the run — the actions your agent took and the observed-state evidence the referee grades — over an authenticated connection keyed to your wk_live_ API key.
- Registration. Ironhide stores your agent's name and identifiers so results can be attributed to it. The API key is stored only as a one-way hash (see section 3).
03
How your data is protected
- Your API key is shown once at registration and stored only as a one-way hash. Ironhide cannot recover it.
- Run results are transmitted over an authenticated connection and stored against your agent's opaque id.
- Agent routes (runs, reports, data, plan) require your API key; operator routes require a separate operator token.
- Your agent never sees another customer's data, and no other customer's agent ever sees yours.
04
What leaves Ironhide, and what never does
Your name, contact email, and agent identifiers are held only in the agent registry, a separate store that is never exported.
Your agent's trajectory is never resold. What Ironhide retains from a run is the environment your agent was tested against — scrubbed of secrets and added to the shared attack-episode library so every agent is graded against a growing world. Your agent's own prompts, code, and recorded actions are used only to render your results and your CI gate.
Anything that does feed the shared library is de-identified first: none of the fields above are included, and your agent's id is replaced with a random, per-export pseudonym that cannot be joined back to you or to any other export. Preview-grade and held-out evaluation output is excluded from every shared or sold dataset (see Terms & Data Rights).
Ironhide does not sell your identifiable personal data.
05
Data stored in your browser
Signing in stores your email and your agent's identifiers in this browser's local storage so you stay signed in on this device. Signing out (or ironhide logout) clears them. This is a convenience mechanism on your device, not a security control.
06
Retention and deletion
Delete your agent and Ironhide removes your registration and all stored secrets immediately. Your reports and run history go with it.
Scrubbed, de-identified environment data that has already been added to the shared attack library at record time is not individually reversible — it no longer carries your identifiers or your agent's trajectory. This is described in Terms & Data Rights.
Questions about your data or a deletion request? Email hello@ironhideai.com.
IRONHIDE