Back to Arbood

Privacy Policy

Effective Date: June 13, 2026 | Document ID: AP-PRV-2026-V2

Arbood Inc. ("Arbood", "we", "us", or "our") operates a suite of artificial intelligence tools for cybersecurity auditing, penetration testing, compliance reporting, and risk score calculation (collectively, the "Services"). We are deeply committed to safeguarding your privacy and protecting all organizational and personal data under our administration.

This strict Privacy Policy governs the access, storage, processing, and transfer of data collected when using our site and services. By accessing our Services, you agree to the binding terms of this Policy.

1. Data Collection Categories

We process data under strict encryption and isolation guidelines. We collect information that you submit to us directly or that is generated automatically during system utilization.

Category Description Retention Limit
Account Registry Data Corporate email, company name, billing contacts, and credential hashes. Duration of contract + 30 days
Vulnerability Scanning Logs Imported Nessus, Nmap, or Burp Suite outputs utilized for AI report compilation. Deleted after 24 hours (unless stored by explicit contract)
Behavioral Biometrics Keystroke dynamics and gesture cadences evaluated for identity validation (Secure X). Stored locally; never uploaded to primary cloud services
Compliance Audit Inputs GRC document snapshots, active IAM policies, and system config logs. Duration of audit cycle

2. Purpose of Data Processing

All data processed by Arbood is strictly utilized to deliver the core functionalities of our cybersecurity products:

AI Model Governance & Isolation

All client queries processed by BladeworkX and Report Genie X are executed in dedicated, single-tenant virtual machines. System inputs, source code uploads, and terminal execution histories are completely scrubbed from the active memory buffers immediately upon execution termination.

3. Information Sharing and Disclosure

We do not sell, rent, or lease corporate data to third parties. We will only share data under the following strict legal conditions:

  1. Subprocessors: Checked AWS and Google Cloud instances hosting isolated API nodes under tight NDAs.
  2. Regulatory Mandates: To comply with federal regulations, legal warrants, or binding audits.
  3. Mutual Defense: When threat activity on our servers requires coordinating defensive configurations with cyber threat alliances.

4. Data Storage and Security Controls

All storage entities are protected with enterprise security measures conforming to SOC 2 Type II and ISO 27001 guidelines:

5. User Rights & Data Scrubbing

You have full authority over your data. In compliance with GDPR and CCPA, you may request access to, rectification of, or permanent scrubbing of your account databases. Submit requests to privacy@arbood.com. Scrubbing requests are executed within 48 business hours.