Privacy notice
Last updated 17 August 2026. This describes what happens to information you give us through this website, our assessment tool and our client portal.
The short version. If you fill in a form here, we use what you send to reply to you. We do not sell it, we do not add you to a marketing sequence you did not ask for, and we do not share it with anyone except the service providers listed below who help us run the business. In our client work we hold governance metadata only — never your prompts, your model responses, or the contents of your documents.
AegisPoint is a trading name of TrustPlane LLC, Montana, United States. For any question about this notice or about information we hold, write to privacy@aegispoint.ai.
The discovery-call form and the partner enquiry form
Your name, work email, organisation, and whatever you choose to write in the notes field. The discovery-call form also records the sector and stage you select, and whether you opted in to the Daily AI Risk Brief. We use this to reply to you and, if you opted in, to send the brief. You can unsubscribe from the brief at any time.
Reached by an assessment link we send you
Your name and role, your organisation, the date, and your answers to the assessment questions. This is the substance of an engagement rather than a marketing interaction: we use it to produce your assessment, and it is retained as part of that engagement record.
clients.aegispoint.ai, for clients with an account
Account details for the people your organisation nominates, and the governance records that make up your programme — inventory entries, risks, policies, roadmap items and evidence references. Access is scoped to your organisation at the query layer.
Our host records standard request information, including IP address, when a page is served. We do not run advertising trackers or third-party analytics on this site.
In our client work we hold governance metadata only. We record that an event happened, which framework domain it maps to, and whether an adopted policy covers it. We do not hold prompt text, model output, or the contents of your documents. That boundary is architectural rather than a policy we could quietly relax, and it exists so that we do not become a custodian of your regulated data.
We use the following providers to run the business. Each processes information on our behalf under its own terms.
| Provider | What it does for us |
|---|---|
| Netlify | Hosts this website and receives form submissions |
| Airtable | Stores engagement and governance records, including assessment responses |
| Softr | Runs the client portal interface over those records |
| Microsoft 365 | Email, documents and file storage |
| Anthropic | Provides the AI models behind our agents and assessment tooling |
We do not sell personal information, and we do not share it with anyone for their own marketing.
Enquiries that do not become engagements are kept while they are live and then deleted. Engagement records are retained for the duration of the engagement and afterwards for as long as we need them to evidence the work — governance records are, by their nature, the thing a later audit asks about. If you want your information removed, write to us and we will tell you what we hold and what we can delete.
You can ask us what information we hold about you, ask us to correct it, ask us to delete it, or unsubscribe from the Daily AI Risk Brief. Write to privacy@aegispoint.ai and a person will answer — not an agent.
Depending on where you live you may have additional rights under laws such as the GDPR or state privacy legislation. Tell us where you are based when you write and we will handle your request on that footing.
If this notice changes materially we will update the date at the top and, where the change affects an active engagement, tell the client contact directly.
AegisPoint is not a law firm, and this notice is a plain description of our practices rather than legal advice. It does not form part of any contract; engagement terms are agreed separately in writing.