Privacy Policy
Effective July 7, 2026
Who we are
SightGlass is a security-posture monitoring and governance, risk & compliance (GRC) platform. This policy describes what we collect when you use it, why, and the choices you have. Questions? Contact [email protected].
What we collect
Account data. Your name, email address, and authentication credentials (passwords are stored only as argon2id hashes; SSO sign-in shares only what your identity provider releases).
Workspace content. What your organization puts into the product: scan reports, findings, assets, risks, controls, audit evidence, policies, and vendor records. This content belongs to your organization.
Operational records. An append-only activity log of actions taken in your workspace (who did what, when) — this is a core audit feature of the product — plus in-app notifications.
Technical data. Essential session cookies (no advertising or cross-site tracking cookies) and IP addresses used transiently for rate limiting and abuse prevention.
How we use it
Solely to operate the service: authenticate you, isolate and display your organization's data, send the emails you or your organization configure (alerts, digests, reports, verification), and keep the platform secure. We do not sell personal data or use it for advertising.
Service providers (subprocessors)
We share the minimum data required with providers that help run the service:
- Email delivery — transactional email is relayed through the configured SMTP provider (SMTP2GO by default, or your organization's own SMTP server).
- Anthropic — only if your organization enables AI features (scan analysis, remediation drafts, vendor research), the relevant finding or vendor context is sent to the Anthropic API to generate the response.
- Cloudflare Turnstile — only if bot protection is enabled, sign-in and sign-up pages include Cloudflare's challenge.
Threat-intelligence enrichment (FIRST EPSS scores, the CISA KEV catalog) involves fetching public data about CVE identifiers; no personal data is transmitted.
Retention and deletion
Workspace data is retained while your organization's account is active. Organization administrators can configure activity-log retention, after which older entries are purged automatically. When an organization is deleted, its data is removed; individual accounts can be deleted and personal fields anonymized on request.
Your rights
Depending on your jurisdiction (including under GDPR), you may have rights to access, correct, export, or delete your personal data. SightGlass includes a built-in data-subject-access export for workspace members; for anything else, contact us and we'll respond within a reasonable timeframe.
Security
Tenant data is isolated with PostgreSQL row-level security enforced at the database layer, credentials and integration secrets are encrypted at rest (AES-256-GCM), transport is TLS, uploads are malware-scanned before storage, and every mutation is recorded in a tamper-evident audit trail. See our security documentation for the full posture and how to report a vulnerability.
Changes
If this policy changes materially, we will notify organization administrators by email or in-app notice before the change takes effect.