Privacy Policy
Parapet is built content-free by default: the gateway's audit trail and the control plane's telemetry exclude prompt and response text unless you explicitly turn that on in your own deployment. We don't sell personal information and we don't train models on your data. Control-plane data is encrypted at rest and in transit, and retained only as long as your account is active or your backup window requires. Full detail below.
1. Who this policy covers
Parapet is operated by SaaS Scaling LLC, a California limited liability company ("Parapet," "we," "us," or "our"). This Privacy Policy explains how we collect, use, store, and protect information in connection with parapet.run, the Parapet control plane (the web dashboard and API your team uses to manage policy and view telemetry), and the Parapet gateway (the runtime component that sits in your agents' request path). It applies to visitors to our website, to customers and their team members with a control-plane account, and to the traffic that passes through a Parapet-governed agent deployment.
If you're evaluating Parapet for your organization, the sections most worth reading closely are Content minimization by default and Data storage & encryption — they describe the specific technical choices that shape what we can and can't see about your agents' traffic.
2. What we collect
What we collect depends on which part of Parapet you're using:
- parapet.run (this website). Standard web analytics (pages viewed, referrer, approximate location from IP, browser/device type) and anything you submit directly, such as a contact form or a demo request (name, work email, company, and the message itself).
- Control-plane accounts. Your email address, name, the organization/tenant(s) you belong to, your role, and login/session metadata. If your organization signs in via an identity provider (OIDC/SSO), we receive the profile fields your identity provider is configured to share.
- Agent traffic through the gateway. By default, the gateway's decision audit log and the control plane's telemetry record only routing and policy-decision metadata — the calling agent's identity, the action/tool being authorized, the policy decision, and timing. Prompt text, response text, and tool-call arguments are excluded by construction unless your deployment explicitly opts in — see §3.
- Billing. If you're on a paid plan, billing details (company/billing name, address, payment method) are collected and processed by our payment processor; Parapet does not store full payment card numbers.
3. Content minimization by default
This is the part of Parapet's architecture most relevant to your privacy review, so we're specific about it rather than general:
- The gateway's
decisionaudit log strips prompt/response content before it is ever written — it records the routing and policy decision, not the message. - OpenTelemetry spans exported to the control plane follow the same rule: attributes that would carry
full prompt/response text or tool-call arguments are only populated if an operator explicitly sets
PARAPETAI_OTEL_LOG_CONTENT=truein their own deployment. This is off by default. - A separate, distinct opt-in —
PARAPETAI_LOG_PROMPTS=true, also off by default — exists specifically for teams tuning their own policy rules against real traffic shape. Turning it on is a deliberate, visible configuration change made by the operator running the gateway, never a default anyone inherits by installing Parapet.
In other words: if you evaluate a Parapet deployment out of the box, we do not have your prompts or responses. If your team turns on one of the settings above for policy tuning, that content flows to wherever your own logging/telemetry pipeline is configured to send it, under your control.
4. How we use data
- To operate the Service — authenticate you, route and authorize agent traffic per your policy, and show you the resulting audit trail and telemetry.
- To provide support and respond to what you send us.
- To send service communications (security notices, changes to these terms, account/billing notices). With your consent, product updates and marketing.
- To maintain the security, integrity, and availability of the Service, including detecting abuse.
- To comply with legal obligations.
We do not sell personal information, and we do not use customer traffic to train machine-learning models.
5. Legal bases (GDPR)
Where GDPR applies, we process personal data under one of the following bases: performance of a contract with you (operating your account and the Service), our legitimate interests (securing the Service, preventing abuse, improving reliability) balanced against your rights, compliance with a legal obligation, or your consent where we ask for it (e.g., marketing communications).
6. Data storage & encryption
- At rest. Control-plane data — accounts, tenant/policy configuration, and telemetry — is stored in Azure SQL Database, which encrypts all data at rest by default (Transparent Data Encryption, AES-256).
- In transit. Connections between the gateway and the control plane, between the control plane and its database, and between your browser and our dashboard are encrypted with TLS.
- Access control. Access to control-plane data is role-based (owner / admin / viewer). An account with a missing or unrecognized role is treated as the least-privileged role — access fails closed, never open.
- Credentials. In Parapet's default operating mode, the gateway forwards your own provider credential (e.g., your OpenAI API key) upstream unchanged and does not store it. An opt-in "broker" mode, if your deployment enables it, holds a provider credential on your behalf instead — ask us which mode your deployment runs if you're unsure.
7. Data retention & deletion
We retain account and control-plane data for as long as your account is active. Automated database backups are kept on a rolling retention window and age out automatically; data is not recoverable from a backup once it has aged out of that window.
If you close your account, or ask us to delete your data, we delete it from production systems within 30 days of the request, and it is fully purged from backups as those backups age out on their normal schedule thereafter. Content that only exists because your deployment opted in under §3 follows this same deletion timeline and is otherwise governed by whatever retention your own logging pipeline applies, since that content flows to infrastructure you control.
8. Security incident response
We maintain a security incident response process:
- Detection & monitoring. We monitor the Service for indicators of unauthorized access or misuse.
- Containment & investigation. On confirming an incident, we act to contain it and investigate its scope and root cause.
- Notification. If we determine an incident resulted in unauthorized access to your data, we will notify you without undue delay — and, to the extent required by applicable law, within 72 hours of confirming the incident — with what we know at the time: the nature of the incident, the data involved, and the steps we're taking.
- Remediation. We address the root cause and, where appropriate, share a post-incident summary with affected customers.
- Reporting a concern. If you believe you've found a security vulnerability or incident affecting the Service, email security@parapet.run. We investigate every report.
9. Sub-processors & international transfers
We use Microsoft Azure to host the Service and store control-plane data, currently in Azure's East US region. If you access the Service from outside that region, your data is transferred to and processed there. As we engage additional providers that process personal data on our behalf, we'll update this policy; email privacy@parapet.run for the current list.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise any of these, email privacy@parapet.run. We'll respond within the time required by applicable law. If you're a member of an organization's control-plane account, some of these requests may need to go through your organization's account owner, since they administer that data.
11. Children's privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16.
12. Changes to this policy
We'll update the date at the top of this page when we make changes, and for material changes we'll provide more prominent notice (e.g., email to account owners).
13. Contact us
Questions about this policy: privacy@parapet.run
Security reports: security@parapet.run
SaaS Scaling LLC, a California limited liability company