RiskVoid
Threat modelingCoverageEU AI ActProductHow it worksFAQBlog

Privacy Policy

Last updated · April 21, 2026

1. Who we are

RiskVoid, Inc. (“RiskVoid”, “we”, “us”) operates a DevSecOps platform that performs threat modeling and vulnerability analysis on source code for AI agents. This Privacy Policy explains what information we collect when you visit riskvoid.com, submit a lead through the analyze form, or receive an analysis from our platform.

2. Information you provide

Contact and lead information

When you submit the analyze form or contact us, we collect the information you provide, which may include your work email, full name, company, role, team size, primary framework, and a free-text description of the agent you would like us to review.

Source code you submit

If we engage with you on an analysis, you may grant us access to a source repository. We clone it read-only into an isolated sandbox. We do not retain the cloned source after the analysis is complete; we retain only the generated report and the metadata necessary to reproduce it.

3. Information we collect automatically

  • IP address and user-agent string, for security and rate-limiting purposes.
  • Referrer URL and any UTM parameters present on the page you arrived from.
  • Pages viewed and anonymous aggregated usage via Vercel Analytics.
  • A Cloudflare Turnstile challenge token on form submission, which Cloudflare may process according to its own privacy policy.

4. How we use your information

  • To respond to your inquiry and line up an intro call or analysis.
  • To deliver, debug, and improve the analysis we perform on your behalf.
  • To operate the website: serving pages, preventing abuse, and measuring aggregate traffic.
  • To comply with legal obligations when they apply.

We do not use your information for behavioral advertising, and we do not sell it.

5. How we share information

We share information only with the service providers we need to run the platform. These include:

  • Supabase (database, authentication).
  • Vercel (hosting, analytics).
  • Cloudflare (DNS, edge, Turnstile bot mitigation).
  • Anthropic and OpenAI (LLM inference for parts of the analysis pipeline).

We may also disclose information when required by law, when necessary to investigate fraud or security incidents, or in connection with a corporate transaction (merger, acquisition, asset sale) where the recipient is bound by terms at least as protective as this policy.

6. Data retention

We retain lead submissions for up to 24 months from the date of submission, unless you ask us to delete them sooner. We retain analysis reports for the duration of your engagement with us plus 12 months, unless a contract specifies otherwise. Aggregated analytics data is retained indefinitely in anonymized form.

7. Your rights

Depending on your location, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to processing or withdraw consent. To exercise any of these rights, email us at hello@riskvoid.com. We will respond within 30 days.

8. International transfers

Our infrastructure is hosted in the United States and the European Union. If you are located outside those regions, your information may be transferred to, stored in, and processed in them. We rely on standard contractual clauses where applicable.

9. Security

We use encryption in transit (TLS 1.2+) and at rest for all data we store. We restrict internal access to personal information to the team members who need it to do their work. No method of transmission over the internet is perfectly secure; if we become aware of a breach that affects you, we will notify you without undue delay.

10. Cookies

We use a small number of strictly necessary cookies to keep you signed in and to remember your cookie consent. We do not use third-party advertising cookies.

11. Children

RiskVoid is not directed at children under 16. We do not knowingly collect personal information from anyone under 16.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change, we will update the “Last updated” date at the top of this page and, where appropriate, notify you by email.

13. Contact

Questions about this policy or a specific request?

RiskVoid, Inc. · hello@riskvoid.com
RiskVoid

Shift-left security for teams shipping AI agents.

CompanyBloghello@riskvoid.com
LegalPrivacyTerms
© 2026 RiskVoid, Inc.