Privacy Policy
Effective Date: March 7, 2026 • Last updated: March 7, 2026
This Privacy Policy describes how Agents Incorporated collects, uses, stores, and shares your personal information when you access or use Attest, our compliance attestation platform. Please read it carefully. By using the Service, you agree to the practices described in this Policy.
In short: to analyze your code, Attest clones your repository temporarily and runs deterministic security scanners on it; only for the controls no tool can evaluate does it send the code to Anthropic (our AI provider, which does not train on it) for an “AI-assessed” verdict. The working copy is then deleted — the findings and report are what we keep. This is a plain-English summary, not a substitute for reading the full Policy below or for legal review.
1.Introduction
Agents Incorporated ("Company," "we," "us," or "our") operates Attest, a compliance attestation platform accessible at agentsincorporated.ai and its associated subdomains (collectively, the "Service"). We are incorporated and operating under the laws of the State of Israel.
This Privacy Policy ("Policy") governs our collection, use, disclosure, storage, and protection of information about you when you visit our website, create an account, subscribe to a plan, or otherwise interact with the Service. It applies to all users of the Service regardless of geographic location.
This Policy is incorporated by reference into our Terms of Service. Terms not defined here have the meanings given to them in the Terms of Service. If there is any conflict between this Policy and the Terms of Service with respect to data privacy, this Policy controls.
We are committed to handling your personal information responsibly and in accordance with applicable law, including the Israeli Privacy Protection Law, 5741-1981, and its regulations, as well as other data protection laws that may apply to your jurisdiction. If you have questions about this Policy or your personal data, please contact us at support@agentsincorporated.ai.
2.Information We Collect
We collect several categories of information depending on how you interact with the Service. We collect only what is reasonably necessary for the purposes described in this Policy.
2.1 Account Information
When you register for an account, we collect personal information you provide directly to us, including your full name, email address, chosen password (stored only as a cryptographic hash), and optionally your organization or company name. If you update your account profile, we collect any revised information you provide. This information is used to create and manage your account and to communicate with you about the Service.
2.2 Billing Information
When you purchase a one-time report or subscribe to a paid plan, your order is processed by Paddle, our merchant of record — Paddle.com Inc. for purchases made from the United States, and Paddle.com Market Limited for purchases made from elsewhere (together with their affiliates, "Paddle"). Paddle is the seller of record for your purchase and handles all payment processing, tax calculation and remittance, and transaction receipts. We do not collect, transmit, or store full payment card numbers, card verification codes (CVV/CVC), or other sensitive cardholder data on our servers. Paddle provides us with your billing name, billing country, subscription plan details, and transaction identifiers solely for the purpose of activating your purchase and managing your subscription. All payment processing is subject to Paddle's Privacy Policy.
We retain records of subscription transactions, invoice amounts, plan history, and payment dates for up to seven (7) years to satisfy our financial record-keeping and tax obligations.
2.3 GitHub Personal Access Token
If you connect a private repository, you may provide a GitHub Personal Access Token ("PAT"). Your PAT is encrypted before it is stored and is decrypted only at the moment it is needed to clone a repository for a scan. We use your PAT solely to read the repositories you have authorized; we do not use it for any other purpose, and we never display the full value back to you once it is saved.
2.4 Repository Source Code and Reports
The Service is designed for you to connect a source code repository for analysis. When you start a scan, we clone the repository you specify (collectively with any other code, files, or materials you submit, "Repository Content") into a transient working copy solely to perform the analysis. That working copy is deleted once the scan completes; we do not retain a persistent copy of your source code.
Most analysis is performed by deterministic security scanners (such as Semgrep, gitleaks, osv-scanner, and checkov) that run within the Service and produce reproducible findings. For the subset of control clauses that no deterministic tool can evaluate, the working copy is made available to Anthropic, PBC (“Anthropic”), our AI subprocessor, which processes it through its API to produce an “AI-assessed” verdict; those verdicts are clearly labeled and kept separate from the deterministic findings. Under Anthropic’s commercial terms, your Repository Content and the resulting outputs are not used to train Anthropic’s models. Anthropic’s processing of this data is governed by its own privacy policy.
We do retain the output of the analysis — including the specific findings, the control clauses they map to, the file paths and line numbers cited as evidence, the reasoning behind each finding, and the resulting attestation report (collectively, "Reports") — for as long as described in Section 7. Reports may contain snippets or references to your source code where necessary to show the evidence for a finding.
Repository Content may contain personal information about you or third parties if such information is present in the code, comments, or commit history of the repository you connect. You are responsible for the repositories you submit, and we encourage you not to connect repositories containing unnecessary sensitive personal data, credentials, or confidential third-party information beyond what is needed for your compliance review.
2.5 Scan Metadata and Usage Data
We automatically collect information about how you interact with the Service. This includes scan metadata (such as the repository connected, the framework selected, scan start/end times, and scan status), features and pages accessed, frequency and duration of use, actions taken within the platform, session duration and activity patterns, error events and performance metrics, and subscription and billing activity. This data is primarily collected to operate, maintain, improve, and secure the Service, and to enforce our Terms of Service.
2.6 Technical Data
When you access the Service, our servers and analytics systems automatically record certain technical information, including your IP address (which may be used to infer approximate geographic location), browser type and version, operating system and device type, screen resolution and language settings, referring URL, pages visited and timestamps, and HTTP request metadata. This data is used for security monitoring, fraud prevention, debugging, and aggregate analytics.
2.7 Local Storage and Session Data
The Attest application does not use cookies for authentication or session management. Instead, authentication tokens and user session data are stored exclusively in your browser's localStorage. This data is stored locally in your browser and is never transmitted except as part of authenticated API requests to the Service. No third-party tracking cookies are set by the application. See Section 11 for further details.
3.How We Use Your Information
We use the information we collect for the following purposes, relying on the legal bases indicated where applicable under Israeli law and, where relevant, under the laws of other jurisdictions:
3.1 Providing and Operating the Service
We use your account information, GitHub token, Repository Content, and technical data to create and maintain your account, authenticate you, clone and analyze the repositories you connect, transmit code to our analysis engine to generate findings, produce and deliver Reports, manage your connected repositories and scan history, and deliver all other core features of the Attest platform. This processing is necessary for the performance of our contract with you.
3.2 Processing Transactions and Billing
We use your billing information and account details to activate purchases processed by Paddle, manage subscription renewals and cancellations, resolve payment disputes, and maintain financial records in compliance with applicable accounting and tax laws. Invoices and receipts for your purchases are issued by Paddle in its capacity as merchant of record. This processing is necessary for the performance of our contract with you and for compliance with legal obligations.
3.3 Communications
We use your email address to send you transactional and service communications, including account verification and password reset emails, subscription confirmations, invoices, and billing notifications, service announcements (maintenance windows, feature updates, incident notifications), and responses to your support inquiries. These communications are necessary for the operation of your account. With your consent where required by law, we may also send promotional communications about new features or plans; you may unsubscribe from marketing emails at any time.
3.4 Improving the Platform
We use aggregated and de-identified usage data, technical data, and performance metrics to analyze how users interact with the Service, identify areas for improvement, develop new features and capabilities, improve the accuracy of our analysis and framework mappings, and conduct internal research and quality assurance. Where we use your data for improvement purposes, we take steps to aggregate or anonymize it where practicable so that individual users are not identifiable in our analysis.
3.5 Security and Fraud Prevention
We use IP addresses, usage patterns, technical data, and account information to detect, investigate, and prevent unauthorized access, fraudulent activity, abuse of the platform, security incidents, and violations of our Terms of Service. We may also use this information to enforce plan limits and usage caps. This processing reflects our legitimate interests in protecting the integrity and security of the Service and our users.
3.6 Legal Compliance
We may process and retain your information as necessary to comply with applicable law, regulation, legal process, or governmental requests, including tax, accounting, and record-keeping obligations, and to respond to lawful requests from courts and law enforcement authorities.
4.How We Share Your Information
We do not sell, rent, or trade your personal information to third parties for their own marketing or commercial purposes. We share your information only in the limited circumstances described below.
4.1 Third-Party AI Subprocessor
Attest analyzes your Repository Content primarily with deterministic security scanners (such as Semgrep, gitleaks, osv-scanner, and checkov) that run within the Service and produce reproducible findings. For the subset of control clauses that no deterministic tool can evaluate, Attest transmits your Repository Content to a third-party AI model provider (currently Anthropic, PBC, maker of Claude) to produce an “AI-assessed” verdict; those verdicts are clearly labeled and kept separate from the deterministic findings. This transmission occurs only for the AI-assessed portion of the analysis. Under Anthropic’s commercial terms, your code is not used to train Anthropic’s general models. Specific provider terms are available upon request at support@agentsincorporated.ai.
By using the Service and connecting a repository, you acknowledge and consent to this transmission of your code to our AI subprocessor for the AI-assessed controls as part of normal platform operations. You are responsible for ensuring that any repository you connect does not include data that you are not authorized to share with a third-party processor.
4.2 Cloud Infrastructure Providers
Our platform is hosted on Amazon Web Services ("AWS") in the US-East-1 (Northern Virginia) region. AWS processes and stores your data on our behalf under a data processing agreement and its own security and compliance programs, including SOC 2 Type II, ISO 27001, and others. AWS does not have the right to use your data for any purpose other than providing hosting services to us.
4.3 Payment Processing (Merchant of Record)
Our order process is conducted by Paddle, our merchant of record. We share billing-related information with Paddle to facilitate checkout, payment processing, tax calculation, and subscription management. This includes your email address, billing name, billing country, and subscription plan details. Paddle processes this information as an independent controller subject to its own privacy policy and its certifications under applicable payment industry standards (PCI DSS).
4.4 Analytics Providers
We may use third-party analytics services to help us understand how users interact with the Service. These providers may receive certain technical data (such as anonymized usage events, session data, and device information) processed on our behalf. We require analytics providers to process data only for the purposes of providing their analytics services to us and not to share it with other parties or use it for their own advertising purposes.
4.5 Legal Requirements
We may disclose your information to courts, law enforcement agencies, government authorities, regulatory bodies, or other third parties if we reasonably believe that disclosure is required or permitted by applicable law, regulation, or legal process, including in response to a valid subpoena, court order, search warrant, or equivalent legal instrument. Where permitted by law, we will attempt to notify you of such requests before disclosing your information. We may also disclose information where we believe in good faith that it is necessary to protect the rights, property, or safety of the Company, our users, or the public.
4.6 Business Transfers
If Agents Incorporated is involved in a merger, acquisition, financing, corporate reorganization, sale of all or substantially all of its assets, bankruptcy, or similar transaction, your information may be transferred to the acquiring or successor entity as part of that transaction. We will notify you via email and/or a prominent notice within the Service before your personal information is transferred and becomes subject to a different privacy policy.
4.7 With Your Consent
We may share your information with third parties in circumstances not listed above when we have obtained your explicit, informed consent to do so.
4.8 No Sale of Personal Information
We do not sell your personal information to advertisers, data brokers, or any other third parties for their own commercial benefit. We do not use your personal information, Repository Content, or Reports for third-party advertising targeting.
5.Data Storage and Security
5.1 Storage Location
All user data — including account information, encrypted GitHub tokens, Reports, scan metadata, billing records, and usage logs — is stored on servers operated by Amazon Web Services in the US-East-1 (Northern Virginia) data center region. As described in Section 2.4, cloned repository source code is held only transiently for the duration of a scan and is not part of our persistent storage. By using the Service, you consent to the storage and processing of your data in the United States.
5.2 Encryption at Rest
Data stored on our servers, including Reports, GitHub tokens, database records, file storage, and backups, is encrypted at rest using AES-256 (Advanced Encryption Standard with a 256-bit key length), which is the current industry standard for symmetric encryption. Encryption keys are managed through AWS Key Management Service (KMS) with access strictly limited to authorized system processes.
5.3 Encryption in Transit
All data transmitted between your browser or client application and our servers, as well as data transmitted between our internal services, is protected using Transport Layer Security (TLS) version 1.2 or higher. We do not support legacy SSL or TLS 1.0/1.1 connections. HTTPS is enforced for all public endpoints of the Service.
5.4 Access Controls and Monitoring
Access to production systems and user data is restricted on a need-to-know basis to authorized Company personnel and contractors who require it to perform their job functions. Access is controlled through role-based permissions, multi-factor authentication, and audit logging. We maintain monitoring and alerting systems to detect anomalous access patterns, unauthorized changes, and potential security incidents. All access to user data by Company personnel is logged and subject to periodic review.
5.5 Limitations of Security
Despite our efforts to employ commercially reasonable and industry-standard security measures, no system can be guaranteed to be completely secure. The transmission of information over the Internet inherently involves risks, and we cannot warrant or guarantee the absolute security of your data. In the event of a data security incident that affects your personal information, we will notify you and applicable regulatory authorities as required by applicable law.
You share responsibility for security. We encourage you to use a strong, unique password for your account, enable any multi-factor authentication options we offer, promptly notify us if you suspect unauthorized access to your account, and avoid storing highly sensitive credentials or regulated data within the platform beyond what your project requires.
6.International Data Transfers
Agents Incorporated is incorporated in and operates from the State of Israel. Our infrastructure is hosted in the United States. If you are located outside of the United States or Israel, your use of the Service involves the cross-border transfer of your personal information to the United States, and potentially to other countries where our AI analysis provider or other sub-processors operate.
The United States and Israel may have data protection laws that differ from those of your home jurisdiction. By accessing or using the Service and submitting information to us, you acknowledge and consent to the transfer of your information to the United States and to Agents Incorporated's processing of that information in the United States as described in this Policy.
For users in jurisdictions that regulate international data transfers (such as the European Economic Area, Switzerland, or the United Kingdom), we rely on applicable legal transfer mechanisms, which may include Standard Contractual Clauses (SCCs) issued by the European Commission or equivalent mechanisms, data processing agreements incorporating appropriate safeguards, or other transfer tools recognized by applicable law. If you require information about the specific transfer mechanisms applicable to your jurisdiction, please contact us at support@agentsincorporated.ai.
Israel is recognized by the European Commission as providing an adequate level of data protection for personal data transferred from the European Economic Area. Transfers from Israeli systems to US-hosted infrastructure are subject to the contractual and technical safeguards described in this Policy.
7.Data Retention
We retain your personal information, Reports, and other account data for as long as necessary to fulfill the purposes for which it was collected, to operate your account, and to comply with our legal, regulatory, tax, and contractual obligations. The following retention periods apply:
7.1 Active Subscription
While your subscription is active, we retain your account information, connected repository metadata, Reports, findings, and associated scan data for the full duration of your subscription term. This data is necessary for us to provide you with uninterrupted access to your scan history and reports. As described in Section 2.4, the cloned repository source code itself is deleted immediately after each scan and is not retained.
7.2 Post-Cancellation Retention
Upon cancellation or expiration of your subscription, your Reports, findings, and associated scan data are retained in active storage for a period of thirty (30) days from the date of cancellation. This window allows you to reactivate your subscription and recover your data, or to export your data before it is deleted. After this 30-day window, your data is permanently deleted from active storage systems.
7.3 Backup Retention
Residual copies of your data may persist in encrypted backup archives for up to ninety (90) days following deletion from active storage. These backups are maintained solely for disaster recovery purposes and are subject to the same access controls and encryption as primary storage. After 90 days, backup copies are permanently destroyed.
7.4 Billing Records
Records of subscription payments, invoice history, and related financial transactions are retained for up to seven (7) years following the transaction date, in accordance with applicable tax and financial record-keeping laws in Israel and to support potential financial audits, dispute resolution, and legal compliance.
7.5 Usage Logs
Server access logs, security event logs, and operational audit logs are retained for up to two (2) years. These logs are used for security investigations, fraud detection, debugging, and performance analysis. After this period, logs are purged or irreversibly anonymized.
7.6 Exceptions
We may retain data beyond the periods described above if: (a) a legal hold, litigation, regulatory investigation, or law enforcement request requires it; (b) you have outstanding amounts owed or unresolved disputes; or (c) retention is otherwise required or permitted by applicable law. In such cases, we will retain only the data necessary for the specific retention purpose.
8.Your Rights
Depending on your location and applicable law, you may have certain rights with respect to your personal information. We honor these rights to the extent required or permitted by applicable law, including the Israeli Privacy Protection Law and, where applicable, the EU General Data Protection Regulation (GDPR) or equivalent national legislation. To exercise any of the rights described below, please contact us at support@agentsincorporated.ai.
8.1 Right of Access
You have the right to request confirmation of whether we process personal information about you, and if so, to receive a copy of that information along with details about how it is used and with whom it is shared. We will respond to verified access requests within a reasonable timeframe, generally within 30 days.
8.2 Right to Correction
You have the right to request that we correct or update any personal information we hold about you that is inaccurate, incomplete, or outdated. You may update certain account information (such as your name and email address) directly within your account settings. For corrections to other data, please contact our support team.
8.3 Right to Deletion
You have the right to request the deletion of your personal information and account. You may initiate account deletion by contacting support@agentsincorporated.ai. Upon verification of your request, we will initiate the deletion process described in Section 7. Please note that we may retain certain information where we have a legal basis to do so, such as billing records retained for tax compliance or data subject to a legal hold.
8.4 Right to Data Portability
You have the right to request an export of your Reports and account data in a structured, commonly used, machine-readable format. You may request a data export at any time prior to account deletion by contacting our support team. We will make reasonable efforts to fulfill export requests within 14 business days. Exports will include your Reports, findings, scan metadata, and account profile information to the extent technically feasible. Because cloned repository source code is not retained after a scan, it is not included in data exports.
8.5 Right to Object to Processing
Where we process your personal information based on legitimate interests (such as security monitoring or analytics), you have the right to object to that processing on grounds relating to your particular situation. If you object, we will consider your request and either cease the processing or demonstrate compelling legitimate grounds that override your interests. You may also opt out of marketing communications at any time by clicking "unsubscribe" in any marketing email or by contacting us directly.
8.6 Right to Restriction of Processing
In certain circumstances — for example, where you contest the accuracy of your data or have objected to processing pending our determination of legitimate grounds — you may have the right to request that we restrict our processing of your personal information to storage only while the matter is resolved.
8.7 How to Exercise Your Rights
To exercise any of the rights described above, please submit a written request to support@agentsincorporated.ai with sufficient information to verify your identity. We will not discriminate against you for exercising your rights under this Policy. Note that certain rights may be limited or subject to exceptions under Israeli law and other applicable legislation, including where the requested deletion or restriction would prevent us from fulfilling our legal obligations.
9.Children's Privacy
The Service is not intended for, directed at, or designed to be used by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and you believe that your child under the age of 18 has provided us with personal information without your consent, please contact us immediately at support@agentsincorporated.ai.
Upon receiving a verified notification that we have collected personal information from a child under 18, we will take prompt steps to delete that information from our systems. If we discover independently that we have inadvertently collected personal information from a child under 18, we will similarly delete it without delay. By using the Service, you represent and warrant that you are at least 18 years of age.
10.Third-Party Links and Services
The Service may contain links to third-party websites, integrations, or external services that are not owned or controlled by Agents Incorporated. These include links to documentation resources, third-party developer tools, and other external references. This Policy does not apply to any third-party websites, products, or services, even if they are accessible via links on our platform.
We have no control over, and assume no responsibility for, the content, privacy policies, data practices, or security of third-party sites or services. Visiting any third-party site is at your own risk, and we encourage you to review the privacy policy of any third-party site before providing them with personal information.
As noted in Sections 4.1 and 4.3, certain third parties — including our AI analysis provider and Paddle — process your data as a necessary component of the Service. These parties are bound by separate data processing agreements with us and their own privacy policies, which govern their handling of your data in their role as sub-processors or independent processors.
11.Local Storage and Session Management
The Attest application does not set or use cookies for authentication, session management, analytics, or any other purpose. No first-party or third-party tracking cookies are used by the application.
11.1 Browser localStorage
To maintain your authenticated session, the application stores the following data exclusively in your browser's localStorage — a browser-native storage mechanism that is local to your device and is not automatically transmitted to any server:
- An authentication token — A JSON Web Token (JWT) issued upon successful login. This token is included as a Bearer token in authenticated API requests and expires after a fixed period of inactivity.
- Cached profile data — Basic user profile data (such as your name and email) cached locally to avoid unnecessary API round-trips during your session.
This data is stored solely on your device and is only transmitted to our servers as part of authenticated API requests. It is never shared with third-party services for advertising or tracking purposes.
11.2 Infrastructure Cookies
While the Attest application itself does not set any cookies, certain cloud infrastructure components — such as AWS Elastic Load Balancers — may set short-lived technical cookies (for example, load balancer session affinity cookies) as part of routing requests to our backend services. These cookies are set by the underlying infrastructure, not by the application, contain no personal information, and are used solely for network routing purposes.
11.3 Managing localStorage Data
You can clear your localStorage data at any time through your browser's developer tools or by logging out of the Service, which removes both stored keys. Clearing this data will end your active session and require you to log in again. Because the application does not rely on cookies, standard browser cookie controls have no effect on the application's session behavior.
12.Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal obligations, or the features of the Service. When we make material changes to this Policy — meaning changes that meaningfully affect your rights or the way we handle your personal information — we will provide you with at least thirty (30) days' advance notice before the changes take effect.
Notice of material changes will be provided by one or more of the following methods: (a) an email to the address associated with your account; (b) a prominent notice displayed within the Service when you log in; or (c) an updated "Last updated" date at the top of this page. We recommend reviewing this page periodically even if you have not received a notification.
For minor or non-material changes — such as typographical corrections, clarifications to existing practices, or updates to contact information — we may update the Policy without advance notice, and such changes will be effective upon posting. The most current version of this Policy will always be available at agentsincorporated.ai/privacy.
Your continued use of the Service after the effective date of any updated Policy constitutes your acceptance of the revised Policy. If you do not agree to a material change, you may request deletion of your account and data before the change takes effect.
13.Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or our data practices — including requests to exercise your rights under Section 8, questions about international data transfers, or reports of suspected data security incidents — please contact us at:
We aim to respond to all privacy-related inquiries and rights requests within 3 business days. For urgent matters such as data breach notifications or suspected unauthorized access to your account, please include "URGENT" in your subject line so we can prioritize your request.
If you are not satisfied with our response to your inquiry, and you are located in a jurisdiction with a data protection supervisory authority, you may have the right to lodge a complaint with the relevant authority. In Israel, the relevant authority is the Israeli Privacy Protection Authority (PPA).
© 2026 Agents Incorporated. All rights reserved.
Back to Home