Privacy Policy
Last updated: September 5, 2026
1. Who we are
Orithos is a product of Antanox, based in India ("we", "our", "us"). Antanox is the data controller for account and billing information described in this policy. When you use Orithos to scan AI agents on behalf of your organisation, your organisation is the controller of any personal data contained in agent configurations and scan traffic, and Antanox acts as a data processor under our Data Processing Agreement.
Contact our data protection point of contact at [email protected]. General privacy questions: [email protected].
2. Information we collect
2.1 Account information. When you create an account, we collect your email address and authentication credentials. If you sign in via GitHub or Google OAuth, we receive the email address associated with that account — nothing else from your OAuth profile.
2.2 Agent configurations. When you register an agent for scanning, we store what you provide: the agent name, endpoint URL, system prompt, tool schemas, RAG source configurations, and guardrail policies. These configurations may contain personal data (for example, names or identifiers embedded in a system prompt). You are responsible for ensuring you have a lawful basis to provide this data to us.
2.3 Scan traffic and findings. During a scan we send probe payloads to your agent endpoint and record your agent's responses (traces), the judge pipeline's verdicts, and the resulting findings with evidence. Probe payloads and agent responses are retained only for your plan's retention window (see Section 4) unless you enable Zero-Knowledge mode, in which traces are never persisted at all.
2.4 Billing information. Payments are processed by Dodo Payments. We receive transaction records (plan, amounts, credit balances) but never see or store your payment card details.
2.5 Product analytics. We collect pseudonymised product usage events (feature use, scan volumes, API request counts) through PostHog, keyed to a random identifier — not to your name. We use this solely to operate and improve the service.
2.6 Error reports. Crash and error diagnostics are collected through Sentry with personal identifiers stripped where possible.
2.7 Cookies. We use strictly necessary cookies only: encrypted session cookies for authentication (HttpOnly, never accessible to page scripts). We do not use advertising cookies, cross-site trackers, or browser-based analytics beacons — product analytics runs server-side (see 2.5). You can clear session cookies through your browser at any time; you will simply be signed out.
2.8 Correspondence. Emails you send to [email protected], [email protected], or our legal addresses, and waitlist signups (email address only), are retained to handle your request.
3. Lawful bases and purposes
Where the EU/UK GDPR applies, we process personal data on these bases (India's DPDP Act 2023: consent and legitimate uses; other regions: the equivalent applicable ground):
- Contract — providing scans, findings, evidence packs, and support you request.
- Legitimate interests — securing and improving the platform, preventing abuse, pseudonymised analytics. We balance these against your rights and offer objection (Section 7).
- Consent — OAuth sign-in, waitlist and marketing emails (withdrawable at any time).
- Legal obligation — tax records, responses to lawful orders.
We never use your agent configurations, prompts, or scan traffic to train machine-learning models — ours or anyone else's.
4. Data retention
Scan data is retained per plan, then automatically exported to you and purged:
- Free — 14 days
- Starter — 90 days
- Team, Business, Enterprise — 365 days (Business and above may set a custom window)
- Zero-Knowledge mode — probe payloads and agent responses are never stored
Account information is kept until you delete your account; terminated-account data is deleted within 30 days unless law requires longer. Billing records are kept as tax law requires. Analytics are kept in pseudonymised form only. Full detail: Data Retention docs.
5. Sharing and subprocessors
We do not sell personal information and never share it for cross-context behavioural advertising. We disclose data only to the subprocessors needed to run the service, each bound by contract:
- Infrastructure hosting — dedicated virtual private servers in the European Union (application, database, cache).
- Dodo Payments — subscription and credit-pack billing.
- LLM evaluation gateway — probe payloads and agent responses are evaluated by judge models (default: DeepSeek via our inference gateway) to produce verdicts. Payloads are sent for evaluation only, with sampling temperature fixed at 0, and are not used for model training.
- PostHog — pseudonymised product analytics.
- Resend — transactional email (scan reports, retention exports, notices).
- Sentry — error diagnostics.
- GitHub / Google — OAuth sign-in (email only).
We will notify customers of material subprocessor changes at least 30 days in advance. We may disclose information where required by law, to enforce our terms, or to protect the security of the service — and where lawful to do so, we will notify you first.
6. International transfers
Antanox is based in India and hosts service data in the EU. Some subprocessors process data in the United States. Where GDPR/UK GDPR applies, transfers outside the EEA/UK rely on an adequacy decision or the EU Standard Contractual Clauses (2021/914) plus the UK Addendum, with transfer risk assessments. India DPDP transfer rules and other applicable regimes are observed for their territories.
7. Your rights
Depending on your jurisdiction (GDPR, UK GDPR, India DPDP Act, CCPA/CPRA and others), you may have the right to:
- Access, correct, or delete your personal data
- Object to or restrict processing based on legitimate interests
- Data portability (receive your data in a usable format)
- Withdraw consent at any time (withdrawal does not affect prior lawful processing)
- Nominate another person to exercise rights on death/incapacity (India DPDP Act)
- Lodge a complaint with your supervisory authority
Exercise rights via [email protected] or [email protected]. We verify identity proportionately and respond within one month (sooner where your law requires). California residents: we do not sell or share personal information as defined by the CCPA/CPRA.
8. Security
Defense in depth: TLS 1.3 in transit; AES-256 encryption at rest; bcrypt-hashed API keys; Fernet-encrypted agent credentials; per-organisation data isolation; role-based access control; immutable audit logging; per-route rate limiting. No method of electronic storage is completely secure, so we cannot guarantee absolute security — but we treat a vulnerability in our own platform as a highest-priority incident. Report issues to [email protected].
9. Children
Orithos is a business security product and is not directed at children. You must be at least 18 years old (or the age of majority where you live) to use it. We do not knowingly collect children's data; contact us and we will delete any we discover.
10. Changes to this policy
Material changes are notified by email or in-product notice at least 14 days before taking effect. Continued use after the effective date constitutes acceptance. Previous versions are available on request.
11. Contact and complaints
Privacy questions: [email protected]. Data protection: [email protected]. You also have the right to complain to your supervisory authority (for example, the ICO in the UK, your EU member-state authority, or the Data Protection Board of India).