Privacy
Focused AI governance. Minimal data collection.
Certaic is designed to process the information needed to discover and govern supported AI applications without becoming a general employee browsing-history product.
What Certaic processes
Depending on product configuration and supported capabilities, Certaic may process organization and enrollment identity, supported AI application identity, timestamps, governance decisions, enforcement outcomes, browser or extension health/version, and employee-entered justification when a policy requires one.
Supported-AI browsing activity
The browser extension processes limited browsing activity associated with supported AI applications solely to provide enterprise AI discovery, governance, enforcement, and evidence. It is not designed to collect general-purpose employee browsing history.
What Certaic does not routinely retain
- AI prompt text
- AI response content
- arbitrary webpage content
- uploaded file contents
- clipboard contents
- screenshots
- passwords, cookies, or authentication tokens as ordinary telemetry
Justifications
If an organization requires justification, the employee-entered justification is stored as governance evidence and should be treated as sensitive customer data. Access is limited to authorized customer roles.
Customer data
Customer governance, telemetry, identity, justification, and evidence data are processed to provide and operate the Certaic service. Customer data is not intended to be used to train shared or general-purpose AI models.
Retention and deletion
Retention periods and customer offboarding procedures are documented according to the applicable pilot or production terms. Active customer data can be removed through the approved tenant offboarding process, while backups expire according to the backup-retention policy.
Talk to Certaic