Legal
Privacy Policy
Last updated — 2026-07-26
01Overview
Felswerk is committed to protecting your privacy. This policy describes what data we collect, how we use it, and your rights regarding that data.
02Data we collect
| Data type | Purpose | Retention |
|---|---|---|
| Email address (via SSO) | Authentication and account identification | Duration of account |
| Organization name | Multi-tenant data isolation | Duration of account |
| Uploaded reports | Knowledge extraction, framework mapping, enrichment | Configurable (default: retained) |
| Generated findings and analytics | Trend analysis, dashboards, reporting | Configurable via data retention policy |
| Usage logs | Platform reliability and rate limiting | 90 days |
| Audit logs | Security compliance and accountability | Retained for compliance (default: 7 years) |
03How report data is processed
Understanding exactly what happens to your uploaded reports is critical. Here is the complete data flow:
| Step | Where it runs | What happens |
|---|---|---|
| 1. Text extraction | Our servers (local) | PDF text is extracted locally. No external API is called. |
| 2. Technique identification | Google Gemini API | Extracted text is sent to Google Gemini to identify ATT&CK techniques and validate findings. Semantic-search embeddings are also generated via the Gemini API. Google Gemini is the only external AI service used in this pipeline. |
| 3. Enrichment and analysis | Our servers (local) | Compliance mapping, risk scoring, enrichment cross-referencing, and analytics run locally using deterministic SQL and Python calculations. |
| 4. Storage | Our database | Results are stored in our PostgreSQL database, where every record is keyed to your organization and all access is scoped to it. |
Beyond report processing, optional AI-assisted features — such as natural-language query, generated briefs, and drafting tools — send the relevant content to Google Gemini when you use them.
Important: content sent to Google Gemini is processed under the data-handling terms and configuration applicable to Felswerk’s Google Cloud account. Felswerk does not use your content to train its own models. For organizations requiring fully air-gapped processing, contact us about self-hosted deployment options.
04General data usage
- Enrichment. Findings are cross-referenced against public threat-intelligence sources (MITRE ATT&CK, CISA KEV, Elastic Rules, LOLDrivers, and others) — all enrichment data stays on our servers.
- Analytics. Analytics engines compute results deterministically from your data using SQL aggregation. No AI or LLM is used for analytics.
- No selling. We never sell your data to third parties.
- No training. Felswerk does not use your content to train AI or machine-learning models.
- Cross-customer aggregates. If your organization participates in Collective Intelligence (enabled by default; administrators can opt out at any time in the platform), de-identified ATT&CK-technique statistics — never report content, finding text, asset data, or organization identifiers — contribute to aggregate insights. Aggregates are released only for cohorts of at least five contributing organizations, with statistical noise applied to every released count; below-threshold signals are suppressed entirely.
05Data isolation and security
- All data is logically isolated by organization: every record carries your organization’s identifier, and the application enforces that scoping on every query.
- Data is encrypted in transit using HTTPS/TLS and at rest using the encryption mechanisms provided by Google Cloud.
- Infrastructure runs on Google Cloud services covered by Google Cloud’s compliance programs and certifications. These provider certifications do not independently constitute certification of Felswerk.
- Access is controlled via single sign-on with role-based permissions (admin, user, viewer).
06Third-party services
- Google Cloud Platform — hosting, database, authentication
- Google Gemini — AI-powered report analysis
- Stripe — payment processing (we do not store credit card numbers)
- Firebase Hosting — static frontend delivery
Each third-party provider maintains its own privacy policies and security certifications.
07Retention and deletion
- You may configure data retention policies via the platform’s admin settings.
- You may request full data export or deletion by contacting hello@felswerk.com.
- Upon a verified deletion request, we delete your organization’s content from production systems within 30 days. Audit records and encrypted backups may persist for a limited additional period for compliance and disaster-recovery purposes before being purged on their own schedules.
09Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Object to specific processing activities
10Changes to this policy
We may update this policy periodically. We will notify you of material changes via email or an in-app notification.
11Contact
For privacy questions or data requests, contact us at hello@felswerk.com.