Privacy Policy
Contents
1. Overview
Also Known As, Inc. (“AKA Security”, “we”, “our”) builds AI Traffic Control (AI-TC), an open-source security engine for AI agents, and operates the website at akasecurity.io. This policy describes the personal information we collect, how we use it, and the choices you have. It applies to visitors to our website, prospects who contact us, and customers under a commercial engagement.
The short version: AI-TC runs on your own machine. The prompts and tool calls your agents make never travel to us. The information we do collect is what you give us when you contact us or sign a commercial agreement, plus standard website analytics. We do not sell it.
2. How AI-TC handles your data
AI-TC is the open-source security engine we publish on GitHub. It runs on the same machine where your AI agent runs. Every prompt and tool call your agent makes is scanned against its detection rules locally, and the warn, redact, or block decision is made on your machine.
In the default local deployment, we do not receive your prompts, your tool calls, your findings, or any other runtime data from AI-TC. There is no telemetry pipe back to AKA Security. AI-TC contains no phone-home. Findings stay in a local store on your machine.
If you build AI-TC from source, you can read the code on GitHub and confirm the detection path makes no network calls of its own.
For Enterprise deployments, AKA offers a hosted control plane: rule distribution and fleet reporting run on AKA-managed infrastructure under a separate agreement. Detection and enforcement still run on your machines. Fleet reporting carries finding counts, categories, and severities, never the underlying values, prompts, or payloads. This is separate from our managed-services engagements, where AKA operates AI-TC inside your own environment.
3. What we collect
We collect personal information in three places: visits to our website, requests to contact us, and active commercial engagements. The table below describes each.
| Who | What we collect | Why |
|---|---|---|
| Website visitors | Pages visited, referrer, browser type, IP address (truncated), country. | To understand what the site is used for and improve it. |
| Prospects (you contact us) | Name, work email, organization name, and any message you send. | To reply to your inquiry and, if you ask, schedule a meeting. |
| Customers (signed agreement) | Names and contact details of the people working with us, and any information you share with us in the course of an engagement. | To deliver the agreed work and meet our legal obligations. |
| Job candidates | Resume, application materials, and anything you tell us in interviews. | To evaluate your application. |
4. What we do not collect
To be explicit, AKA Security does not collect:
- Prompts and tool calls made by your agents through AI-TC.
- The rules or configuration you set for AI-TC.
- The findings AI-TC records on your machine.
- Source code, prompts, secrets, or any other content read or written by your agents.
- Behavioral profiles, advertising identifiers, or cross-site tracking.
5. How we use information
We use the information we collect to:
- Respond to inquiries and schedule meetings.
- Deliver and support commercial engagements.
- Improve our website and product.
- Send occasional product or company updates, which you can unsubscribe from at any time.
- Comply with applicable legal obligations.
6. Sharing
We do not sell, rent, or trade your personal information. We share information with a limited set of service providers we use to run the business (for example, our email host, the contact-form provider, and our analytics provider), and only what each provider needs to do its job. These providers are bound by written confidentiality and data-handling obligations.
We may also disclose information if required by law, to enforce our rights, or in connection with a corporate transaction (such as a merger, acquisition, or sale of assets). The acquirer would be bound by this policy.
7. Security and retention
AKA Security is SOC 2 Type II certified and ISO 27001 certified. We maintain technical and organizational controls aligned to those programs, including least-privilege access, encryption of data in transit and at rest, and logging of administrative actions.
We retain personal information for as long as it is needed for the purpose it was collected, then delete or anonymize it. Inquiries that do not lead to a customer relationship are retained for up to 24 months. Customer records are retained for the duration of the engagement and for the period required by tax, accounting, and contractual obligations.
8. Your rights
Depending on your location, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain uses. To exercise any of these rights, write to [email protected]. We will respond within the timeframe required by applicable law.
If you are in the European Economic Area, the United Kingdom, or Switzerland, the legal bases on which we process your information are: your consent, the performance of a contract with you, compliance with a legal obligation, and our legitimate interests in operating and improving the business.
9. Changes and contact
We may update this policy from time to time. When we do, we update the “Last updated” date at the top of the page. Material changes will be flagged on this page or sent to active customers by email.
Questions, requests, or complaints about this policy go to [email protected] or through our contact form.