Draft for review. This text is not yet in effect.
Who we are
Overwatch Console is operated by [Company legal name] ("we"). For privacy questions, write to [privacy contact email].
For the security data your organization connects, your organization is the controller and we process it on your behalf to provide the service.
What we store
Account data: name, email address, role, a salted password hash, sign-in times and failed sign-in counts used to stop password guessing.
Security data you connect: Microsoft Sentinel incidents, alerts, entities and the results of queries the agents run in your workspace, plus the agents' notes, verdicts and approval records.
Connection settings: Azure tenant, subscription and workspace identifiers and the service principal credentials you provide. Credentials are encrypted at rest and never shown back in full.
Usage data: an audit log of agent and user actions, and model token counts per agent and day.
Who processes it
Railway hosts the application and its PostgreSQL database.
Model calls go through OpenRouter to the model providers it routes to (currently Google and Anthropic). Incident details and query results are sent in those calls so the agents can analyze them.
Resend delivers account emails such as invitations and password resets.
Microsoft Azure is reached with your own credentials to read your Sentinel workspace and, only after a person approves it, to change it.
We do not sell personal data or use your security data to train models.
How long we keep it
Your data stays while your organization uses the service. Administrators can delete agent and audit logs older than 30 days. Token usage records are kept for 90 days.
Demo session data is deleted 24 hours after demo access ends. When an organization leaves, its data is deleted within [number] days unless the law requires us to keep it.
Your choices
Users can ask their organization's administrator, or us, to access, correct or delete their personal data. We answer within 30 days.
Organizations can export their records and ask us to delete them when they leave.
Security
Each organization's data is kept separate. Sign-in is rate limited, credentials are encrypted, and consequential changes to your Sentinel workspace need a person's approval unless an administrator turns on auto mode for that action.