Privacy Policy
Effective: June 14, 2026
Cabreza, Inc. ("Cabreza," "we," "us") provides a critical-infrastructure-protection platform for business customers. This Privacy Policy explains how we collect, use, share, and protect personal data when you use our websites and the Cabreza platform (the "Services"). Capitalized terms not defined here have the meaning in our Terms of Service.
This policy covers personal data of: (1) account users — people at our business customers who use the Services; (2) website visitors and prospects; and (3) third-party individuals whose information appears in our intelligence data (see Section 7). Where we process customer data on a business customer's behalf, the customer is the controller and our Data Processing Addendum governs.
1. Information We Collect
You provide:
- Account and contact data — name, work email, company, and job title when you register, request a demo, or contact us. Account identity is managed in AWS Cognito; we require a work email and do not accept personal webmail accounts.
- Customer Content — data you submit or create in the Services, including your Digital Twin (your private inventory of your own sites, technology and OT assets, personnel, suppliers, and security posture), uploaded documents, and documents you generate. This may include sensitive operational-technology and security information.
- Billing data — handled by our payment processor. We store subscription and reference identifiers only; we do not store full payment-card numbers.
- Communications — messages you send us and to the in-product assistant.
Collected automatically:
- Technical and product-usage data — IP address, browser and device type, pages viewed, features and in-product actions used, and diagnostic data. Our own product analytics is first-party: we collect it, it stays within our own infrastructure, and we use it only to secure, operate, and improve the Services. We do not use advertising trackers or advertising cookies, we do not use any of this data for advertising, and we do not sell or share it. We automatically honor your browser's Global Privacy Control (GPC) signal, which turns off both this and the session analytics described below.
- Session analytics and replay — in the signed-in application we use Microsoft Clarity to understand how pages are actually used, through click and scroll heatmaps and session replays. Clarity runs in strict masking mode: text, form inputs, and media are masked in your browser before anything is sent, so your Customer Content is not captured. It sets its own cookies to recognize a returning session, runs only on our production application, and is disabled entirely by the GPC signal.
- Error and performance monitoring — we use Sentry to capture errors and performance data. When an error occurs, Sentry may record a short replay of the affected session to help us reproduce it; these replays mask text, form inputs, and media so your content is not captured.
- Authentication telemetry — sign-in and multi-factor events recorded by our identity provider for security.
See Section 9 for cookies.
2. How We Use Information
- Provide, operate, secure, maintain, and improve the Services.
- Authenticate users and manage Accounts, seats, and entitlements.
- Process subscriptions, Credits, and payments.
- Power AI features (Section 4).
- Provide support, respond to requests, and send service, security, and administrative messages.
- Monitor, investigate, and prevent fraud, abuse, security incidents, and violations of our terms.
- Generate aggregated, de-identified analytics and benchmarks (Section 8).
- Comply with law and enforce our agreements.
We may send product and marketing communications to business contacts; you can opt out at any time.
3. How We Share Information
We do not sell personal data. We share it:
- With sub-processors and service providers that help us run the Services, under contract and confidentiality obligations. Our current sub-processors are listed in the Sub-processor List (part of the Data Processing Addendum) and include AWS (hosting, storage, identity, email, and AI via AWS Bedrock), Anthropic and Amazon foundation models (accessed only through AWS Bedrock), Chargebee (billing), Sentry (error and performance monitoring), Microsoft (Clarity session analytics and replay), and Serper and Tavily (web-search providers used for intelligence research). Where you enable enterprise single sign-on, Scalekit processes authentication data.
- Within the shared intelligence corpus — see Section 7. Intelligence we compile about an organization may be visible to other customers monitoring that organization. This does not include your private Customer Content.
- For legal reasons — to comply with law, legal process, or enforceable government requests, or to protect rights, safety, security, or property.
- In a business transfer — in connection with a merger, acquisition, financing, or sale of assets.
- With your direction or consent — including when you connect the Services to third-party tools via our API.
4. AI Processing and Sub-Processors
Certain features use third-party foundation models accessed exclusively through AWS Bedrock. To deliver these features, we send relevant inputs — which can include your Customer Content (Digital Twin data, uploaded document text, assistant messages) and Platform Intelligence — to AWS Bedrock for inference only.
We do not use your Customer Content to train foundation models, and our AI sub-processor processes inputs to return results to us and does not use your inputs to train its own models. Foundation models in use today include Anthropic Claude and Amazon Nova, all via AWS Bedrock; the specific models may change.
5. Staff Access and Support
To operate and support the Services, authorized Cabreza personnel may access Account data and may temporarily act within an Account on the customer's behalf to diagnose issues, fulfill support or provisioning requests, ensure billing accuracy, and protect security. This access is limited to authorized staff, restricted in time, used only for legitimate operational purposes, and recorded in an internal audit log. We may also view authentication and security events (such as sign-in and multi-factor history) for security and support.
6. Data Retention and Deletion
- We retain personal data and Customer Content for as long as your Account is active and as needed to provide the Services, then for a limited period as required for legal, security, billing, or audit purposes.
- Account deletion. When you delete your organization, we soft-delete it immediately and remove access, then permanently purge the organization's stored data after a recovery window of approximately 30 days, including the organization's private data store and its backups, uploaded files, and generated documents. Where a user has no remaining organization, the user's login identity is removed as part of this process.
- Records we retain. Certain records may persist after deletion for legitimate purposes, including billing and tax records, security and audit logs, and de-identified aggregate data. Shared Platform Intelligence (Section 7) is not Customer Content and is not deleted when an Account is deleted.
7. Intelligence About Organizations and Individuals (Including Non-Customers)
A core function of the Services is compiling cybersecurity intelligence about organizations — including organizations that are not Cabreza customers ("targets") — and the individuals publicly associated with them.
- Sources. We collect only from publicly accessible and licensed sources: public web pages, search providers, regulatory and public registries (such as SEC EDGAR, EPA, EIA, SDWIS, OSHA, PHMSA, NRC, and FEMA), certificate-transparency logs, public code repositories, vulnerability and advisory feeds (such as CISA, NVD, and GHSA), and similar. We do not attempt to bypass authentication or access controls.
- Third-party personal data. This intelligence can include the names, job titles, professional roles, public profile links, and work locations of executives and security or operational personnel at target organizations, compiled to describe an organization's public profile and security-relevant exposure. We do not seek special-category personal data.
- Leaked-credential detection. We detect references to potentially exposed credentials in public sources and store only a non-reversible fingerprint and a source reference — never the live credential.
- Legal basis. Where data-protection law applies, we rely on our legitimate interests (providing cybersecurity and risk intelligence to our customers) for processing third-party personal data from public sources, balanced against the rights of the individuals concerned.
- Your rights as a data subject. Individuals and organizations may request review, correction, objection, or — where applicable law requires — erasure of intelligence about them. As described in the Intelligence Sourcing & Takedown Policy, our default for public-source information is to provide the source citation and direct you to the original source; we correct inaccuracies and honor legally required erasure or objection. Contact intelligence@cabreza.com.
8. Aggregated and De-Identified Data
We create aggregated, de-identified statistics and benchmarks from use of the Services (for example, anonymized "organizations like you" cohort signals). This data is stripped of identifiers, enforces a minimum cohort size, excludes an organization from its own benchmark, and does not identify or attribute data to any named organization. We take reasonable measures to prevent re-identification of de-identified data. We may use and retain this data without the restrictions that apply to personal data.
9. Cookies
Most of the cookies we use are strictly necessary for the Services to function, such as keeping you signed in and remembering your selected workspace, and we use Sentry for error and performance monitoring. Our first-party product-usage analytics (Section 1) uses your browser's local storage rather than cookies. Microsoft Clarity, which provides the session analytics and replay described in Section 1, does set its own cookies to recognize a returning session. We honor the Global Privacy Control signal for both. We do not use advertising cookies. Where required by law, we will provide cookie controls. You can also manage cookies and site storage through your browser.
10. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls, per-organization data isolation, and audit logging. No method of transmission or storage is fully secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach, we will act as required by applicable law. Where Cabreza processes personal data as a processor on a customer's behalf, we will notify the customer (the controller) without undue delay so the customer can fulfill its own regulatory notification obligations; the customer is responsible for notifying the relevant authority. Where Cabreza is the independent controller — for example, for our own website visitors or the intelligence corpus — we will notify you and notify the relevant authorities directly as required by law.
11. International Data Transfers
The Services are hosted in the United States (AWS, us-east-1). If you access the Services from outside the United States, you understand your data will be transferred to and processed in the United States. Where required, we provide an appropriate transfer mechanism (such as Standard Contractual Clauses) in our Data Processing Addendum. Data-residency options may be available to Enterprise customers.
12. Your Privacy Rights
Depending on your jurisdiction (including under the GDPR and UK GDPR and U.S. state laws such as the CCPA/CPRA), you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. You can export your organization's data through the Services, and you can delete your organization as described in Section 6. To exercise other rights, contact privacy@cabreza.com. We will respond as required by law and will not discriminate against you for exercising your rights.
California: we do not sell or "share" (for cross-context advertising) personal data. Authentication and certain security telemetry are collected for security purposes.
13. Children's Privacy
The Services are for business use and are not directed to individuals under 16. We do not knowingly collect personal data from children.
14. Changes and Contact
We may update this Privacy Policy; we will post the revised version, update the "Effective" date, and provide additional notice where required. Contact: privacy@cabreza.com — Cabreza, Inc., 18 Manassas Dr, Middletown, Delaware 19709, US.