Privacy Policy

Effective: August 14, 2026

Cabreza, Inc. ("Cabreza," "we," "us") provides a critical-infrastructure-protection platform for business customers. This Privacy Policy explains how we collect, use, share, and protect personal data when you use our websites and the Cabreza platform (the "Services"). Capitalized terms not defined here have the meaning in our Terms of Service.

This policy covers personal data of: (1) account users — people at our business customers who use the Services; (2) website visitors and prospects; and (3) third-party individuals whose information appears in our intelligence data (see Section 7). Where we process customer data on a business customer's behalf, the customer is the controller and Cabreza is the processor. We make a data processing addendum available on request at privacy@cabreza.com.


1. Information We Collect

You provide:

  • Account and contact data — name, work email, company, and job title when you register, request a demo, or contact us. Account identity is managed in AWS Cognito. Registration asks for the email address you use for work, and we may restrict some features to a verified organizational domain.
  • Customer Content — data you submit or create in the Services, including your Context (your private inventory of your own sites, technology and OT assets, personnel, suppliers, and security posture), uploaded documents, and documents you generate. This may include sensitive operational-technology and security information.
  • Billing data — handled by our payment processor. We store subscription and reference identifiers only; we do not store full payment-card numbers.
  • Communications — messages you send us and to the in-product assistant.

Collected automatically:

  • Technical and product-usage data — IP address, browser and device type, pages viewed, features and in-product actions used, and diagnostic data. Inside the signed-in application our product analytics is first-party: we collect it, it stays within our own infrastructure, and we use it only to secure, operate, and improve the Services.
  • Marketing-website analytics — on our public website (cabreza.com) we use Google Analytics 4, delivered through Google Tag Manager, to measure page views and navigation, and Apollo.io, Digital Pilot, and Warmly to identify the companies that visit us so our team can follow up on business interest. These are third-party providers and are listed in Section 3. Advertising storage is switched off for every visitor: we do not run advertising, we do not use advertising cookies, we do not use any of this data for advertising, and we do not sell or share it. These providers run only on the public website, never inside the signed-in application, and they never receive Customer Content.
  • Session analytics and replay — we use Microsoft Clarity to understand how pages are actually used, through click and scroll heatmaps and session replays. Clarity runs on both the public website and the signed-in application. In the application it runs in strict masking mode: text, form inputs, and media are masked in your browser before anything is sent, so your Customer Content is not captured. It sets its own cookies to recognize a returning session.
  • Your browser-level opt-out. We automatically honor your browser's Global Privacy Control (GPC) signal. When your browser sends GPC we load no website analytics, no company-identification providers, and no session analytics or replay, and we set no advertising, analytics, or measurement storage.
  • Error and performance monitoring — we use Sentry to capture errors and performance data. When an error occurs, Sentry may record a short replay of the affected session to help us reproduce it; these replays mask text, form inputs, and media so your content is not captured.
  • Authentication telemetry — sign-in and multi-factor events recorded by our identity provider for security.
  • Plugin requests — when someone uses the Cabreza plugin in Claude or ChatGPT without signing in, we receive the request and any answers they give to Cabreza's questions, together with technical data about the request. We do not receive a name or an email address for that person.

See Section 9 for cookies.


2. How We Use Information

  • Provide, operate, secure, maintain, and improve the Services.
  • Authenticate users and manage Accounts, seats, and entitlements.
  • Process subscriptions, Credits, and payments.
  • Power AI features (Section 4).
  • Provide support, respond to requests, and send service, security, and administrative messages.
  • Monitor, investigate, and prevent fraud, abuse, security incidents, and violations of our terms.
  • Generate aggregated, de-identified analytics and benchmarks (Section 8).
  • Comply with law and enforce our agreements.

We may send product and marketing communications to business contacts; you can opt out at any time.


3. How We Share Information

We do not sell personal data. We share it:

  • With sub-processors and service providers that help us run the Services, under contract and confidentiality obligations. The full list is in Section 3.1 below.
  • Within the shared intelligence corpus — see Section 7. Intelligence we compile about an organization may be visible to other customers monitoring that organization. This does not include your private Customer Content.
  • For legal reasons — to comply with law, legal process, or enforceable government requests, or to protect rights, safety, security, or property.
  • In a business transfer — in connection with a merger, acquisition, financing, or sale of assets.
  • With your direction or consent — including when you connect the Services to third-party tools via our API. This includes the Cabreza plugin for Claude and ChatGPT. When you use it, our answers travel to Anthropic or OpenAI as the operator of the window you are working in, under their own privacy policy.

3.1 Sub-processor List

"Platform" means the signed-in Cabreza application. "Website" means our public website at cabreza.com. "Redaction Studio site" means our free browser tool at redact.cabreza.com, which never uploads your documents anywhere.

Sub-processorWhat it doesWhere it runs
AWSHosting, storage, identity, email, and AI via AWS BedrockPlatform and website
Anthropic and Amazon foundation modelsAI inference, accessed only through AWS BedrockPlatform
ChargebeeBilling and subscription managementPlatform
SentryError and performance monitoringPlatform and website
MicrosoftClarity session analytics and replayPlatform and website
GoogleAnalytics 4 and Tag Manager, website measurementWebsite only
Apollo.ioIdentifies the company a business visitor works forWebsite only
Digital PilotIdentifies the company a business visitor works forWebsite only
WarmlyIdentifies the company a business visitor works for and provides on-site chatWebsite only
Serper and TavilyWeb-search providers used for intelligence researchPlatform
ScalekitEnterprise single sign-on, where you enable itPlatform
U.S. Census Bureau geocoder and OpenStreetMap NominatimTurns a site address into map coordinates so your sites appear on the map. They receive the address only, never the organization it belongs to.Platform
HubSpotContact and enquiry managementRedaction Studio site only
FormSubmitDelivers contact-form messages to usRedaction Studio site only
Hugging FaceServes the redaction model your browser downloads once. It receives the model request only, never your document.Redaction Studio site only

We will update this table before we add a new sub-processor. To receive advance notice of changes, contact privacy@cabreza.com.


4. AI Processing and Sub-Processors

Certain features use third-party foundation models accessed exclusively through AWS Bedrock. To deliver these features, we send relevant inputs — which can include your Customer Content (Context data, uploaded document text, assistant messages) and Platform Intelligence — to AWS Bedrock for inference only.

We do not use your Customer Content to train foundation models, and our AI sub-processor processes inputs to return results to us and does not use your inputs to train its own models. Foundation models in use today include Anthropic Claude and Amazon Nova, all via AWS Bedrock; the specific models may change.


5. Staff Access and Support

To operate and support the Services, authorized Cabreza personnel may access Account data and may temporarily act within an Account on the customer's behalf to diagnose issues, fulfill support or provisioning requests, ensure billing accuracy, and protect security. This access is limited to authorized staff, restricted in time, used only for legitimate operational purposes, and recorded in an internal audit log. We may also view authentication and security events (such as sign-in and multi-factor history) for security and support.


6. Data Retention and Deletion

  • We retain personal data and Customer Content for as long as your Account is active and as needed to provide the Services, then for a limited period as required for legal, security, billing, or audit purposes.
  • Account deletion. When you delete your organization, we soft-delete it immediately and remove access, then permanently purge the organization's stored data after a recovery window of approximately 30 days, including the organization's private data store and its backups, uploaded files, and generated documents. Where a user has no remaining organization, the user's login identity is removed as part of this process.
  • Records we retain. Certain records may persist after deletion for legitimate purposes, including billing and tax records, security and audit logs, and de-identified aggregate data. Shared Platform Intelligence (Section 7) is not Customer Content and is not deleted when an Account is deleted.

7. Intelligence About Organizations and Individuals (Including Non-Customers)

A core function of the Services is compiling cybersecurity intelligence about organizations — including organizations that are not Cabreza customers ("targets") — and the individuals publicly associated with them.

  • Sources. We collect only from publicly accessible and licensed sources: public web pages, search providers, regulatory and public registries (such as SEC EDGAR, EPA, EIA, SDWIS, OSHA, PHMSA, NRC, and FEMA), certificate-transparency logs, public code repositories, vulnerability and advisory feeds (such as CISA, NVD, and GHSA), and similar. We do not attempt to bypass authentication or access controls.
  • Third-party personal data. This intelligence can include the names, job titles, professional roles, public profile links, and work locations of executives and security or operational personnel at target organizations, compiled to describe an organization's public profile and security-relevant exposure. We do not seek special-category personal data.
  • Leaked-credential detection. We detect references to potentially exposed credentials in public sources and store only a non-reversible fingerprint and a source reference — never the live credential.
  • Legal basis. Where data-protection law applies, we rely on our legitimate interests (providing cybersecurity and risk intelligence to our customers) for processing third-party personal data from public sources, balanced against the rights of the individuals concerned.
  • Your rights as a data subject. Individuals and organizations may request review, correction, objection, or — where applicable law requires — erasure of intelligence about them. Our default for public-source information is to provide the source citation and direct you to the original source; we correct inaccuracies and honor legally required erasure or objection. Contact intelligence@cabreza.com.

8. Aggregated and De-Identified Data

We create aggregated, de-identified statistics and benchmarks from use of the Services (for example, anonymized "organizations like you" cohort signals). This data is stripped of identifiers, enforces a minimum cohort size, excludes an organization from its own benchmark, and does not identify or attribute data to any named organization. We take reasonable measures to prevent re-identification of de-identified data. We may use and retain this data without the restrictions that apply to personal data.


9. Cookies

Most of the cookies we use are strictly necessary for the Services to function, such as keeping you signed in and remembering your selected workspace, and we use Sentry for error and performance monitoring. Our first-party product-usage analytics inside the application (Section 1) uses your browser's local storage rather than cookies.

Cookies are also set by Microsoft Clarity, and, on the public website only, by Google Analytics 4 and by the company-identification providers named in Section 1. These are analytics and measurement cookies.

We do not use advertising cookies. Advertising storage is switched off for every visitor to our website, in every country, and there is no way to turn it on.

In the EU, EEA, UK, and Switzerland the website sets no analytics cookies until you accept them on the cookie banner. Everywhere, we honor the Global Privacy Control signal: when your browser sends it, we load no analytics or company-identification providers at all. You can also manage cookies and site storage through your browser.


10. Security

We use technical and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls, per-organization data isolation, and audit logging. No method of transmission or storage is fully secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach, we will act as required by applicable law. Where Cabreza processes personal data as a processor on a customer's behalf, we will notify the customer (the controller) without undue delay so the customer can fulfill its own regulatory notification obligations; the customer is responsible for notifying the relevant authority. Where Cabreza is the independent controller — for example, for our own website visitors or the intelligence corpus — we will notify you and notify the relevant authorities directly as required by law.


11. International Data Transfers

The Services are hosted in the United States (AWS, us-east-1). All storage of your data stays in that region.

AI inference is the one exception. Some AI features use Amazon Bedrock's global routing, which sends the request to whichever AWS region has capacity at that moment. That region can be outside the United States. Bedrock processes the request and returns the result; nothing is stored in the region that served it, and no foundation model is trained on your data.

If you access the Services from outside the United States, you understand your data will be transferred to and processed in the United States. Where required, we provide an appropriate transfer mechanism, such as Standard Contractual Clauses, in the data processing addendum we make available on request. Data-residency options may be available to Enterprise customers.


12. Your Privacy Rights

Depending on your jurisdiction (including under the GDPR and UK GDPR and U.S. state laws such as the CCPA/CPRA), you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. You can export your organization's data through the Services, and you can delete your organization as described in Section 6. To exercise other rights, contact privacy@cabreza.com. We will respond as required by law and will not discriminate against you for exercising your rights.

California: we do not sell or "share" (for cross-context advertising) personal data. Authentication and certain security telemetry are collected for security purposes.


13. Children's Privacy

The Services are for business use and are not directed to individuals under 16. We do not knowingly collect personal data from children.


14. The Cabreza Plugin for Claude and ChatGPT

Cabreza publishes a plugin for Claude and for ChatGPT. It is an MCP server, and it reaches the same Cabreza service as the Cabreza application. Everything else in this policy applies to that use as written.

What reaches us. Claude or ChatGPT sends the plugin what you ask Cabreza to do, and the answers you give to Cabreza's questions. It does not send us your chat history, your other conversations, or files you have open in that window.

What we do with it. We use it to answer you, to run and secure the Services, and to improve Cabreza, including our library, our guidance and our coverage of the standards our customers ask about. Sections 1 and 2 govern this. We do not sell it.

What you save. If you are signed in and you save something through the plugin, it lands in your Cabreza workspace. Section 6 governs how long we keep it and how you delete it.

Claude and ChatGPT are not ours. Each has its own privacy policy, and it covers everything inside that window. Read Anthropic's Privacy Policy for Claude and OpenAI's Privacy Policy for ChatGPT.

Turning it off. Remove the plugin in Claude's or ChatGPT's settings. That stops all traffic between the plugin and Cabreza at once. To reach us about your data, email privacy@cabreza.com. Section 12 covers your rights.


15. Changes and Contact

We may update this Privacy Policy; we will post the revised version, update the "Effective" date, and provide additional notice where required. Contact: privacy@cabreza.com — Cabreza, Inc., 18 Manassas Dr, Middletown, Delaware 19709, US.