Privacy Policy

GDPRCCPA / CPRACalOPPA

Privacy Policy

Effective Date: June 20, 2026

At Armorstack, we are committed to protecting your privacy and securing your personal information. As an AI-powered Managed Intelligence Provider specializing in cybersecurity, IT operations, strategic advisory, and physical security, we prioritize data protection in all our interactions, including on our website, social media pages, and related services.

This Privacy Policy explains how Armorstack, LLC (hereinafter “Armorstack,” “we,” “us,” or “our”) collects, uses, discloses, retains, and safeguards your personal information. It also describes your rights under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and the California Online Privacy Protection Act (CalOPPA).

By engaging with our website, social media pages (including Facebook and Instagram), or related services, you acknowledge that you have read and understand this Privacy Policy. Where required by law, we will obtain your consent before processing your personal data.

1. Information We Collect

Armorstack, LLC collects information you provide directly (name, email, phone, company, role, service interests) when you request a consultation, download resources, subscribe to communications, or engage our services. We also collect information automatically through cookies and similar technologies: IP address, browser type, device identifiers, pages visited, referring URL, and engagement metrics. For clients, we collect information necessary to deliver contracted services, which may include technical data from monitored systems, configuration details, and security event telemetry.

2. Lawful Basis for Processing (GDPR)

For individuals in the European Economic Area, United Kingdom, or Switzerland, we process personal data under one or more of these lawful bases: (a) consent, which you may withdraw at any time; (b) contract, where processing is necessary to deliver services you requested; (c) legitimate interests, balanced against your rights, including business development, service improvement, and security operations; (d) legal obligation, where required by applicable law. Where we rely on legitimate interests, you may object and we will evaluate the request.

3. How We Use Your Information

We use collected information to deliver services you engaged us for, respond to inquiries, send requested communications including newsletters and service updates, administer accounts and billing, protect against fraud and security threats, improve our offerings and site experience, and comply with legal obligations. For marketing communications, we rely on your consent or legitimate interest, and every commercial message includes a one-click unsubscribe mechanism.

4. Sharing of Information

We share information only as necessary: with technology providers bound by written data protection agreements, including Google LLC (Google Analytics 4, via the MonsterInsights plugin) for website analytics; with CRM, email delivery, and payment-processing providers under the same written protections; with professional advisors (legal, accounting, insurance) under confidentiality obligations; with business partners when you engage services that involve joint delivery, with notice; with law enforcement or regulators when legally required or to protect rights, safety, or property; and in connection with a merger, acquisition, or asset sale, with appropriate notice. We do not sell personal information. As our website infrastructure evolves, this section will be updated to reflect any additional analytics, security, or content-delivery vendors placed into active service — see our Cookie Policy for the current, detailed list of tracking technologies in use and how to manage your preferences.

5. Your Privacy Rights

Depending on your location, you may have rights to: access the personal data we hold about you; correct inaccurate or incomplete data; delete your data subject to retention obligations; restrict or object to certain processing; receive your data in a portable format; withdraw consent where processing is consent-based; and lodge a complaint with a supervisory authority. Wisconsin, California, and other state residents have additional statutory rights. To exercise any right, email [email protected] — we respond within 30 days (or as required by applicable law).

6. Data Security

Armorstack is a Managed Intelligence Provider — security is the core of what we deliver. We implement administrative, technical, and physical safeguards including: role-based access control, multi-factor authentication on all privileged accounts, encryption in transit (TLS 1.2+) and at rest (AES-256), continuous monitoring via our SENTRY SOC, vulnerability management, employee security training, and documented incident response procedures aligned to NIST CSF 2.0. No method of transmission or storage is 100% secure; we continuously improve our controls and will notify you promptly of any incident that materially affects your data.

7. Data Retention

We retain personal data only as long as necessary for the purposes collected, or as required by law, contract, or legitimate business need. Marketing contacts: until you unsubscribe or request deletion. Client service records: term of engagement plus seven years for tax, audit, and statute-of-limitations compliance. Security telemetry: per contracted retention in the applicable Master Services Agreement, typically 90–365 days for operational data and longer for incident evidence. Backups are retained on rotation and overwritten on schedule.

8. International Data Transfers

Armorstack is a U.S.-based company. If you are located outside the U.S., your information will be transferred to, stored, and processed in the U.S. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) or other valid transfer mechanisms, and we evaluate the recipient jurisdiction’s legal regime. You may request a copy of the safeguards in place by contacting [email protected]. For business customers requiring a signed Data Processing Addendum (DPA) reflecting GDPR Article 28 processor obligations, see our Data Processing Addendum or contact [email protected].

9. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or service offerings. Material changes will be communicated through the site, via email to active clients, or through other reasonable means. The effective date at the top of the policy reflects the last revision. Continued use of our site or services after notice constitutes acceptance of the updated policy.

10. Data Breach Notification

If we discover a security incident that compromises your personal data, we will notify affected individuals and applicable regulators within timeframes required by law: 72 hours for GDPR-covered EU/UK residents, timelines set by Wisconsin Statute §134.98 and HIPAA §164.404 for U.S. residents, and per any contractual commitments to clients. Notifications describe the nature of the incident, data affected, mitigation steps taken, and recommended actions for affected individuals. Our Incident Response team is staffed 24/7.

11. Contact Us

For privacy questions, rights requests, or concerns about this policy, contact: Armorstack, LLC — Attention: Privacy Officer — Email: [email protected] — Phone: (877) 890-5508. We respond to privacy inquiries within five business days and complete formal rights requests within 30 days (or sooner where required by law).

12. Additional Disclosures

California residents (CCPA/CPRA): you may request disclosure of categories and specific pieces of personal information collected, sold, or shared in the prior 12 months; request deletion; opt out of sale or sharing (we do not sell); and limit use of sensitive personal information. Non-discrimination: we will not deny service, charge different prices, or provide different quality for exercising your rights. Nevada residents: we do not sell personal information as defined under Nevada law. Do Not Track: our site does not respond to browser DNT signals; use the cookie consent interface to manage preferences. Children’s Privacy (COPPA): our website and services are directed to businesses and professionals, not children. We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected personal information from a child under 13, we will delete it promptly. Parents or guardians who believe we may have collected information from a child under 13 should contact us at [email protected].

Armorstack – The Standard of Truth in Technology.

Unifying security for a resilient future.

Product AddendumInboxSentry

InboxSentry Privacy Addendum

Effective: June 20, 2026 — Supplements the Privacy Policy above for the InboxSentry desktop application and related services.

Why a separate section? Most Armorstack services (advisory, managed security, vCIO/vCISO, CITADEL physical security) are professional services where Armorstack personnel access client systems under contract. InboxSentry is materially different. InboxSentry is a desktop application engineered for local-first processing and minimal data egress. Where the master Privacy Policy and this addendum address the same topic, the more protective provision controls.

Variance Summary

TopicOther Armorstack ServicesInboxSentry
Email content storageMay be reviewed by Armorstack personnel under MSAOn-device only, encrypted at rest, never transmitted to Armorstack
Mailbox credentialsMay be provisioned for service techniciansOAuth-only; tokens never stored on device in plaintext
AI processingGenerally not applicableEmail metadata sent to Anthropic Claude for triage; full bodies only on user-requested reply drafts
Data residencyUnited States (Armorstack infrastructure)On-device for email content; minimal metadata in U.S. infrastructure
Data subject accessPer MSASelf-serve via the application; uninstall = full deletion of local data

1. Information InboxSentry Collects

Account & licensing. Email address used for license issuance, Stripe customer ID (Stripe processes payment cards; Armorstack never receives card data), a non-reversible hardware device fingerprint used to enforce per-license device limits, and license heartbeat metadata (last-active timestamp, app version, OS version).

OAuth authorization. InboxSentry uses Google OAuth for Gmail and Microsoft OAuth for Outlook/M365 with minimum-necessary scopes. Refresh tokens are stored only in encrypted server-side connector storage at our serverless backend provider; tokens are not stored on user devices in plaintext and are not exposed through any application API.

Email metadata for AI triage. For each scanned message, InboxSentry sends the following to Anthropic Claude: sender address, sender name, subject line, timestamp, and a short content snippet (typically the first 500 characters). Full message bodies are NOT sent for standard triage. Under our enterprise terms with Anthropic, prompts and outputs are not used to train Anthropic models.

AI reply drafting (v2.1+). Full message thread context is sent to Anthropic only when the user explicitly requests a draft.

Local content. Email bodies, attachments, sender history, and triage results live in an encrypted SQLite database on the user device. This content is never transmitted to Armorstack, our backend provider, or any third party. Uninstalling InboxSentry deletes the local database.

2. InboxSentry Sub-Processors

Sub-ProcessorPurposeData HandledRegion
Stripe, Inc.Payment processingEmail, billing detailsUnited States
Anthropic, PBCAI inference (Claude API)Email metadata; reply context on user requestUnited States
Google LLCOAuth provider (Gmail)OAuth grantUnited States
Microsoft CorporationOAuth provider (Outlook/M365)OAuth grantUnited States
Cloudflare, Inc.CDN delivery of installer + manifestIP address (transient)Global edge
Base44Serverless backend hostingLicense + token dataUnited States

3. Your Rights for InboxSentry Data

All rights set forth in the master Privacy Policy above (access, rectification, erasure, portability, objection) apply to InboxSentry data. Exercise them by emailing [email protected]. Note that uninstalling the application also deletes all on-device email data — no Armorstack action required.

4. Data Retention

  • License records: active period + 7 years (tax compliance)
  • OAuth refresh tokens: until you disconnect the account or revoke at Google/Microsoft
  • Email metadata sent to Anthropic: not retained by Armorstack; Anthropic retains per their stated policy
  • Local on-device data: until you uninstall or delete manually

5. Security Posture

InboxSentry has been audited and hardened against eleven specific findings, each remediated and mapped to NIST 800-53 Rev. 5 controls and (where applicable) DISA STIG requirements. The full Security Audit & Hardening Report is available to enterprise customers under NDA via [email protected]. See also the Security & Vulnerability Disclosure Policy.

6. Brand Separation Notice

The InboxSentry product, the inboxsentry.ai domain, and product-specific marks are owned by Armorstack, LLC and may be transferred independently of the broader Armorstack business. In the event of such a transfer, this addendum will be updated and active license holders will receive thirty (30) days advance notice. The master Privacy Policy above governs all other Armorstack services and is unaffected by such a transfer.

7. Contact for InboxSentry-specific Privacy Inquiries

Email: [email protected] (subject line: “InboxSentry Privacy”)

Mailing: Armorstack, LLC

Questions About Your Privacy?

Our Privacy Officer responds to inquiries within five business days.

Contact Us