Effective Date: March 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between VeriSwarm (“Processor”) and the customer entity identified in the applicable service agreement (“Controller”) for the provision of the VeriSwarm platform services.
This DPA sets out the terms under which the Processor processes personal data on behalf of the Controller in connection with the VeriSwarm platform, in compliance with applicable data protection laws including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).
| Controller | The Customer. Determines the purposes and means of processing Personal Data through the VeriSwarm platform. |
| Processor | VeriSwarm. Processes Personal Data solely on the Controller's behalf and in accordance with documented instructions. |
The following categories of data may be processed through the VeriSwarm platform:
| Category | Description |
|---|---|
| Agent events | Behavioral events generated by AI agents, including tool calls, task completions, errors, and interactions. May contain personal data if agents process user-facing content. |
| Trust scores | Computed scores across identity, risk, reliability, and autonomy dimensions. Derived from event data. |
| PII tokens | Tokenized representations of personal data detected by Guard. Original PII is encrypted separately from tokens. |
| Conversation logs | Conversations between end-users and managed agents (Cortex runtime). May contain personal data. |
| API usage metadata | Request counts, timestamps, IP addresses, and authentication metadata associated with platform usage. |
| Account data | Names, email addresses, and organizational information provided during registration and workspace management. |
The Processor processes Personal Data solely for the following purposes, as instructed by the Controller:
Data retention periods are determined by the Controller's plan tier:
| Plan | Default Retention |
|---|---|
| Free (Gate) | 7 days |
| Pro | 90 days |
| Max | 365 days |
| Enterprise | Custom (as agreed in service contract) |
The Controller may request early deletion of data at any time via the API (GDPR deletion endpoint) or the platform dashboard. Upon account termination, all data is deleted within 30 days unless a longer retention period is required by law.
The Processor engages the following sub-processors. The Controller consents to these sub-processors as of the effective date of this DPA. The Processor will notify the Controller at least 30 days in advance of adding new sub-processors.
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Cloudflare, Inc. | CDN, DDoS protection, DNS, and tunnel infrastructure | Global (edge network) |
| Microsoft Azure | LLM inference for Cortex agent runtime (Azure OpenAI Service) | US East |
| Stripe, Inc. | Payment processing and billing | US |
Each sub-processor is bound by data processing terms no less protective than this DPA. The Processor remains liable for the acts and omissions of its sub-processors.
The Processor implements the following technical and organizational measures to protect Personal Data:
| Measure | Implementation |
|---|---|
| Encryption at rest | AES-256 / Fernet encryption for stored data and secrets |
| Encryption in transit | TLS 1.3 for all API and web traffic |
| Access control | Role-based access control (RBAC) with tenant isolation. Three auth mechanisms: API keys, bearer tokens, session tokens. |
| Multi-factor authentication | MFA available for all user accounts |
| PII tokenization | Guard NER + regex detection replaces PII with opaque tokens before LLM processing. Original data stored encrypted separately. |
| Audit logging | All administrative actions and data access logged. Vault provides hash-chained immutable records. |
| Tenant isolation | Organization → Tenant → Agent hierarchy with strict data boundaries. No cross-tenant data access. |
| Backup and recovery | Daily automated backups with 7-day rotation. Tested recovery procedures. |
| Security testing | Internal red-teaming, prompt injection scanning, and adversarial testing of managed agents. |
The Processor will assist the Controller in fulfilling its obligations to respond to Data Subject requests, including:
GET /v1/admin/gdpr-export) and the dashboard.DELETE /v1/admin/gdpr-delete) or the dashboard. Deletion propagates to all platform components including Vault records.In the event of a Personal Data breach, the Processor will:
Personal Data is currently processed and stored in US East. Where Personal Data is transferred outside the European Economic Area (EEA) or the United Kingdom:
The Controller may audit the Processor's compliance with this DPA. Audits are subject to the following conditions:
This DPA remains in effect for the duration of the Controller's use of the VeriSwarm platform. Upon termination:
Liability under this DPA is subject to the limitations set forth in the underlying service agreement between the parties. Each party is liable for damages caused by its own breach of this DPA or applicable data protection laws.
For questions about this DPA, data processing practices, or to exercise data subject rights:
Request a signed copy of this DPA for your records.
Last updated: March 2026