Privacy Policy
Effective date: 2026-05-27
Last updated: 2026-08-11
This Privacy Policy describes how Standard Forensics, Inc. ("Standard Forensics," "we," "us," or "our") collects, uses, and discloses information when you use our website at standardforensics.com (the "Site"), our Cloud Service (the "Service"), or otherwise interact with us.
Standard Forensics provides an AI execution layer for disputes and investigations. The platform's current entry point is forensic data analytics, where agents plan, execute, check, and package analytical work under human direction and review.
This Policy is divided into two parts:
- Part A addresses information we collect directly from individuals who visit our Site, use the Service, or otherwise interact with us. In these contexts, Standard Forensics generally acts as a controller.
- Part B addresses information Customers provide to the Service. Customers control this data, and Standard Forensics processes it on their instructions as a processor. Applicable customer agreements, including any executed Data Processing Agreement (DPA), govern that processing.
Part A — Information we collect about you directly
1. Information we collect
Account information. When you or your organization uses the Service, we process your name, email address, organization affiliation, and account and membership identifiers. Authentication is provided through WorkOS AuthKit. Credentials and multi-factor authentication enrollment data are submitted directly to WorkOS; Standard Forensics does not receive or store those credentials. The Service maintains the application identity, membership, authorization, and session state needed to provide access.
Communications. When you contact a Standard Forensics email address, we collect the content of your communications and any information you choose to share with us.
Service and security records. When you use the Service, we create purpose-specific operational, security, and analytical records. Depending on the action, these records may include account, organization, engagement, workspace, or session identifiers; actions initiated and their outcomes; timestamps; and basic request or device information when available. These records support operation, security, reviewability, and forensic defensibility. They are not one comprehensive record of every action in the Service.
Site and Service analytics. We use Vercel Web Analytics on the Site and Service to understand traffic and product navigation. Vercel Web Analytics uses aggregated data and does not use cookies. We do not use Google Analytics, advertising trackers, or third-party marketing pixels.
Cookies. The Service uses cookies that are necessary for authentication and session management. We do not use advertising or cross-site tracking cookies.
We do not ordinarily collect payment card numbers, government-issued identifiers, health information, biometric data, or precise location data from Site visitors or Service users under Part A. Customer materials governed by Part B may contain these or other categories of data.
2. How we use information
We use information described in Part A to:
- Provide, maintain, secure, and improve the Service and Site
- Authenticate users and enforce access controls
- Communicate about accounts, the Service, and security matters
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Maintain operational, security, and analytical records
- Comply with applicable law and respond to lawful requests
We do not use information collected under Part A to train artificial intelligence or machine learning models, sell it, or use it for advertising.
3. How we share information
Subprocessors. We use subprocessors to operate the Service. Our current list is published at standardforensics.com/subprocessors. Contractual notice and objection rights, if any, are governed by the applicable executed customer agreement.
Business service providers. We use other service providers for our internal business operations, such as communications, collaboration, and payment processing. They receive only the information needed for the relevant function and do not receive Customer engagement materials through the Service.
Legal compliance. We may disclose information when required by law or legal process, or when reasonably necessary to protect the rights, property, or safety of Standard Forensics, our Customers, or others. When legally permitted and required by an applicable customer agreement, we will notify an affected Customer of legal process directed at its Customer Content.
Business transfers. Information may be transferred as part of a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable confidentiality and data-protection obligations.
We do not sell personal data, share personal data for cross-context behavioral advertising, or disclose personal data to data brokers.
4. Security
We maintain administrative, technical, and physical safeguards designed to protect personal data. These include encryption in transit and at rest, authentication through WorkOS AuthKit, authorization against current application-owned membership and engagement records, network-isolated execution of customer-data analytical code, and documented incident-response procedures.
Additional security information is available by contacting security@standardforensics.com. Some materials may require confidentiality protections.
5. Data retention
We retain Part A information for as long as reasonably necessary to provide and secure the Service, meet applicable legal and contractual obligations, resolve disputes, and enforce agreements. Retention varies by record type and purpose; we do not apply one seven-year period to all application or security records.
When Customer engagement data is destroyed under Part B, active application data is removed and verified across the applicable database, object-storage, and local execution or cache surfaces. Provider-managed database backups and point-in-time recovery may retain deleted database rows for up to seven days before expiry. Limited security, financial, legal, and destruction records may be retained when required for their stated purpose or by an applicable agreement.
Vercel Web Analytics data is retained in aggregated form.
6. Your rights
Depending on your location and the circumstances, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal data, withdraw consent where consent is the basis for processing, and complain to a data-protection authority.
To exercise a right concerning Part A information, contact legal@standardforensics.com. We will verify and respond to requests within the time required by applicable law. If your account is provided by a Customer, some requests may be most directly handled through that organization's administrator.
7. California residents
California law may provide additional rights concerning personal information. During the preceding 12 months, the categories of Part A personal information we may have processed include identifiers; customer records; service-usage and internet activity; approximate location inferred from an IP address; professional or employment information; and account credentials processed by our authentication provider.
We do not sell personal information or share it for cross-context behavioral advertising. California residents may have rights to know, access, delete, or correct personal information and to non-discrimination for exercising those rights. To submit a request, contact legal@standardforensics.com. An authorized agent may submit a request as permitted by applicable law.
8. European Economic Area and United Kingdom residents
Where applicable, we process Part A information to perform a contract, pursue legitimate interests such as securing and improving the Service, comply with legal obligations, or based on consent. We balance legitimate interests against affected individuals' rights where required.
Our subprocessors may process data in the United States and other locations described in the current Subprocessor List. Where a restricted transfer mechanism is required, we use the mechanism provided by applicable law and the relevant executed agreement, which may include the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.
EEA and UK residents may have the rights described in Section 6 and may lodge a complaint with an applicable supervisory authority, including the UK Information Commissioner's Office for UK matters.
9. Children's privacy
The Site and Service are intended for business and professional use and are not directed to children. If you believe a child provided Part A personal information to us, contact legal@standardforensics.com.
10. Changes to this Policy
We may update this Policy as our practices or legal obligations change. We will update the date above and provide additional notice when required by applicable law or agreement.
11. Contact
Privacy questions, rights requests, or complaints:
legal@standardforensics.com
Part B — Customer Content
Customers may provide financial records, communications, direct chat attachments, and other materials for analysis. Those materials may contain personal data about employees, vendors, counterparties, investigation subjects, or other individuals.
Customers control this data. We process Customer Content on a Customer's documented instructions and under the applicable customer agreement.
Where Customer Content is processed. The Service uses:
- Amazon Web Services for primary application compute, object storage, and Amazon Bedrock model inference
- Supabase-managed PostgreSQL for application records, including conversations and direct chat attachments, workflow and analytical records, findings, catalog metadata, and security or audit records
- Vercel for frontend hosting, content delivery, and aggregated web analytics
- WorkOS for authentication and user management; WorkOS does not receive engagement materials through the Service
Model inference may receive prompts, direct chat attachments, selected or extracted document text, engagement context, metadata, findings, and bounded analytical results assembled for the requested task. Uploading a source file does not automatically send that file's raw bytes to a model. The current subprocessor list provides additional detail.
Our processing commitments. Standard Forensics does not train AI or machine learning models on Customer Content or Customer analytical outputs, and does not combine Customer Content or methodology across Customers to improve the Service for other Customers. Our application enforces organization and engagement boundaries, and generated analytical code runs in a credential-free, network-isolated sandbox.
Destruction. At a Customer's instruction and as provided by the applicable agreement, destruction removes and verifies active database, object-storage, and local execution or cache state. Provider-managed database backups and point-in-time recovery may retain deleted rows for up to seven days. A limited destruction record and other records that must be retained for security, legal, or financial purposes may remain.
If your personal data appears in Customer Content, contact the relevant Customer to exercise your rights. Standard Forensics assists Customers as required by applicable law and executed agreements. You may also contact legal@standardforensics.com, and we will route the request when reasonably possible.
Definitions
- "Customer" means an organization authorized to use the Service under an agreement with Standard Forensics.
- "Customer Content" means information a Customer or its users submit to, generate through, or direct the Service to process, subject to the applicable agreement.
- "Service" means the Standard Forensics Cloud Service at
app.standardforensics.comor a successor URL. - "Site" means the public website at
standardforensics.com. - "Personal data" and "personal information" have the meanings given by applicable data-protection laws.