Privacy Policy
Last updated: 24 July 2026
1. Who we are
SecAI is operated by Tech Steps LLC, licensed in Sharjah Media City, United Arab Emirates ("we", "us"). This policy explains what data we collect through the SecAI platform and agent, why we collect it, who we share it with, and what rights you have over it.
For questions about this policy or to exercise any of the rights described below, contact us at [email protected].
2. Data we collect
Account data
When you register we collect your name, email address, organisation name, and a hashed password. If you subscribe to a paid plan we also process billing records. We never see or store full payment card details - these are handled by our payment provider.
Server telemetry
The SecAI agent runs on servers you choose to monitor and transmits operational and security data, including:
- Hostname, operating system, distribution version, and agent version
- System metrics such as CPU, memory, disk and uptime
- Installed package names and versions, used for vulnerability matching
- Cryptographic hashes and paths of monitored files, for integrity checking
- Security events, including authentication failures, source IP addresses of detected attacks, blocked addresses, process and listening-port information, and outbound connection metadata
- Configuration state relevant to security posture, such as SSH settings
The agent is designed to transmit security-relevant metadata. It does not read, collect or transmit the contents of your application databases, user files, or customer records stored on the monitored server.
Usage data
We record logins, actions taken in the dashboard, and API access for security and audit purposes.
3. How we use data
- To detect, alert on and respond to security threats on your servers
- To generate AI-assisted security audits, risk scores and remediation guidance
- To match installed packages against public vulnerability databases
- To send you alerts, reports and service notifications
- To provide, bill for and support the service
- To investigate abuse of the platform and meet legal obligations
We do not sell your data, and we do not use your data for advertising.
4. AI processing and sub-processors
SecAI uses third-party large language model providers to analyse security telemetry and produce audit findings. Where an AI audit is generated, relevant security telemetry from your servers is transmitted to these providers for processing. This may involve transfer of data outside the United Arab Emirates.
The third parties we rely on are:
| Provider | Purpose | Location |
|---|---|---|
| OpenAI | AI security audit generation | United States |
| Anthropic | AI security audit generation | United States |
| OSV.dev (Google) | Vulnerability data lookup for installed packages | United States |
| PayPal | Subscription billing and payment processing | United States / global |
| Cloudflare | Network security, DNS and traffic delivery | Global |
If your organisation has data residency requirements that prohibit this processing, contact us before enabling AI audit features and we will discuss available options.
5. Where data is stored
Platform data, including account records, telemetry and incident history, is stored on infrastructure we operate. Data transmitted to the sub-processors listed above is processed on their infrastructure under their own terms and security controls.
6. Retention
- Incident and security event history is retained according to your subscription plan
- Audit reports are retained for the life of the account unless you delete them
- Account and billing records are retained as required for legal and accounting purposes
- On account closure, we delete or anonymise platform data within 90 days, except where retention is legally required
7. Security
We use encrypted transport for all agent and dashboard communication, hash stored passwords and API keys, enforce organisation-level data isolation between tenants, and restrict internal access to production data. No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your data, we will notify you without undue delay.
8. Your rights
Subject to applicable law, including the UAE Personal Data Protection Law, you may request access to the personal data we hold about you, correction of inaccurate data, deletion of your data, restriction of or objection to certain processing, and a copy of your data in a portable format. You may also withdraw consent where processing is based on consent.
To make a request, email [email protected]. We will respond within the period required by applicable law.
9. Your responsibilities
You are responsible for ensuring you have the right to install the SecAI agent on the servers you monitor, and for informing anyone whose personal data may appear in that telemetry, where required by law. If you monitor servers on behalf of your own clients, you are responsible for the appropriate agreements with them.
10. Cookies
We use strictly necessary cookies and local browser storage to keep you signed in and to remember interface preferences such as theme and language. We do not use advertising cookies.
11. Children
SecAI is a business product and is not directed at anyone under 18. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy as the service changes. Material changes will be communicated to account holders by email or through the dashboard, and the date at the top of this page will be updated.
13. Contact
Tech Steps LLC
Sharjah Media City, United Arab Emirates
[email protected]