Security & privacy
We hold ourselves to the posture we measure for you. 8200.dev is agentless and read-oriented, has no offensive capability, and minimizes what it sends to any model.
Our own posture
Connectors request read-oriented, least-privilege scopes by default — enough to map permissions, never more. We are agentless: nothing is installed inside your environment. The platform has no offensive or exploitation capability — it reads metadata and reasons about it.
Standard security headers, rate limiting and append-only audit logging are in place; sensitive operations are recorded, and connector credentials are encrypted at rest.
Data minimization to the model
The engines are rule-first and deterministic by default; the AI model is an optional escalation. When a verdict does call the model, only minimized metadata is sent — never your file contents. The rule floor alone is enough to operate.
Data residency
Application data is hosted in the EEA (Iceland). When a verdict requires the model, the minimized metadata is processed by Anthropic in the US under appropriate transfer safeguards. No customer file contents leave for the model.
Your data rights
You can export your data as JSON and delete your account from in-app settings. Deletion disconnects connectors and destroys stored credential ciphers immediately, blocks access, and hard-purges after a short grace window.
Subprocessors
Anthropic (the AI support assistant and executive-summary narratives, US; never file contents or credentials), Resend (transactional email), PayPal (billing), RunPod (hosting and database) and Cloudflare (network edge). The Trust page and the legal documents carry the authoritative, current list.