Privacy Policy & Code Sovereignty Pledge
Our legally binding architecture governance framework: zero public LLM training, ephemeral AST memory processing, and 100% client intellectual property ownership.
1. Corporate Identity & Platform Scope
This Privacy Policy and Code Sovereignty Pledge ("Policy") governs all interactions with the Paae.ai platform and the CodeArchaeologist (`PAAE_ARCH`) engine.
Paae.ai is a proprietary software platform owned and operated by Resvanta Technologies Inc. ("Resvanta Group", "we", "us", or "our"), with cross-border headquarters in San Francisco, CA and Toronto, ON ([resvanta.com](https://resvanta.com)).
For commercial client deals, Paae.ai operates under the Resvanta Group Master Enterprise Contract Suite, comprising our Parent Enterprise Master Services Agreement (MSA), Bilateral Confidentiality Agreement (Mutual NDA), and Schedule C — CodeArchaeologist by Paae.ai (PAE).
Under the General Data Protection Regulation (GDPR), the UK Data Protection Act, and the California Consumer Privacy Act (CCPA/CPRA), Resvanta Technologies Inc. acts as the Data Controller for direct corporate account data, and as a Data Processor with respect to customer source code and architectural telemetry.
2. Read-Only AST Static Analysis & Ephemeral Processing
CodeArchaeologist is engineered to provide comprehensive architectural intelligence without ever risking the exposure or retention of your business logic:
Deterministic Compiler-Level Parsing
Our engine operates at the Abstract Syntax Tree (AST) compiler level. Rather than analyzing code through generative external APIs, CodeArchaeologist uses deterministic static analyzers to extract structural relationships (class inheritance, package imports, entry-point routers, and relational foreign keys).
Volatile Ephemeral Enclaves
When you submit a repository via Git URL or compressed archive:
- The repository is unpacked exclusively into an ephemeral, encrypted scratch directory or non-root memory enclave.
- Abstract Syntax Trees are traversed to compute graph metrics (PageRank centrality, Martin's instability index, and Tarjan circular knots).
- During this traversal, proprietary business formulas, internal comments, and data literals are stripped out.
- Instant Purge: The moment the audit analysis finishes, the temporary codebase directory is permanently deleted using secure file-shredding routines.
3. Data Classification: What We Collect vs. What We Never Touch
| Data Classification | Data Elements Processed | Storage & Retention Policy |
|---|---|---|
| Account & Executive Identity | Name, corporate work email, company name, direct telephone number, job title. | Encrypted at rest (AES-256). Retained for active customer account lifecycle. |
| Structural Architecture Metadata | File paths, language SLOC counters, dependency edge lists, coupling indices, living ADR logs. | Encrypted at rest. Stored in the ArchaeologyDossier. Contains zero lines of source code. |
| Cryptographic Fingerprints | SHA-256 tree hashes, Git root commit fingerprints, HMAC audit seals. | Immutable audit ledger. Used for document verification and anti-salami-peeling quota protection. |
| Proprietary Business Logic | Algorithm code, application formulas, internal functions. | NEVER RETAINED. Ephemeral memory only; shredded immediately post-analysis. |
| Production Database Records | Live customer records, database rows, financial transactions. | NEVER COLLECTED. We parse DDL schemas only; we never connect to production databases. |
| Credentials & Access Secrets | Git Personal Access Tokens (PATs), SSH keys. | Held in volatile memory only during clone operation; never saved to disk or persistent logs. |
4. Enterprise Security Controls & Sovereign Topologies
To meet the stringent vendor risk requirements of Tier-1 financial institutions, healthcare networks, and defense contractors, we enforce rigorous infrastructure controls:
- Encryption in Transit: All HTTP and API traffic enforces TLS 1.3 with Perfect Forward Secrecy (PFS). Legacy TLS protocols (< TLS 1.2) are blocked at the edge.
- Encryption at Rest: All database records, audit dossiers, and metadata backups are encrypted using AES-256 with managed HSM keys.
- Tenant Isolation: Every corporate domain is allocated an isolated workspace boundary, preventing cross-tenant data leakage.
- Air-Gapped Sovereign Appliance: For institutions subject to strict zero-egress regulations (e.g. DORA, Basel III, defense intelligence), we offer
code-arch airgap—a self-contained binary and container appliance that executes 100% offline within your internal VPC without public internet access.
5. Global Privacy Rights (GDPR, CCPA/CPRA, PIPEDA)
We extend complete data protection rights to all enterprise contacts globally:
- Right to Erasure ("Right to Be Forgotten"): You may request permanent deletion of your account, company history, and generated audit dossiers at any time.
- Right of Access & Portability: You may request a complete export of all structural telemetry and account information associated with your corporate domain.
- Right to Rectification: You may update or correct executive contacts, billing profiles, or advisory practice accreditations.
Exercising Your Data Rights
To submit a data access or deletion request, or to request vendor security compliance questionnaires (SOC 2, SIG, CAIQ):
⚖️ Corporate Legal & Privacy Escalation: [email protected]
⚙️ System Administration Support: [email protected]
6. Audited Enterprise Subprocessors
Paae.ai relies on a minimal, audited group of SOC 2 Type II-certified infrastructure partners:
- Cloudflare, Inc.: Edge proxy routing, DDoS defense, SSL/TLS termination.
- Amazon Web Services (AWS): Cloud compute environments and encrypted storage vaults.
- Google Workspace: Authenticated transactional email dispatch with full DKIM, SPF, and MX verification.
All subprocessors are bound by enterprise Data Processing Addenda (DPAs) strictly prohibiting the secondary use of client data.
7. Contact & Governance Notice
This Policy is maintained by the Resvanta Technologies Inc. Architecture Governance Board. For legal inquiries, formal DPA execution, or compliance attestations:
Attn: Office of the Chief Architect & Data Protection Officer
Website: resvanta.com • Platform: paae.ai
Technical Inquiries: [email protected]
Legal & Privacy Escalation: [email protected]