🛡️ Institutional Code Sovereignty Protocol

Privacy Policy & Code Sovereignty Pledge

Our legally binding architecture governance framework: zero public LLM training, ephemeral AST memory processing, and 100% client intellectual property ownership.

Operating Entity: Resvanta Technologies Inc. (Resvanta Group) • Effective Date: October 7, 2026 • Version: 2.1.0

🔒 The Paae.ai Code Sovereignty Pledge

Enterprise software architectures power global commerce, banking, and healthcare. We believe proprietary source code must never be treated as training fuel for third-party artificial intelligence models. Our platform enforces strict mathematical isolation:

1. Zero Public AI Training

Customer code (Java, Python, C#, COBOL, TypeScript, SQL) is NEVER fed to public LLMs or foundational model datasets.

2. 100% Customer IP Ownership

Clients retain exclusive, perpetual ownership of all source code, extracted dependency graphs, ADRs, and target blueprints.

3. Ephemeral In-Memory Scans

Repositories are parsed at the AST level in volatile sandbox memory and immediately shredded upon audit completion.

4. Zero-Code Data Retention

Our persistent databases store only high-level structural metrics and dependency matrices. Zero raw code lines are stored.

1. Corporate Identity & Platform Scope

This Privacy Policy and Code Sovereignty Pledge ("Policy") governs all interactions with the Paae.ai platform and the CodeArchaeologist (`PAAE_ARCH`) engine.

Paae.ai is a proprietary software platform owned and operated by Resvanta Technologies Inc. ("Resvanta Group", "we", "us", or "our"), with cross-border headquarters in San Francisco, CA and Toronto, ON ([resvanta.com](https://resvanta.com)).

For commercial client deals, Paae.ai operates under the Resvanta Group Master Enterprise Contract Suite, comprising our Parent Enterprise Master Services Agreement (MSA), Bilateral Confidentiality Agreement (Mutual NDA), and Schedule C — CodeArchaeologist by Paae.ai (PAE).

Under the General Data Protection Regulation (GDPR), the UK Data Protection Act, and the California Consumer Privacy Act (CCPA/CPRA), Resvanta Technologies Inc. acts as the Data Controller for direct corporate account data, and as a Data Processor with respect to customer source code and architectural telemetry.

2. Read-Only AST Static Analysis & Ephemeral Processing

CodeArchaeologist is engineered to provide comprehensive architectural intelligence without ever risking the exposure or retention of your business logic:

Deterministic Compiler-Level Parsing

Our engine operates at the Abstract Syntax Tree (AST) compiler level. Rather than analyzing code through generative external APIs, CodeArchaeologist uses deterministic static analyzers to extract structural relationships (class inheritance, package imports, entry-point routers, and relational foreign keys).

Volatile Ephemeral Enclaves

When you submit a repository via Git URL or compressed archive:

3. Data Classification: What We Collect vs. What We Never Touch

Data Classification Data Elements Processed Storage & Retention Policy
Account & Executive Identity Name, corporate work email, company name, direct telephone number, job title. Encrypted at rest (AES-256). Retained for active customer account lifecycle.
Structural Architecture Metadata File paths, language SLOC counters, dependency edge lists, coupling indices, living ADR logs. Encrypted at rest. Stored in the ArchaeologyDossier. Contains zero lines of source code.
Cryptographic Fingerprints SHA-256 tree hashes, Git root commit fingerprints, HMAC audit seals. Immutable audit ledger. Used for document verification and anti-salami-peeling quota protection.
Proprietary Business Logic Algorithm code, application formulas, internal functions. NEVER RETAINED. Ephemeral memory only; shredded immediately post-analysis.
Production Database Records Live customer records, database rows, financial transactions. NEVER COLLECTED. We parse DDL schemas only; we never connect to production databases.
Credentials & Access Secrets Git Personal Access Tokens (PATs), SSH keys. Held in volatile memory only during clone operation; never saved to disk or persistent logs.

4. Enterprise Security Controls & Sovereign Topologies

To meet the stringent vendor risk requirements of Tier-1 financial institutions, healthcare networks, and defense contractors, we enforce rigorous infrastructure controls:

5. Global Privacy Rights (GDPR, CCPA/CPRA, PIPEDA)

We extend complete data protection rights to all enterprise contacts globally:

Exercising Your Data Rights

To submit a data access or deletion request, or to request vendor security compliance questionnaires (SOC 2, SIG, CAIQ):

📧 Architecture & Security Desk: [email protected]
⚖️ Corporate Legal & Privacy Escalation: [email protected]
⚙️ System Administration Support: [email protected]

6. Audited Enterprise Subprocessors

Paae.ai relies on a minimal, audited group of SOC 2 Type II-certified infrastructure partners:

All subprocessors are bound by enterprise Data Processing Addenda (DPAs) strictly prohibiting the secondary use of client data.

7. Contact & Governance Notice

This Policy is maintained by the Resvanta Technologies Inc. Architecture Governance Board. For legal inquiries, formal DPA execution, or compliance attestations:

Resvanta Technologies Inc. ("Resvanta Group")
Attn: Office of the Chief Architect & Data Protection Officer
Website: resvanta.com • Platform: paae.ai
Technical Inquiries: [email protected]
Legal & Privacy Escalation: [email protected]