A small product. A clear data story.
This notice describes how InfraVerdict processes information when you use the site and request an infrastructure review.
Information we process
We process your account email, authentication metadata, analysis metadata, AI-generated results and limited technical logs needed to operate the service. If you join the early-access list, we retain your email and the time of your request.
Analysis metadata includes the source type, environment, cloud, optional filename, input size, input hash, redaction count, timestamps, model, prompt version, processing time and token usage where available. We do not require access to your cloud account or infrastructure.
Submitted infrastructure and AI analysis
Your infrastructure text and optional context are processed to provide the analysis you request. When AI analysis is enabled, sanitized content may be sent to Anthropic’s API. Anthropic processes those requests under its applicable API terms and policies.
Raw infrastructure input is not intentionally persisted in the InfraVerdict PostgreSQL database after processing. Generated reports are stored and may contain sanitized excerpts as evidence. Automated secret detection is best-effort, so do not submit credentials or unnecessary personal data.
Authentication and service providers
Sign-in emails are delivered through the operator’s SMTP server. We store secure hashes of sign-in codes and session tokens, rather than the raw values. An HTTP-only session cookie keeps you signed in. It expires and is invalidated when you sign out.
The application uses PostgreSQL for account and report storage, SMTP for email delivery and Anthropic for enabled AI analysis. Cloudflare handles public traffic and may process connection metadata. The public demo is static and does not send the example inputs to an AI provider.
Retention and deletion
Account information and reports remain available while your account exists unless you delete them. You can delete individual analyses, clear your analysis history or delete your account from the application. Account deletion removes the account, its analyses and active sessions from the application database.
Technical operational logs may be retained separately for troubleshooting. They are designed to exclude raw infrastructure text, credentials and sign-in codes. We do not promise immediate removal from operational backups or logs when a database record is deleted.
Early-access list
Joining the early-access list lets us record your interest and contact you when access expands. There is no automated marketing sequence. Deleting your account also removes the early-access entry for the same email address. You can sign in with that address and use account deletion in Settings to remove it.
Changes to this notice
This service is evolving. We will update this page when the way we process information materially changes. We make no claims of privacy certifications or independent compliance audits.