Skip to content
Private preview — Design partners are now being selected for controlled agent-execution pilots. Apply now
Data Handling

Data Handling

What the DecisionHypervisor™ platform receives, generates, and retains — determined by the integration, policy, deployment mode, and customer configuration.

The framing

DecisionHypervisor is designed to minimize the information required to evaluate a proposed action. Actual data received and retained depends on the integration, policy, deployment mode, and customer configuration.

Decision data flow
Actor
Agent
DecisionHypervisor
Protected Tool
Target System
↳ Evidence Store — hash-chained Decision Trace ↳ Human Reviewer — escalation path

The agent proposes; the DecisionHypervisor platform decides. Only an authorized action reaches the protected tool. Decisions write to the evidence store, and REVIEW_REQUIRED outcomes route to a human reviewer instead of executing.

Information submitted in an authorization request

An authorization request arrives as an Execution Intent: a strictly typed record describing the actor, the proposed action, the target, and the context the applicable policy requires. Unknown or undeclared fields are rejected at the boundary. Integrations declare only the context their policies reference.

Information generated by a decision

Each evaluation produces a Decision Object — the resolution and its basis — and appends to a hash-chained Decision Trace. Where evidence export is configured, a Proof Record bundles the decision, the grant, and the trace for independent verification.

Contact and form data

The access-request and contact forms collect name, email, company, role, and use case. Submissions are delivered as transactional email and used only to evaluate and respond to the request.

Analytics

Plausible provides cookie-less, aggregate site analytics by default; it does not collect IP addresses or personal data. Google Analytics 4 loads only after explicit opt-in through the consent banner, and withdrawing consent stops subsequent measurement.

Playground input

Text entered into the AI Policy Playground is sent to the Google Gemini API to generate illustrative output. Never enter confidential, proprietary, or personal information. Playground output is non-binding and may be inaccurate.

Retention

Form submissions are kept as long as needed to respond to the request and to meet legal obligations. Retention of decision data inside a deployment — intents, Decision Objects, traces — is configured per deployment by the customer.

Model training

We do not use your decision data to train models. Decision content in a customer deployment is not used for model training by the DecisionHypervisor platform.

Deployment differences

Self-hosted and customer-VPC deployments: decision data stays inside the customer boundary and evaluation resolves locally. Managed services: none are offered today — there is no DecisionHypervisor-operated hosted control plane in service.

Customer responsibilities

Customers decide what context their policies require, configure retention and evidence-export settings in their own deployment, and remain responsible for the lawfulness of the data they submit.

Privacy questions, data requests, and subprocessor inquiries are handled by the privacy contact.

privacy@decisionhypervisor.com →
Request a Control Pilot