Data Handling
What the DecisionHypervisor™ platform receives, generates, and retains — determined by the integration, policy, deployment mode, and customer configuration.
DecisionHypervisor is designed to minimize the information required to evaluate a proposed action. Actual data received and retained depends on the integration, policy, deployment mode, and customer configuration.
The agent proposes; the DecisionHypervisor platform decides. Only an authorized action reaches the protected tool. Decisions write to the evidence store, and REVIEW_REQUIRED outcomes route to a human reviewer instead of executing.
An authorization request arrives as an Execution Intent: a strictly typed record describing the actor, the proposed action, the target, and the context the applicable policy requires. Unknown or undeclared fields are rejected at the boundary. Integrations declare only the context their policies reference.
Each evaluation produces a Decision Object — the resolution and its basis — and appends to a hash-chained Decision Trace. Where evidence export is configured, a Proof Record bundles the decision, the grant, and the trace for independent verification.
The access-request and contact forms collect name, email, company, role, and use case. Submissions are delivered as transactional email and used only to evaluate and respond to the request.
Plausible provides cookie-less, aggregate site analytics by default; it does not collect IP addresses or personal data. Google Analytics 4 loads only after explicit opt-in through the consent banner, and withdrawing consent stops subsequent measurement.
Text entered into the AI Policy Playground is sent to the Google Gemini API to generate illustrative output. Never enter confidential, proprietary, or personal information. Playground output is non-binding and may be inaccurate.
Form submissions are kept as long as needed to respond to the request and to meet legal obligations. Retention of decision data inside a deployment — intents, Decision Objects, traces — is configured per deployment by the customer.
We do not use your decision data to train models. Decision content in a customer deployment is not used for model training by the DecisionHypervisor platform.
Self-hosted and customer-VPC deployments: decision data stays inside the customer boundary and evaluation resolves locally. Managed services: none are offered today — there is no DecisionHypervisor-operated hosted control plane in service.
Customers decide what context their policies require, configure retention and evidence-export settings in their own deployment, and remain responsible for the lawfulness of the data they submit.
Privacy questions, data requests, and subprocessor inquiries are handled by the privacy contact.
privacy@decisionhypervisor.com →