Official Legal Document

Privacy Policy

This Privacy Policy explains how Cognispace, LLC collects, uses, stores, and protects information when you use the Material Governance Condition (MGC) platform, APIs, developer tools, and Reference Monitor.

Document ID MGC-POL-001
Version 1.0
Effective Date October 2026
Data Controller Cognispace, LLC
Standard Authority Cognispace Governance Architecture

01. Core Privacy Principles

Cognispace, LLC designs systems with privacy and data minimization as structural constraints. In operating the Material Governance Condition (MGC) Reference Monitor, our posture is guided by three principles:

  • Metadata Exclusivity: We process entity identifiers, cryptographic digests, and lineage edges—not raw underlying proprietary code, datasets, or model weights.
  • Zero Cross-Tenant Leakage: Multi-tenant isolation is enforced at the database kernel level through PostgreSQL Row-Level Security.
  • No Monetization of Customer Data: We do not sell, rent, or monetize customer data, nor do we train generative AI models on customer lineage graphs.

02. Information We Collect

We collect information in three categories:

  • Account Information: Name, work email address, organization name, and billing details provided during registration or subscription management.
  • Cryptographic & Provenance Data: SHA-256 entity digests, W3C PROV-O derivation edges, condition inscription records, and KMS-signed disposition tokens submitted via API or MCP endpoints.
  • Operational Telemetry: API access timestamps, request latency, HTTP status codes, client user agents, and IP addresses used for fraud prevention and system health monitoring.

03. Metadata-Only Processing

Structural Guarantee: MGC evaluates conditions against cryptographic hashes (e.g. urn:sha256:...) and graph topology. At no point does the MGC reference monitor ingest, inspect, or store your private model weights, training corpora text, or source code files.

Your proprietary assets remain in your cloud environments or on-premises storage. Only their cryptographic identifiers and governance conditions interact with our evaluation engine.

04. How We Use Information

We use collected data solely to:

  • Traverse derivation graphs and compute semilattice downward inheritance verdicts.
  • Vend short-lived AWS STS credentials upon verified condition discharge.
  • Maintain cryptographic audit trails for enterprise compliance reporting.
  • Enforce subscription quotas, billing accuracy, and rate limits.
  • Detect and mitigate security threats, API abuse, and unauthorized access attempts.

05. Database Tenant Isolation

All customer provenance graphs and condition states are partitioned by a unique tenant identifier (org_id). We enforce this boundary using PostgreSQL Row-Level Security (RLS) with FORCE ROW LEVEL SECURITY enabled across all tenant-scoped tables. Database roles utilized by the API service lack bypass privileges, preventing accidental cross-tenant data exposure.

06. Third-Party Sharing

We do not share your information with third parties except as strictly necessary to deliver the Services:

  • Infrastructure Providers: Amazon Web Services (AWS) for secure cloud hosting and hardware KMS key management.
  • Payment Processors: Stripe for secure payment processing and subscription billing.
  • Legal Obligations: When required by valid subpoenas, court orders, or applicable law.

07. Data Retention & Deletion

We retain provenance records and audit logs for the duration of your active subscription and as necessary to comply with legal obligations. Upon termination of your account, you may request the deletion of all stored provenance graphs and account metadata by contacting our privacy team.

08. Your Rights (GDPR & CCPA)

Depending on your jurisdiction, you possess the right to:

  • Request access to the personal data we hold about you.
  • Request rectification of inaccurate personal data.
  • Request erasure of your personal data ("right to be forgotten").
  • Object to or restrict certain processing activities.
  • Request data portability in a machine-readable format.

09. Privacy Contact

For privacy inquiries, data subject access requests, or regulatory questions, please contact our Data Protection Officer at:

Cognispace, LLC — Privacy Office
Email: [email protected]
Address: Cognispace, LLC, Legal & Privacy Operations, United States