Entity specs, ISO/IEC 42001 & SOC 2 certifications
Data governance, zero-retention & SMS compliance
Master services terms, IP allocation & licensing
Privacy Policy & Data Governance
Executive Zero-Retention Covenant
Adept operates under a legally binding zero-retention architecture. We do not retain, store, inspect, or aggregate client proprietary source code, internal model weights, vector embeddings, synthetic evaluation artifacts, or prompt payloads to train foundation models, calibrate public baselines, or construct third-party datasets.
1.0 Scope & Corporate Applicability
This Corporate Privacy Policy & Data Governance Specification (“Policy”) governs all processing of enterprise technical telemetry, commercial inquiry metadata, and personal data by Adept (“Company,” “we,” “us,” or “our”). This applies to our public web properties (heyadept.com), proprietary software platforms (including the Adept Mayar AI Evaluation Engine and Adept Kawas Sub-15ms Prompt Firewall), API gateways, and contracted professional services (Technical Assessments, Red-Teaming, Architecture Advisory, and Embedded Engineering Residencies).
When clients contract for enterprise engagements, bilateral Statements of Work (SOWs), Master Services Agreements (MSAs), and Data Processing Addenda (DPAs) supersede this general web policy where specific bespoke technical confidentiality or data sovereignty provisions apply.
2.0 Information Collection Standards & Non-Retention
Adept enforces strict data minimization protocols. We collect and process only the minimal information strictly required to maintain network integrity, execute contracted validation suites, and service enterprise accounts:
3.0 Telephony & SMS Compliance Policy (TCPA / CTIA / 10DLC)
If you submit your telephone number through our contact channels and explicitly check the SMS consent checkbox, Adept may transmit automated or direct SMS communications regarding technical assessment schedules, security incident notifications, and status alerts.
Mobile phone numbers and SMS consent records are strictly confidential. We do not sell, rent, license, or share mobile numbers or opt-in verification logs with any third parties, affiliates, data brokers, or marketing partners for promotional purposes.
4.0 Platform Data Processing: Mayar & Kawas Architecture
Mayar executes automated synthetic evaluation test suites within ephemeral, isolated compute sandboxes. When an evaluation run terminates, memory caches are flushed. Test artifacts are persisted exclusively into client-designated repositories or private S3/GCS buckets.
Kawas inspects prompt token streams in volatile sub-15ms memory matrices to detect jailbreaks, prompt injection, and semantic boundary violations. Unencrypted prompt payloads are never written to permanent disk without explicit client debug telemetry flags.
5.0 Subprocessors & Data Sovereignty
Adept maintains sovereign, enterprise-grade cloud compute instances located exclusively in Tier-4 SOC 2 certified data centers within the United States and European Union. We do not utilize third-party consumer LLM APIs to process confidential client code or telemetry without explicit client authorization and dedicated zero-retention enterprise enterprise agreements.
All infrastructure subprocessors undergo rigorous annual security auditing and are bound by Data Processing Addenda adhering to standard contractual clauses (SCCs).
6.0 Enterprise Security Controls & Infrastructure
Adept enforces institutional-grade information security controls aligned with SOC 2 Type II, ISO/IEC 27001, and ISO/IEC 42001 standards:
- Encryption in Transit: TLS 1.3 enforced across all ingress endpoints with strict HSTS, Perfect Forward Secrecy, and modern cipher suites.
- Encryption at Rest: AES-256-GCM hardware-accelerated encryption for all databases, volume storage, and audit logs.
- Access Governance: Strict Role-Based Access Control (RBAC), mandatory hardware FIDO2 MFA, and automated session invalidation.
- Confidential Computing: Dedicated VPC peering and AWS Nitro / GCP Confidential Enclaves available for regulated enterprise tiers.
7.0 Global Privacy Rights (GDPR / CCPA / CPRA / UK GDPR)
Depending on your jurisdiction, you possess statutory rights regarding your personal information, including the right to access, rectify, port, or erase your records, and the right to object to processing.
Adept does not sell, rent, or cross-contextualize personal data as defined under the California Consumer Privacy Act (CCPA) or California Privacy Rights Act (CPRA). To exercise statutory privacy rights, email our Data Protection Officer at connect@heyadept.com with the subject “Privacy Rights Request”.
8.0 Incident Response & Security Notification Protocol
In the event of a confirmed cybersecurity incident impacting client assessment telemetry or operational services, Adept maintains a continuous 24/7 Computer Security Incident Response Team (CSIRT). We adhere to a maximum 72-hour formal customer breach notification window in compliance with GDPR Article 33 and applicable US state data breach notification statutes.
9.0 Contact & Data Protection Officer
For legal notices, data processing addenda requests, or security inquiries: