Legal · Privacy

Privacy Policy

kolm.ai issues cryptographically signed, offline-verifiable evidence reports for AI application security reviews. This policy explains, in plain terms, what personal and organisational data we collect to deliver that service, why we collect it, how long we keep it, who we share it with, and how you exercise your rights under GDPR, CCPA, and equivalent laws.

What this covers, in plain language

We collect only what running the service needs: your account and billing contact, the redacted material you submit for an audit, and basic request logs. We do not sell your data, use it to train any model, or buy data about you from brokers. Audit material is deleted within 90 days of report delivery. You can ask to access, correct, or delete your data at dev@kolm.ai. The sections below are the binding detail.

We will respond within 2 business days.

Compiler-ready Signed artifacts Sample report

Caveats: Scope is contractual. Permission posture, redaction and audit-trail integrity are assessed. Injection is tested and reported, not warranted.