How We Build
Software Factory
Flightcrew Agents
  • Atlas States what the control has to do
  • Flightplan Orders the changes for review
  • Scout Finds the smallest version that works
  • Pilot Flies the Flightcrew protocol
  • Copilot Runs the control against its scenarios
  • Debrief Rewrites what came back wrong
Agent Harness Security
  • AI Traffic Control Prompts and tool calls checked inline
  • Claude-Tools A hardened baseline for Claude Code
  • Preflight-Skills Multi-harness development skills
  • Codex-Tools not yet released
  • Antigravity Tools not yet released
Meet the OSS Family
About Us Contact
How We BuildSoftware FactoryFlightcrewAI-TCAbout UsContact
Back to home

Privacy Policy

Last updated: June 29, 2026

Contents

  1. Overview
  2. How AI-TC handles your data
  3. What we collect
  4. What we do not collect
  5. How we use information
  6. Sharing
  7. Security and retention
  8. Your rights
  9. Changes and contact

1. Overview

Also Known As, Inc. (“AKA Security”, “we”, “our”) builds AI Traffic Control (AI-TC), an open-source security engine for AI agents, and operates the website at akasecurity.io. This policy describes the personal information we collect, how we use it, and the choices you have. It applies to visitors to our website, prospects who contact us, and customers under a commercial engagement.

The short version: AI-TC runs on your own machine. The prompts and tool calls your agents make never travel to us. The information we do collect is what you give us when you contact us or sign a commercial agreement, plus standard website analytics. We do not sell it.

2. How AI-TC handles your data

AI-TC is the open-source security engine we publish on GitHub. It runs on the same machine where your AI agent runs. Every prompt and tool call your agent makes is scanned against its detection rules locally, and the warn, redact, or block decision is made on your machine.

In the default local deployment, we do not receive your prompts, your tool calls, your findings, or any other runtime data from AI-TC. There is no telemetry pipe back to AKA Security. AI-TC contains no phone-home. Findings stay in a local store on your machine.

If you build AI-TC from source, you can read the code on GitHub and confirm the detection path makes no network calls of its own.

The optional setup calibration

AI-TC has one feature that sends data off your machine, and it stays off until you turn it on. When you first set AI-TC up, it offers to look over your agent's recent history so it can tune its detection posture to the work you actually do. To tell a real leak from routine noise — a live credential from a test fixture — that step sends what the scan found to the model API to be rated, through the same model provider your agent already uses. What travels is the detected value itself plus a short window of the text around it.

Even here, the data goes to the model provider, not to AKA Security. We do not receive it. This step never runs without your explicit consent, it is asked separately from the consent to read your history, and it is not part of live detection or enforcement.

You can withdraw the consent at any time from the AI-TC dashboard, which stops any future scan. Withdrawing cannot recall data already sent, so if a live credential was among the findings, treat it as exposed and rotate it.

For Enterprise deployments, AKA offers a hosted control plane: rule distribution and fleet reporting run on AKA-managed infrastructure under a separate agreement. Detection and enforcement still run on your machines. Fleet reporting carries finding counts, categories, and severities, never the underlying values, prompts, or payloads. This is separate from our managed-services engagements, where AKA operates AI-TC inside your own environment.

3. What we collect

We collect personal information in three places: visits to our website, requests to contact us, and active commercial engagements. The table below describes each.

Who What we collect Why
Website visitors Pages visited, referrer, browser type, IP address (truncated), country. To understand what the site is used for and improve it.
Prospects (you contact us) Name, work email, organization name, and any message you send. To reply to your inquiry and, if you ask, schedule a meeting.
Customers (signed agreement) Names and contact details of the people working with us, and any information you share with us in the course of an engagement. To deliver the agreed work and meet our legal obligations.
Job candidates Resume, application materials, and anything you tell us in interviews. To evaluate your application.

4. What we do not collect

To be explicit, AKA Security does not collect:

  • Prompts and tool calls made by your agents through AI-TC.
  • The rules or configuration you set for AI-TC.
  • The findings AI-TC records on your machine.
  • Source code, prompts, secrets, or any other content read or written by your agents.
  • Behavioral profiles, advertising identifiers, or cross-site tracking.

5. How we use information

We use the information we collect to:

  • Respond to inquiries and schedule meetings.
  • Deliver and support commercial engagements.
  • Improve our website and product.
  • Send occasional product or company updates, which you can unsubscribe from at any time.
  • Comply with applicable legal obligations.

6. Sharing

We do not sell, rent, or trade your personal information. We share information with a limited set of service providers we use to run the business (for example, our email host, the contact-form provider, and our analytics provider), and only what each provider needs to do its job. These providers are bound by written confidentiality and data-handling obligations.

We may also disclose information if required by law, to enforce our rights, or in connection with a corporate transaction (such as a merger, acquisition, or sale of assets). The acquirer would be bound by this policy.

7. Security and retention

AKA Security is SOC 2 Type II certified and ISO 27001 certified. We maintain technical and organizational controls aligned to those programs, including least-privilege access, encryption of data in transit and at rest, and logging of administrative actions.

We retain personal information for as long as it is needed for the purpose it was collected, then delete or anonymize it. Inquiries that do not lead to a customer relationship are retained for up to 24 months. Customer records are retained for the duration of the engagement and for the period required by tax, accounting, and contractual obligations.

8. Your rights

Depending on your location, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain uses. To exercise any of these rights, write to privacy@akasecurity.io. We will respond within the timeframe required by applicable law.

If you are in the European Economic Area, the United Kingdom, or Switzerland, the legal bases on which we process your information are: your consent, the performance of a contract with you, compliance with a legal obligation, and our legitimate interests in operating and improving the business.

9. Changes and contact

We may update this policy from time to time. When we do, we update the “Last updated” date at the top of the page. Material changes will be flagged on this page or sent to active customers by email.

Questions, requests, or complaints about this policy go to privacy@akasecurity.io or through our contact form.

Forward Deployed Security

Product
FlightcrewAI-TCAI-TC DocsOpen source
Company
How We BuildAboutContactFAQ
Legal
PrivacyTermsMSATrust center
© 2026 Also Known As, Inc.