Trust center

What we run today, what it stores, and how long we keep it. We'll update this page as each module ships.

What's live

This website, Emissar's public A2A agent, and early access signup. None of the product modules are in production yet; their status is on the product page.

Data we store

SourceWhatWhereRetention
Early access formName, email, company, role, which side you're on, and what you wroteCloudflare D1Deleted after 24 months, or sooner on request
Messages to our A2A agentMessage content, task ids, the calling agent's name or user agent, approximate countryCloudflare D1Deleted after 90 days
Early access sent over A2AThe same fields as the form, plus the calling agent's nameCloudflare D1Deleted after 24 months, or sooner on request
Every requestIP address and request details, processed by Cloudflare to deliver and protect the siteCloudflarePer Cloudflare's policies

Deletion is automated: a scheduled job removes records past these limits every day. The site sets no advertising or tracking cookies.

Subprocessors

Cloudflare, Inc.
Hosting, content delivery, database (D1), security, and privacy-preserving analytics.

We'll add any new subprocessor here before it handles your data.

Certifications

Emissar has no third-party security certifications yet. When an audit starts, we'll list it here with its scope and dates.

Security practices in place

  • The site and agent are served only over HTTPS.
  • Form and agent inputs are validated, size-limited, and stored with parameterized queries.
  • The public agent can't list tasks, so one caller can't read another caller's requests without the task id.
  • The public agent answers only from published site content.

Report a security issue

Email security@emissar.ai. Our security.txt has the details. Good-faith research that follows our acceptable use policy is welcome.