Trust center
What we run today, what it stores, and how long we keep it. We'll update this page as each module ships.
What's live
This website, Emissar's public A2A agent, and early access signup. None of the product modules are in production yet; their status is on the product page.
Data we store
| Source | What | Where | Retention |
|---|---|---|---|
| Early access form | Name, email, company, role, which side you're on, and what you wrote | Cloudflare D1 | Deleted after 24 months, or sooner on request |
| Messages to our A2A agent | Message content, task ids, the calling agent's name or user agent, approximate country | Cloudflare D1 | Deleted after 90 days |
| Early access sent over A2A | The same fields as the form, plus the calling agent's name | Cloudflare D1 | Deleted after 24 months, or sooner on request |
| Every request | IP address and request details, processed by Cloudflare to deliver and protect the site | Cloudflare | Per Cloudflare's policies |
Deletion is automated: a scheduled job removes records past these limits every day. The site sets no advertising or tracking cookies.
Subprocessors
- Cloudflare, Inc.
- Hosting, content delivery, database (D1), security, and privacy-preserving analytics.
We'll add any new subprocessor here before it handles your data.
Certifications
Emissar has no third-party security certifications yet. When an audit starts, we'll list it here with its scope and dates.
Security practices in place
- The site and agent are served only over HTTPS.
- Form and agent inputs are validated, size-limited, and stored with parameterized queries.
- The public agent can't list tasks, so one caller can't read another caller's requests without the task id.
- The public agent answers only from published site content.
Report a security issue
Email security@emissar.ai. Our security.txt has the details. Good-faith research that follows our acceptable use policy is welcome.