Legal

Privacy & Terms

We believe in transparency. Read how TRINOVION handles your data and the terms governing use of our AGI platform.

Last updated: June 3, 2026  ·  Effective: January 1, 2026
1

Information We Collect

ARX1 collects the minimum data necessary to operate our AI-powered DevOps intelligence platform. We collect:

  • Account data — email address, hashed password, organization name, and role when you create an account.
  • Deployment data — repository metadata, deployment configurations, PRR check results, and Zero Trust scores submitted through the platform.
  • Usage data — agent invocation logs, dashboard activity, API call timestamps, and feature interaction telemetry.
  • Technical data — IP address, browser type, operating system, and session tokens used for authentication and security.
  • Communications — messages sent via the enterprise contact form or support channels.

We do not collect source code content, database credentials, secret keys, or any sensitive environment variables. Our agents analyze structural metadata only.

2

How We Use Your Information

Your data is used exclusively to deliver and improve the TRINOVION platform:

  • Service delivery — running PRR assessments, Zero Trust evaluations, DB safety checks, and generating deployment intelligence reports.
  • Security — detecting anomalous access patterns, enforcing Zero Trust policies, and maintaining audit trails for compliance.
  • Platform improvement — training our pattern-learning models on anonymized, aggregated deployment outcomes (opt-out available for Enterprise plans).
  • Communication — sending deployment status notifications, security alerts, and product updates (unsubscribe at any time).
  • Legal compliance — maintaining records required by applicable laws including HIPAA, SOC 2, and GDPR where applicable.

We never sell your data to third parties. We never use your deployment data to train models for competitors. Your infrastructure information belongs to you.

3

Data Storage & Security

All TRINOVION data is stored in Supabase (PostgreSQL) infrastructure hosted in the EU-West region by default, with US-East available for Enterprise customers requiring data residency.

Data TypeStorage LocationEncryptionRetention
Account credentialsSupabase Authbcrypt + AES-256Until account deletion
Deployment recordsSupabase PostgresAES-256 at rest24 months
Audit logsSupabase PostgresAES-256 at rest7 years (compliance)
Session tokensBrowser localStorageJWT + TLS in transit24 hours
Threat eventsSupabase PostgresAES-256 at rest12 months

All data in transit is protected by TLS 1.3. Our infrastructure undergoes quarterly penetration testing. We maintain SOC 2 Type II compliance and are pursuing ISO 27001 certification.

4

Third-Party Services

TRINOVION integrates with the following third-party services, each with their own privacy practices:

  • Supabase — database and authentication infrastructure. Privacy policy.
  • Railway — backend API hosting. Privacy policy.
  • Anthropic Claude API — AI model inference for agent intelligence. Prompts are not stored by Anthropic for training without consent. Privacy policy.
  • GitHub — repository metadata access via OAuth (read-only, with your explicit authorization). Privacy policy.
  • Google Fonts — font delivery via CDN. May log IP addresses per Google's standard practices.

We do not share your personal data with any third party beyond what is necessary to operate these integrations. We do not use advertising networks or analytics trackers.

5

Data Retention

We retain data only as long as needed for the stated purpose or as required by law:

  • Active account data — retained for the lifetime of your account plus 30 days after deletion request.
  • Deployment records — retained for 24 months from creation date, configurable to 90 days on Starter plans.
  • Audit logs — retained for 7 years to meet financial and healthcare compliance requirements (SOX, HIPAA).
  • Deleted account data — purged within 30 days of account deletion, except audit logs retained for compliance.
  • Backup data — encrypted backups are deleted within 90 days of the source data deletion.

Enterprise customers may request custom retention schedules. Contact privacy@trinovion.ai for data retention agreements.

6

Your Rights (GDPR & CCPA)

Depending on your location, you have specific rights regarding your personal data. TRINOVION honors all applicable rights under GDPR (EU/UK) and CCPA (California):

  • Right to access — request a copy of all personal data we hold about you. We respond within 30 days.
  • Right to rectification — correct inaccurate or incomplete data in your account settings or by contacting us.
  • Right to erasure — request deletion of your account and associated data (subject to legal retention requirements).
  • Right to portability — export your deployment data, audit logs, and account information in JSON or CSV format from the dashboard.
  • Right to object — opt out of model training on your data at any time via account settings.
  • Right to restrict processing — request that we limit how we use your data during a dispute.

To exercise any of these rights, contact privacy@trinovion.ai. EU residents may also lodge a complaint with their local Data Protection Authority.

CCPA notice: TRINOVION does not sell personal information. California residents may still submit a "Do Not Sell My Information" request at privacy@trinovion.ai and we will confirm our non-sale status in writing.

7

Cookies & Local Storage

TRINOVION uses minimal browser storage:

NameTypePurposeDuration
trinovion_tokenlocalStorageAuthentication session tokenSession / 24h
trinovion_userlocalStorageCached user profile for dashboardSession
sb-sessionlocalStorageSupabase auth session (set by Supabase SDK)1 hour (auto-refresh)

We do not use third-party cookies, advertising cookies, or cross-site tracking. No cookie consent banner is required as we only use strictly necessary storage.

8

Contact & Data Protection Officer

For all privacy-related inquiries, data subject requests, or to report a security concern:

We acknowledge all privacy requests within 72 hours and respond fully within 30 calendar days. For urgent security issues, we target a 24-hour acknowledgment.

This Privacy Policy may be updated to reflect changes in our practices or applicable law. Material changes will be communicated by email to registered users at least 30 days in advance.

1

Acceptance of Terms

By accessing or using ARX1 ("the Service"), you agree to be bound by these Terms of Service ("Terms"). If you are using the Service on behalf of an organization, you represent that you have authority to bind that organization to these Terms.

These Terms constitute a legally binding agreement between you (or your organization) and ARX1, Inc. ("TRINOVION", "we", "us"). If you do not agree to these Terms, do not use the Service.

These Terms were last updated June 3, 2026. Continued use of the Service after updates constitutes acceptance of the revised Terms. We will notify registered users of material changes by email at least 30 days in advance.

2

Service Description

ARX1 is an autonomous DevOps intelligence platform that provides:

  • Production Readiness Review (PRR) — automated assessment of deployment readiness across 9 industry verticals using 27 AI agents.
  • Zero Trust Security evaluation — three-tier (Foundation / Advanced / Optimized) continuous security posture assessment.
  • Database Safety Layer — pre-migration analysis, backup verification, and rollback planning for database operations.
  • Audit & Compliance — immutable audit trail generation for SOC 2, HIPAA, SOX, and GDPR compliance requirements.
  • Threat Intelligence — real-time detection and blocking of supply chain attacks, prompt injection, and privilege escalation attempts.

The Service is provided as software-as-a-service (SaaS). We reserve the right to modify, suspend, or discontinue features with reasonable notice.

3

User Obligations

You agree to use the Service only for lawful purposes and in accordance with these Terms. You must not:

  • Use the Service to assess systems you do not own or have explicit written authorization to test.
  • Attempt to reverse-engineer, decompile, or extract the underlying AI models or proprietary algorithms.
  • Use the Service to train competing AI systems or benchmark against TRINOVION without written consent.
  • Share access credentials or API keys with unauthorized parties.
  • Submit false, misleading, or synthetic deployment data intended to manipulate PRR or ZT scores.
  • Interfere with the Service's infrastructure, introduce malware, or conduct denial-of-service attacks.
  • Use the Service in regulated industries (healthcare, finance, defense) without ensuring compliance with applicable sector-specific laws.

Violation of these obligations may result in immediate account suspension and legal action where warranted.

4

Service Level Agreement (SLA)

TRINOVION commits to the following service levels:

PlanUptime SLASupport ResponseIncident Response
Starter FREE95% monthlyCommunity forumBest effort
Pro $99/mo99% monthly48h business hours4h for P1
Enterprise Custom99.9% monthly4h / 24×71h for P1

Uptime is measured as the percentage of minutes in a calendar month during which the API and dashboard are available. Scheduled maintenance windows (communicated 72h in advance) are excluded from uptime calculations.

SLA credits are the sole remedy for uptime failures: 10% monthly bill credit per full percentage point below SLA, up to 30% of monthly fees.

5

Limitation of Liability

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE". TO THE MAXIMUM EXTENT PERMITTED BY LAW:

  • TRINOVION's total liability for any claim arising from use of the Service is limited to the fees paid by you in the 12 months preceding the claim.
  • TRINOVION is not liable for indirect, incidental, consequential, punitive, or special damages, including but not limited to lost profits, data loss, or business interruption.
  • PRR and Zero Trust scores are advisory. Deployment decisions remain the sole responsibility of the customer. TRINOVION does not guarantee that passing a PRR assessment means a deployment will succeed without incident.
  • TRINOVION is not responsible for third-party service failures (Supabase, Railway, Anthropic, GitHub) that affect the Service's availability.

Nothing in these Terms limits liability for gross negligence, willful misconduct, fraud, or death/personal injury caused by our negligence.

6

Intellectual Property

Our IP: The TRINOVION platform, including all software, AI models, algorithms, agent logic, UI designs, brand assets, and documentation, is the exclusive property of ARX1, Inc., protected by copyright, trade secret, and patent laws.

Your IP: You retain all rights to your deployment data, configurations, and any content you submit through the Service. You grant TRINOVION a limited, non-exclusive license to process your data solely to provide the Service.

Feedback: If you provide suggestions, bug reports, or feature requests, you grant TRINOVION a royalty-free, worldwide license to use that feedback to improve the Service without compensation or attribution obligation.

Open Source: Portions of the platform may use open-source components. See our GitHub repository for license attributions.

7

Termination

By you: You may terminate your account at any time by deleting it in account settings or emailing support@trinovion.ai. Paid subscriptions are cancelled at the end of the current billing period; no pro-rata refunds are issued.

By us: We may suspend or terminate your account immediately if:

  • You materially breach these Terms and fail to cure within 10 days of written notice.
  • We are required to do so by law or court order.
  • We reasonably believe your use poses a security risk to the Service or other users.
  • You fail to pay fees due for more than 30 days after the due date.

Upon termination, your right to use the Service ceases immediately. Data export is available for 30 days post-termination, after which data is deleted per our retention policy.

8

Governing Law & Dispute Resolution

These Terms are governed by the laws of the State of California, USA, without regard to conflict-of-law principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

Informal resolution: Before initiating formal proceedings, both parties agree to attempt good-faith resolution for at least 30 days. Contact legal@trinovion.ai.

Arbitration: Any unresolved dispute shall be settled by binding arbitration under the JAMS Streamlined Rules in San Francisco, California. Class action waiver applies — disputes must be brought individually.

Injunctive relief: Either party may seek emergency injunctive relief in any court of competent jurisdiction to prevent irreparable harm pending arbitration.

EU/UK users: Nothing in this section prevents EU or UK consumers from bringing claims in their local courts or before applicable dispute resolution bodies under mandatory consumer protection laws.

For all legal notices: legal@trinovion.ai  ·  ARX1, Inc., Legal Department, San Francisco, CA 94105, USA.