Skip to content
SuperAlign Surface
Esc
navigateopen⌘Jpreview
On this page

Data handling

What Surface collects, what it does not, how long it keeps it, and how organizations are kept apart.

What is collected

Facts about software on each laptop:

  • Which AI tools exist, their version, where they are installed, and how they connect to each other
  • Which policies each tool breaks
  • The laptop’s name, operating system, hardware summary, scanner version, and the person using it

Conversation text is collected only when you turn on a prompt collector.

What is not collected

  • The content of files the scanner looks at. Skill and memory files are reduced to metadata before anything is sent.
  • Passwords found in configuration files. They are reported as a finding, never as the password itself.

How long data is kept

Data Kept for
Sessions 30 days, unless stored in your own S3 or Splunk
Inventory and audit history The life of the organization
A laptop’s credential Disabled after 60 days without contact, deleted after 90

Keeping organizations apart

Every record is tagged with your Organization ID and can only be read within it. Credentials you save for extensions are encrypted and tied to your organization.

In transit and at rest

All traffic between laptops, the console, and SuperAlign is encrypted. A laptop’s credential is stored hashed on the server, so it cannot be read back. Only owners, admins, and viewers can open a transcript, and every opening is written to the audit log.

Was this page helpful?