Data handling
What Surface collects, what it does not, how long it keeps it, and how organizations are kept apart.
What is collected
Facts about software on each laptop:
- Which AI tools exist, their version, where they are installed, and how they connect to each other
- Which policies each tool breaks
- The laptop’s name, operating system, hardware summary, scanner version, and the person using it
Conversation text is collected only when you turn on a prompt collector.
What is not collected
- The content of files the scanner looks at. Skill and memory files are reduced to metadata before anything is sent.
- Passwords found in configuration files. They are reported as a finding, never as the password itself.
How long data is kept
| Data | Kept for |
|---|---|
| Sessions | 30 days, unless stored in your own S3 or Splunk |
| Inventory and audit history | The life of the organization |
| A laptop’s credential | Disabled after 60 days without contact, deleted after 90 |
Keeping organizations apart
Every record is tagged with your Organization ID and can only be read within it. Credentials you save for extensions are encrypted and tied to your organization.
In transit and at rest
All traffic between laptops, the console, and SuperAlign is encrypted. A laptop’s credential is stored hashed on the server, so it cannot be read back. Only owners, admins, and viewers can open a transcript, and every opening is written to the audit log.