SysVitalix Privacy Policy

Effective Date: 7/2/2026

1. Introduction

This Privacy Policy explains how SysVitalix ("we", "us", "our") collects, uses, and discloses information about you when you use our System Integrity Validator platform, including the SysVitalix web dashboard, API, and related services (collectively, the "Services"). We follow a "privacy by design" approach to ensure secure, multi-tenant isolation of your Software Development Life Cycle (SDLC) data.

2. Information We Collect

We collect information you provide directly to us, as well as data automatically synchronized from your connected tools:

  • Account & Identity Data: Names, email addresses, and encrypted passwords. If authenticating via OTP, we process verification codes.
  • SDLC & Integration Data: When you connect external providers (e.g., Atlassian Jira, Azure DevOps, GitHub) via OAuth, we ingest Work Items, User Stories, architecture documents (HLD/LLD), and repository structures.
  • System Telemetry: We collect application logs, error traces, and usage patterns to maintain our Service level agreements and system observability.

3. How We Use Information

We use your information exclusively to provide and improve the SysVitalix platform. Specifically, we use your data to:

  • Execute our proprietary RAG Pipeline to score Story Quality and Architecture Health Indexes.
  • Provide deterministic matching between your required capabilities and deployed components.
  • Maintain Strict Multi-Tenancy by isolating all ingested telemetry and evidence payloads.
  • Communicate important service updates, security alerts, and support responses.

4. How We Store and Secure Information

Data is segmented via strict cryptographic boundaries per `tenantId` in our PostgreSQL databases and immutable JSON evidence storage (Filesystem/S3). OAuth credentials and webhook secrets are encrypted at rest using AES-256. We utilize Role-Based Access Control (RBAC) to ensure users can only access data within authorized workspaces.

5. Data Retention & Deletion

Our data governance policy mandates hard deletion for off-boarding. When a Tenant Owner deletes a workspace, all associated integrations, encrypted credentials, onboarding states, and raw SDLC data are permanently and irreversibly purged. User account deletions cascade to remove refresh tokens, while preserving anonymous audit log trails to satisfy compliance requirements.

6. Vendor Disclosures

SysVitalix does not sell your SDLC artifacts. We share data solely with trusted sub-processors necessary to host our infrastructure (e.g., AWS) and execute our Large Language Model (LLM) analytical pipelines. All data processed by sub-processors is bound by strict confidentiality and localized computing addendums.

7. Contact Us

If you have any questions or requests regarding your personal data or our security practices, please contact our privacy team through the Contact form.