Privacy Policy

Effective date: 20 August 2026. AISG is built on a local-first principle: your code stays on your machine.

1. What We Collect

2. Local-First Scanning — Your Code Never Leaves Your Machine

All scans run on your own computer (or your environment) through the AISG worker. What is sent to our cloud service is only findings metadata — never the source code, configuration contents, or secrets themselves. This is a core architectural commitment, not an option.

3. How We Use Data

We do not sell your personal data. We do not use your scan findings to train third-party models.

4. Payment Processing

Payments are processed by Midtrans, a PCI-DSS compliant payment provider. Your payment details are handled under their privacy and security policies. We only receive confirmation of payment status.

5. Data Retention

Account data and scan metadata are retained while your account is active and for a reasonable period afterward for legal and audit purposes. You may request deletion of your account and associated data at any time (see Section 7).

6. Third-Party Services

We use limited third-party services: Midtrans (payments), and optionally Google Sign-In for authentication. Each has its own privacy policy. We do not use advertising trackers on this site.

7. Your Rights

You may request access to, correction of, or deletion of your personal data at any time. To exercise these rights, contact us — we will respond within a reasonable period (typically within 30 days).

8. Contact

Privacy questions or requests: support@aisg.web.id.