Legal
Privacy Policy
How we handle your data. Short version: we don't want your source code, we don't train on your traces, and we don't sell anything. Last updated September 30, 2026.
What we collect
For website visitors: nothing beyond privacy-preserving analytics with no cookies. For an assessment: the artefacts you send — a firewall configuration export, flow records, and your segmentation matrix. Plus the ordinary contact details needed to run the engagement.
What an assessment involves
Manual assessments do not use customer accounts or a hosted assessment workspace. Guardra is one person performing a manual analysis. Your files are handled on an encrypted device, used only for your engagement, and never used to train anything or benchmark anyone else.
Local browser assessment tools
The local firewall rule reviewer and local hospital assessment tool process policy, inventory, access requirements and review actions in your browser tab. These local tools do not submit the contents to Guardra, store them on a server, or save them in browser storage. Reloading or clearing the local workspace removes the input and findings. Downloaded assessments, templates and reports remain wherever you save them; assessment files and reports include the input data and saved review actions. You can reopen a downloaded assessment to continue locally. The pages still load normal website assets and any configured page analytics. The separate team workspace sends data to the server only when you explicitly save to your hospital.
Optional team workspace
Creating or joining a team workspace stores your account email, hospital membership and a salted password hash on the configured Guardra server. Choosing Save to hospital sends your assessment and saved review actions to that server. Clinical device, exposure and incident records are also sent when you explicitly save their register; its latest 50 encrypted snapshots are retained, with older snapshots removed from the application database on subsequent saves. Downloaded registers and briefings contain the recorded infrastructure and incident details. Assessment revisions are encrypted by the application; account and audit metadata are stored separately. Connector credentials submit source observations to an encrypted intake queue for administrator review. Connector credentials and retry identifiers are hashed; connector names, timestamps, counts, receipt statuses and audit metadata are stored separately. Up to 50 pending batches and the latest 50 reviewed payloads are retained; older reviewed payloads are removed while receipt metadata remains. An administrator may authorize a connector to send data on an ongoing basis. Sessions and invitations use hashed tokens. Optional two-factor authentication stores encrypted authenticator secrets and hashes of single-use recovery codes. Security changes and recovery-code use create audit events without recording the codes. Downloaded recovery codes remain wherever you save them. Administrators can remove members and delete assessments and their saved revisions. Audit event metadata remains. Assessment revisions have no automatic retention expiry; clinical register snapshot retention is described above. No automatic backup deletion is implemented. The installation operator controls hosting, backups and retention. Team saves are separate from the manual assessment service and its handling terms.
Flow records are metadata
The engagement is scoped to metadata — addresses, ports, direction, volume, timing — and structured so PHI is not required. Note that HHS de-identification guidance lists IP addresses and device identifiers among its identifiers, so the absence of packet payload does not by itself mean an export is free of PHI; that depends on content and context. If an export could contain payload or identifiers, say so and we scope it out or run the analysis inside your environment instead.
Where manual assessment files live
Encrypted at rest on a device under our control, or inside your own VDI where nothing leaves your environment at all. No cloud processing of customer artefacts, no third-party analysis service, and no copies beyond what the engagement requires.
Manual assessment retention and deletion
Artefacts are deleted within 30 days of the report being delivered, or immediately on written request. Written confirmation of deletion is provided. The report itself is yours; our copy is deleted on the same schedule unless you ask us to keep it.
What we never do
Publish, reuse or reference your findings without written permission. Share artefacts with anyone. Use one engagement's material to inform another. Sell personal data.
Your rights
UK GDPR, EU GDPR and CCPA: access, rectification, deletion, portability, restriction. Write to privacy@guardra.ai — response within 30 days.
Subprocessors
Site hosting, contact-form delivery, and cookieless analytics — listed in the Trust Centre. Manual assessment handling is separately agreed. Optional team-workspace storage runs on the configured application host; its operator controls the storage location and backups.