Privacy Policy & Telemetry Isolation Standards

Effective Date: September 1, 2026. This policy governs how Syntrace Inc. ("Syntrace", "we", "us", or "our") processes, protects, and isolates enterprise telemetry, source code syntax trees, and infrastructure cluster data.

1. The Zero-Model-Training Guarantee

Binding Enterprise Clause: Syntrace explicitly does NOT pool, store, aggregate, or use customer proprietary source code, Abstract Syntax Tree (AST) representations, git commit histories, cluster network topologies, or runtime eBPF socket traces to train, fine-tune, or calibrate generalized public foundation models or multi-tenant machine learning classifiers.

Your application source code and infrastructure metrics remain strictly confined to your isolated tenant control plane or private on-premises Kubernetes cluster. Algorithmic correlation models execute deterministically within your cryptographic enclave and are never exposed to external entities.

2. Ephemeral AST Parsing & Zero Code Persistence

When Syntrace correlates runtime socket contention against merged pull requests:

  • In-Memory Processing: Git diffs and syntax trees are parsed inside ephemeral, volatile container memory enclaves.
  • Immediate Syntax Eviction: Once root-cause correlation scores are computed, the source code AST is purged from memory. Syntrace does not store raw application source code in permanent databases.
  • Metadata Minimization: The platform persists only the isolated commit hash (e.g. c4b91f0), the offending filename, and the specific line index required to generate the rollback PR.

3. Cryptographic Standards & In-Kernel Safety

All telemetry transmitted between worker node eBPF daemons and the Syntrace control plane is enforced using Transport Layer Security (TLS 1.3) with ChaCha20-Poly1305 and AES-256-GCM cipher suites. All data at rest within customer-dedicated datastores is encrypted using AES-256 with tenant-specific hardware security keys (AWS KMS / GCP Cloud KMS / HashiCorp Vault).

4. Global Compliance Rights: GDPR & CCPA/CPRA

For enterprise customers and data controllers subject to the European Union GDPR, UK Data Protection Act, and California Consumer Privacy Act:

  • Right of Access & Audit Logs: Administrators may export all historical incident remediation logs, rollback payloads, and eBPF event traces in structured JSON format at any time.
  • Right to Complete Tenant Purge: Upon contract completion or formal notice, all customer telemetry records, sandbox images, and tenant configuration files are permanently erased within thirty (30) days in accordance with DoD 5220.22-M / NIST SP 800-88 guidelines.
  • Zero Third-Party Sale: Syntrace has never sold, licensed, or shared customer infrastructure metrics or user records with third-party brokers or advertisers.

5. Security Reporting & Compliance Office

For privacy inquiries, to execute a mutual Data Processing Addendum (DPA), or to request SOC 2 Type II compliance reports, please contact our security team:

Syntrace Inc. Office of Information Security
Direct Compliance Desk: privacy@syntrace.online
Vulnerability Reporting: security@syntrace.online