Join the waitlist

Privacy policy

Effective July 22, 2026

Alectura Labs Pty Ltd ("Alectura," "we," "us," or "our") operates alecturalabs.com and the Alectura platform, an AI Detection & Response (AIDR) service made up of an endpoint agent and a web dashboard that give security and IT teams visibility into how their organization uses AI tools, and let them enforce policy over that usage. This policy explains what personal information we collect, why, and the choices available to you. It applies to visitors of our website, to people who use our dashboard on behalf of a customer, and, because of how the product works, to the employees of our customers whose devices run the Alectura agent.

If you're an employee whose company has deployed Alectura, the company (not Alectura Labs) controls how that deployment is configured and is the right first point of contact about it (see "Our role" below).

Information we collect

Site and waitlist data. If you browse alecturalabs.com or join the waitlist, we collect the email address and any other details you submit, the page you submitted from, and standard web analytics (pages viewed, referrer, approximate region) via Google Analytics. We use Sentry to capture error reports if something on the site breaks.

Account and billing data. If your organization becomes a customer, we collect the name, work email, and role of each person your organization invites to the dashboard, authentication data via our identity provider (Stytch), and billing contact and payment details for invoicing.

Device and diagnostic data. The Alectura agent, once installed on a device, reports device identifiers (hostname, OS version, hardware identifiers), agent version, installation and heartbeat status, and diagnostic/error logs needed to keep the agent running and show the device's status in the dashboard.

AI traffic data. This is the core of the product, so we're specific about it. For AI endpoints in Alectura's "deep capture" set (currently Anthropic's api.anthropic.com and claude.ai), the agent's local proxy inspects and can capture prompt content, tool calls, and MCP traffic passing between the device and that endpoint, so the dashboard can show activity and guardrail policies can act on it. For other known AI domains (e.g. OpenAI, Cursor, Copilot, Gemini, Perplexity), the agent logs only the domain, device, and timestamp. That traffic is tunneled through encrypted and never decrypted or read. Certificate-pinned applications can't be inspected at all; they're counted but pass through untouched. We refer to all of this, collectively, as "Service Data."

Our role: who controls what

For site and waitlist data, and account and billing data, Alectura Labs is the controller. We decide why and how that data is processed, as described in this policy.

For Service Data (device, diagnostic, and AI traffic data captured from a customer's fleet), Alectura Labs acts as a processor on behalf of our customer, who is the controller. Our customer decides which devices run the agent, which policies apply, who on their team can see captured content, and how long it's retained. If you're an employee affected by a company's Alectura deployment and have questions about what's captured or why, your employer is best placed to answer. We act on their instructions and don't use Service Data for our own purposes beyond providing and improving the service.

How we use information

We use site and waitlist data to run the site, respond to inquiries, and, for waitlist signups, to contact people about early access and product updates. We use account and billing data to provide the dashboard, authenticate users, communicate about the service, and invoice. We process Service Data to display device and activity status in the dashboard, evaluate and enforce the guardrail policies our customer has configured, generate alerts to the destinations our customer has configured (e.g. their own Slack or PagerDuty), and maintain and improve the reliability of the agent and proxy. We don't use captured AI traffic content to train models, and we don't sell personal information or share it with third parties for their own marketing.

How we share information

Infrastructure providers that host the service and store data on our behalf, currently AWS (data is hosted in the US; see "International data transfers" below).

Sub-processors we use to operate the service: Stytch (authentication), and, for the marketing site only, Google Analytics and Sentry.

Your own configured integrations. If a customer connects an alert destination (Slack, PagerDuty, Datadog, or a custom webhook), event metadata is sent there under that customer's control. We don't add destinations on a customer's behalf.

Legal and safety. If required by law, legal process, or to protect the rights, property, or safety of Alectura, our customers, or others.

Business transfers. If Alectura is involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to the commitments in this policy.

We don't sell personal information.

Data retention

Site and waitlist data is kept for as long as needed for the purpose it was collected, or until you ask us to delete it. Account and billing data is kept for the life of the customer relationship and as required for tax, accounting, or legal purposes afterward. Service Data retention (including captured AI traffic content) is configurable by each customer and set out in that customer's order form or dashboard settings; absent a customer-specific setting, we apply a default retention period disclosed to the customer at signup.

Security

We use encryption in transit and at rest, access controls scoped to least privilege, and tenant isolation at the database layer (row-level security) so one customer's data is never visible to another. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.

Your rights and choices

Depending on where you're located, you may have the right to access, correct, export, or delete personal information we hold about you, and to object to or restrict certain processing. To exercise these rights over site or waitlist data, or account data where you're the account holder, contact us at hello@alecturalabs.com. For Service Data captured through a customer's deployment, we'll typically need to route the request through that customer, since they control the deployment and its settings. We'll help facilitate that if you reach out to us instead.

International data transfers

Our infrastructure is currently hosted in the United States. If you're located outside the US, your information will be transferred to and processed in the US, which may have different data protection laws than your country. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.

Children's privacy

Alectura is a business product and our website is not directed at children. We don't knowingly collect personal information from anyone under 16.

Changes to this policy

We'll update the effective date above when we make changes, and post the updated policy here. If a change is material, we'll take reasonable steps to let customers and waitlist subscribers know.

Contact us

Questions about this policy or how we handle your information: hello@alecturalabs.com.