Last Updated: July 2, 2026
What changed in this version: corrected to accurately describe how our endpoint agent handles data (on-device matching; we do not collect full AI prompts or transcripts), removed advertising/ad-targeting language, tightened how we use data, and aligned our sub-processor list and breach-notification timing with our Data Processing Agreement (DPA).
At Shadow Span Technologies Inc. (the "Company," "Shadow Span," "we," or "us"), we provide a sovereign B2B cybersecurity SaaS platform. This platform delivers our Cloud-Native Application Protection Platform (CNAPP), enterprise account management and billing, and authenticated access to our security services, including endpoint and executive threat intelligence, External Attack Surface Management (EASM), phishing and brand-impersonation detection, supply-chain risk intelligence, AI-usage monitoring, and our Application Security (AppSec) module (SAST, SCA, IaC scanning, and SBOM generation). (Broader data-loss prevention capabilities are under development and offered on an opt-in basis if and when released.)
Two different roles. This Policy explains how we handle personal information for which we are the controller — principally website, account, billing, and marketing data about the people who visit our site and administer our customers' accounts. Where our platform processes personal data on behalf of a customer (for example, data from a customer's endpoints or environment), we act as a processor, and that processing is governed by our Data Processing Agreement (DPA) — not by this Policy. If the two ever conflict for customer data, the DPA controls.
By accessing our website or services, you agree to this Policy. If you have questions, email privacy@shadowspan.com before submitting information.
When you create an account or interact with us, we collect and retain the information you submit and information generated by your use of the website and platform console. This may include:
Identity and contact data: full name, business email, and, where provided, phone number and job title.
Account and billing data: organisation name, account credentials, plan and subscription details, and billing contact information (card and payment data are handled by our payment processor, not stored by us).
Technical and usage data: IP address, device and browser identifiers, operating system, general location derived from IP, locale, timestamps, and console usage/metadata.
We do not disclose personal identifying information without your consent except as set out in this Policy or as required by law.
Where a customer deploys our endpoint agent to its personnel's devices (with the customer's authorization), we process data as that customer's processor, on the customer's instructions and configuration, under the DPA. The agent supports two functions — endpoint management and posture monitoring (Aegis), and AI-usage monitoring — and the DPA describes each as a separate module. For transparency, and because this is central to how our product protects privacy:
Endpoint management data (Aegis). For endpoint management and security-posture monitoring, the agent processes device/endpoint identifiers (hostname, hardware serial, certificate serial), the last-logged-in username, public IP address, installed-software inventory, OS/patch level, and security-posture/compliance status.
Matching happens on the device. For AI-usage monitoring, pattern matching and redaction occur locally on the endpoint. The raw secret value is never transmitted to us.
We do not collect full AI prompts or transcripts. We never receive the full prompt or transcript as a whole, and there is no on-demand full-content retrieval.
Minimized detection records only. Depending on the evidence level the customer selects (SUMMARY, CONTEXT, or REDACTED; default REDACTED), a detection record may include: the pattern type; a short prefix (up to 8 characters); the match length; cryptographic (SHA-256) hashes of the matched line and a surrounding window; a redaction marker; and — at the CONTEXT and REDACTED levels — a small bounded window of adjacent text (default 5 words) that may contain personal data. At the SUMMARY level, no content is collected.
Caps and options. Stored context is capped (≤ 2,048 characters per field; ≤ 10 KB per evidence object). Usernames can be pseudonymized. Deeper detection categories are off by default and consent-gated.
The full description of this processing, the categories of data, and our security measures are in the DPA. A customer that enables employee monitoring is the controller for that activity and is responsible for its lawful basis and employee notices.
To operate and improve the website and platform, we automatically record certain information about your activity, which may include your IP address, operating system, general location, device and browser identifiers, locale, timestamps, system configuration, and interaction metadata.
We use cookies and similar technologies to keep you signed in, remember your preferences, secure the service, and understand how the website and console are used. You can control cookies through your browser settings; disabling some cookies may limit functionality.
We do not use cookies for third-party advertising or to build advertising profiles, and we do not serve targeted advertisements. For questions about our cookies, contact privacy@shadowspan.com.
We use personal information only to:
provide, secure, support, and improve the website and services;
manage accounts, authentication, and billing;
communicate with you about your account, security matters, and service updates;
comply with legal obligations and enforce our terms; and
prevent fraud and protect the rights, property, and safety of our users, the public, and us.
We may create and use aggregated, de-identified data that cannot reasonably be used to identify you or any individual, for internal purposes such as improving our detection and security capabilities. We do not use customer or employee-monitoring data for our own purposes — that data is processed only as described in the DPA and on the customer's instructions.
Where applicable law requires a legal basis, we rely on one or more of: performance of a contract with you; your consent; compliance with a legal obligation; our legitimate interests (not overridden by your rights), such as securing and improving our services; and processing necessary for payment.
To access, correct, or request deletion of your personal information, email privacy@shadowspan.com. We will respond within a reasonable time and in accordance with applicable law. Deleting certain information may require us to close your account. We retain information as long as needed to provide the services and to meet legal, tax, and security obligations, after which we delete or de-identify it.
We store information on industry-standard cloud infrastructure and maintain appropriate technical and organizational measures — including encryption in transit and at rest, tenant isolation, least-privilege access controls, logging, and regular security testing — as described in our DPA. No system can be guaranteed perfectly secure, but we work continuously to protect your information and to meet the security commitments we make to our customers.
Our servers and sub-processors may be located outside Canada, including in the United States. Where personal information is transferred outside Canada or the EEA, we rely on appropriate safeguards, including Standard Contractual Clauses.
Where we act as a processor of customer data, we notify the affected customer without undue delay and, in any event, within 72 hours of becoming aware of a personal data breach affecting their data, as set out in our DPA. Where we are the controller of website or account data, we notify affected users without undue delay where required by applicable law, and provide information to help them respond.
The website and services are intended for business use by adults (18+). We do not knowingly collect information from persons under 18, and will delete any such information that comes to our attention.
We may disclose personal information: (a) to comply with a legal obligation or a lawful request by a public authority; (b) to enforce our agreements or protect the rights, property, or safety of our users, the public, or us, including for fraud prevention; and (c) in connection with a merger, acquisition, or sale of assets, in which case personal data may be among the transferred assets, subject to this Policy.
To operate the website and provide our services, we engage a limited number of sub-processors, each bound by contract to protect personal information and to process it only to provide their service to us. They fall into the following categories:
Cloud hosting, compute, and object storage (United States).
Managed database and authentication (United States).
Content delivery, web application firewall, and DDoS protection (United States).
Rate-limiting cache (United States).
Transactional and alert email delivery (United States).
AI processing for our own product features, e.g., brand/logo analysis and summaries (United States). We store only usage metadata for these features, not prompt or response content.
Alternative AI processing for those product features, where enabled for a customer (United States).
Important: the endpoint agent's AI-usage monitoring matches data on the device; monitored prompt content is not sent to any AI sub-processor. Those AI sub-processors receive content only for our own product features described above.
A current, itemized list of our sub-processors — including each provider's name, location, and function — is available to customers under our Data Processing Agreement and on request to privacy@shadowspan.com. We do not sell your personal information, and we do not authorize our sub-processors to use it for their own purposes. Where personal information is transferred outside Canada or the EEA, we rely on appropriate safeguards, including Standard Contractual Clauses. We may update these categories as our services evolve; material changes are communicated under Section 14.
We may update this Policy from time to time. Material changes will be communicated by email or a notice on the website. Your continued use after an update constitutes acceptance of the amended Policy.
Questions or requests: privacy@shadowspan.com. We respond to Policy inquiries within 10 days.