Loading...
Last updated: September 3, 2026
This Privacy Policy explains how SolonGate LLC (“SolonGate,” “we,” “us,” or “our”) collects, uses, stores, and shares personal data in connection with our public website, accounts, dashboard, self-service developer products, SolonGate-hosted cloud services, and browser-based security features (collectively, the “Services”).
SolonGate LLC
112 Capitol Trail, Suite A1253
Newark, DE 19711
United States
Privacy Contact: contact@solongate.com
This Privacy Policy applies to SolonGate’s public website and self-service or SolonGate-hosted Services.
It does not govern customer-controlled data processed as part of a separately contracted enterprise or on-premise deployment. Those deployments may use different architectures, storage models, security controls, retention settings, and data-processing arrangements and are governed by the applicable enterprise agreements.
This Privacy Policy may still apply when an enterprise customer or its personnel interact with our public website, communicate directly with SolonGate, or use a separate SolonGate-hosted Service.
SolonGate is designed so that security enforcement occurs locally on the user’s device.
For supported coding agents, SolonGate evaluates tool calls locally and determines whether an action should be allowed or blocked before execution.
For supported browser-based AI protection, the SolonGate browser extension and local components evaluate relevant activity locally before the browser communicates directly with the applicable AI provider.
SolonGate does not operate as a network proxy through which commands or AI requests must pass in order to reach their destination.
Where cloud logging is enabled, SolonGate may receive a security record after local evaluation. Depending on the functionality used, that record may contain a copy of underlying content needed to provide security auditing, investigation, or data-loss-prevention functionality.
The information we process depends on which Services and features you use.
We may process information such as:
We use this information to authenticate users, administer accounts and organizations, provide the Services, communicate with users, and protect accounts.
When cloud audit logging is enabled for supported coding agents, SolonGate may receive security records containing:
Tool-call arguments may contain sensitive or confidential information, including source code, credentials, secrets, personal information, or internal business information.
SolonGate does not collect the output returned by tools or commands as part of Coding Agent audit logging.
The underlying tool call is not sent through SolonGate Cloud for execution. The security decision occurs locally and, where cloud logging is enabled, the resulting audit record is transmitted afterward.
Where local logging mode is enabled, Coding Agent audit records are written to a user-selected location on the user’s device and are not sent to SolonGate Cloud.
The local SolonGate software may still periodically communicate with SolonGate to retrieve policies or configuration. Those requests do not contain the underlying tool-call content.
SolonGate does not control the retention or security of records that remain solely on the user’s device.
When browser-based AI protection is used with a SolonGate-hosted Service, SolonGate may receive information such as:
Because these features are designed to identify potentially sensitive information, a security record may contain the information that triggered a policy.
This may include source code, credentials, personal identifiers, customer information, confidential business information, or other content that SolonGate is configured to protect.
Where required for investigation and audit functionality, captured text may be stored in its original, unmasked form.
File names stored in Shadow AI security events are masked.
Certain historical or footprint-scanning functions retain security findings and counts without retaining the underlying scanned text.
Depending on the enabled functionality, screenshots may be captured in connection with browser-based security activity.
Where applicable, SolonGate may retain both an original screenshot and a masked version.
Screenshots may contain personal, confidential, or sensitive information and are treated as Customer Content for purposes of this Policy.
Where conversation or Sessions functionality is enabled in a SolonGate-hosted Service, SolonGate may process conversation messages and related session metadata.
The underlying browser communication with the relevant AI provider does not pass through SolonGate as a network proxy.
SolonGate uses Anthropic for specific user-initiated functionality, including the dashboard assistant and AI-assisted policy generation.
When a user intentionally invokes these features, information sent to Anthropic may include:
Stored Coding Agent audit records, browser security records, captured content, detected secrets, screenshots, and other security records are not automatically sent to Anthropic merely because they exist in SolonGate.
Our systems and service providers may process limited technical information necessary to operate and protect the Services, such as:
We may process this information for authentication, security, abuse prevention, troubleshooting, and operation of the Services.
If you contact us, request support or a demo, purchase a Service, or otherwise communicate with SolonGate, we may process information such as:
We use “Customer Content” to describe content submitted to, captured by, stored by, or generated through the Services on behalf of a user or organization.
Customer Content may include security audit records, tool-call arguments, source code, credentials, browser security records, screenshots, and conversation content.
When SolonGate determines why and how personal data is processed for our own purposes — such as account administration, direct communications, securing our own systems, or operating our business — SolonGate generally acts as a controller.
Where an organization determines the purposes of processing Customer Content and SolonGate processes that information on the organization’s behalf, SolonGate generally acts as a processor or service provider.
If personal data about you appears in Customer Content because your employer or another organization uses SolonGate, requests relating to that Customer Content should generally be directed to the organization that deployed SolonGate.
We will assist our customers with valid privacy requests where required by applicable law or contract.
We process personal data as reasonably necessary to:
We may use business contact information for business-to-business communications and marketing where permitted by applicable law.
Where consent is required, we will obtain it.
You may unsubscribe from marketing communications at any time.
Because SolonGate is a cybersecurity product, security records may contain the same sensitive information SolonGate was deployed to identify or protect.
For example, a security record may contain a credential, source-code fragment, personal identifier, confidential information, or other sensitive data involved in a security event.
Certain functionality retains raw security evidence so authorized users can understand and investigate the event.
SolonGate does not:
Customer administrators authorized by the relevant customer may access Customer Content through the Services where that access is part of the security, audit, or investigation functionality selected by the customer.
Access to Customer Content by SolonGate personnel is restricted to authorized personnel and permitted purposes.
SolonGate personnel may access Customer Content where reasonably necessary to:
Additional restrictions apply to information obtained through the SolonGate browser extension, as described in Section 12.
SolonGate personnel may not use Customer Content for unrelated personal, advertising, or commercial purposes.
SolonGate uses third-party service providers to operate portions of the Services.
Depending on the Service used, categories of personal data disclosed to service providers may include:
Categories of recipients may include:
Our current service providers that process personal data on our behalf and their purposes are identified in our separate Subprocessor List.
We may also disclose personal data where reasonably necessary to:
Information obtained through our browser extension will be transferred in connection with a corporate transaction only to the extent permitted by applicable browser-platform requirements and with consent where such consent is required.
We do not sell Customer Content.
SolonGate does not use Customer Content to train general-purpose or proprietary AI models.
We do not automatically submit Customer Content to third-party AI providers for training or analysis.
When a user intentionally invokes an AI-assisted feature, the information described in Section 3 may be sent to the provider for the purpose of providing that requested feature.
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy.
Coding Agent cloud audit records are subject to an automated 90-day retention schedule and are deleted when that retention period expires.
SolonGate-hosted browser security events, captured content, conversation records, and associated screenshots are subject to an automated 90-day retention schedule.
Coding Agent audit records generated using local logging remain on the user’s device and are not retained by SolonGate Cloud.
Account, organization, agent, device, session, usage, and similar operational information may be retained while the relevant account or customer relationship is active and for a reasonable period afterward where necessary to operate and secure the Services, resolve disputes, prevent abuse, or comply with legal obligations.
Business correspondence, transaction records, contractual records, invoices, and information needed for accounting, tax, or legal purposes may be retained for longer where reasonably necessary or legally required.
We may retain information in an aggregated or de-identified form where it can no longer reasonably identify an individual.
SolonGate recognizes that Customer Content may contain sensitive security information.
We use reasonable administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction, taking into account the nature and sensitivity of the information being processed.
These safeguards include measures designed to restrict access to authorized users, protect information during transmission and storage, and manage retention and deletion.
No online service, network, or storage system can guarantee absolute security.
Users and customers are also responsible for protecting their devices, credentials, accounts, integrations, and SolonGate configuration.
SolonGate provides a browser extension for supported Chromium-based browsers and Firefox.
The extension’s purpose is to provide AI-use security, policy enforcement, auditing, and data-loss-prevention functionality on supported services.
Depending on the functionality enabled, the extension may access or transmit information such as:
We use this information only for purposes reasonably necessary to provide the browser-based security functionality selected by the user or organization and related security and operational purposes.
We do not use browser-derived Customer Content for unrelated advertising, data-broker activities, credit decisions, or unrelated profiling.
SolonGate personnel do not read browser-derived Customer Content except where:
For versions of the extension distributed through the Chrome Web Store, SolonGate’s use of information obtained through the extension is intended to comply with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Firefox and other browser platforms may separately display information about the permissions and categories of information accessed or transmitted by the extension.
Where SolonGate acts as a controller and applicable law requires a legal basis for processing, including under the GDPR or UK GDPR, we rely on the legal basis appropriate to the activity.
These may include:
Performance of a contract, where processing is necessary to provide a Service requested by you.
Legitimate interests, including operating and securing SolonGate, preventing fraud or abuse, providing support, administering our business, and communicating with customers and prospective business customers.
Consent, where consent is required by applicable law.
Legal obligations, where processing is necessary to comply with applicable law.
Where SolonGate processes Customer Content on behalf of an organization, that organization is generally responsible for determining the applicable lawful basis for collecting and using that Customer Content.
SolonGate LLC is established in the United States and uses service providers and infrastructure that may operate in other countries.
Personal data may therefore be processed or accessed from a country different from the country in which the data originated.
Where applicable data-protection law requires a specific safeguard or transfer mechanism before a restricted international transfer may occur, SolonGate will implement an appropriate legally recognized mechanism as required.
Depending on the circumstances, this may include Standard Contractual Clauses, an applicable UK transfer mechanism, an adequacy framework, or another valid legal mechanism.
You may contact contact@solongate.com for information about safeguards applicable to a particular transfer.
Depending on your location and applicable law, you may have rights relating to personal data that SolonGate controls, including the right to:
These rights may be subject to applicable exceptions.
We may take reasonable steps to verify your identity before responding to a request.
You do not need to create a new SolonGate account solely to submit a privacy request.
To exercise a privacy right, contact:
If we deny a request and applicable law provides a right to appeal, you may appeal by emailing the same address with the subject line:
Privacy Request Appeal
We will review the appeal within the period required by applicable law.
Where required, if an appeal is denied we will provide information about how you may submit a complaint to the relevant regulator or authority, including the Delaware Department of Justice where applicable.
We will not unlawfully discriminate against you for exercising applicable privacy rights.
If your request concerns Customer Content controlled by your employer or another organization, we may direct the request to that organization or assist it in responding.
Our website may use cookies or similar technologies for functionality, authentication, security, preferences, and other purposes described in our separate Cookie Policy.
SolonGate does not use Customer Content for cross-site behavioral advertising.
We do not currently sell personal data or process personal data for targeted advertising through the Services.
Because we do not currently engage in this type of cross-site advertising activity, browser “Do Not Track” signals do not currently change how the Services operate for advertising purposes.
If our practices materially change, we will update this Policy and implement any notices, consent mechanisms, opt-out controls, or opt-out preference signals required by applicable law before beginning the relevant processing.
SolonGate may protect interactions involving independent third-party AI services.
Those third-party services are not operated by SolonGate.
Where a SolonGate security policy permits an interaction to proceed, the user’s browser, agent, or other client communicates with the relevant third-party provider according to that provider’s own architecture.
Those providers process information under their own terms, privacy policies, and customer agreements.
SolonGate is not responsible for their independent privacy practices.
SolonGate is designed for developers, businesses, teams, and professional organizations and is not directed to children.
We do not knowingly solicit personal data directly from children through our Services.
If you believe a child has provided personal data directly to SolonGate inappropriately, contact us at contact@solongate.com.
We may update this Privacy Policy as our Services, technology, service providers, or legal obligations change.
When we make changes, we will revise the Effective Date above.
If a change materially affects how we process personal data, we will provide additional notice where required by applicable law.
We will not treat an update to this Privacy Policy as consent where applicable law requires separate affirmative consent.
For privacy questions, requests, or concerns:
SolonGate LLC
112 Capitol Trail, Suite A1253
Newark, DE 19711
United States
Email: contact@solongate.com