This Privacy Policy explains how AIM Intelligence Co., Ltd. (“AIM Intelligence”, “we”) handles personal data in connection with Stinger, our AI red-teaming platform (the “Service”).
We are the controller for the account, contact, website, and usage data we collect to run our business. We are a processor for the assessment data our customers generate and direct us to process — including attack prompts, target responses, and scoring traces. Processor-role data is governed by our Data Processing Agreement, and the customer remains its controller.
We do not sell, rent, or trade personal data. We do not retain extracted secrets or credentials beyond what is needed to perform the assessment you started, and we do not mine assessment traces for any purpose outside delivering the Service.
To provide, secure, bill, and support the Service, and to improve the platform using our own usage telemetry — never using customer assessment content for product improvement without consent.
Where the GDPR applies, we process on the bases of contract performance, our legitimate interests in operating and securing the Service, legal obligation, and consent where required.
We do not train AI models on your data. Where the Service relies on third-party models (for example, to generate or judge attacks), we require a data processing agreement with each provider stipulating that data we share will not be used to train their models. We retain assessment traces only for a limited window and delete them on request or when retention expires.
We share personal data only with service providers and subprocessors that support the Service (including AWS, hosting in Seoul / ap-northeast-2, and any model providers), under confidentiality and data-protection terms; with affiliates; and where required by law or in a business transfer. A current list of subprocessors is available on request.
Our primary hosting region is Seoul. Where personal data is transferred across borders, we rely on appropriate safeguards, including the EU Standard Contractual Clauses and applicable Korean cross-border transfer requirements.
We keep personal data only as long as necessary for the purposes above or as required by law. Sensitive assessment artifacts and uploaded credentials are kept for a short window and then deleted.
We apply technical and organizational measures including encryption in transit and at rest, access controls, and per-tenant isolation. See our Security page for details.
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent or lodge a complaint with a supervisory authority. For assessment data we process on a customer’s behalf, we route requests to that customer as controller.
The Service is a business tool and is not directed to children.
We may update this policy and will notify material changes. Privacy questions or requests: success@aim-intelligence.com.