HiddenLayer’s Product Data Collection and Handling
Our Commitment to Data Transparency and Protection
Your trust matters to us. Our approach to data protection is grounded in transparency, strong security practices, and clearly defined safeguards. This document explains what data is collected, how it is used to support and deliver product functionality, and how it is protected at every stage. We are committed to being open about our data practices so you can make informed decisions, maintain control of your information, and confidently use our products knowing privacy and security are built in from the start.
Our Commitment to Safeguard Your Data
Data Scope and Boundaries
Personal Information
Personal information is only collected where necessary to support account management, access control, billing, or customer support, and is rarely required for core product functionality.
We retain personal information only as long as needed to fulfill the purposes for which it was collected, and for a limited period afterward to meet legal, contractual, or audit requirements. De-identified or aggregated data may be retained where permitted. Backup and archival copies may persist for a defined period as part of standard system operations.
What Data is Not Collected
HiddenLayer does not collect:
- Customer training datasets
- Business logic or proprietary application code
- Persistent copies of model files, including model weights
- Customer data for training or tuning without explicit authorization
What Data Is Processed and Stored
HiddenLayer processes and stores data in secure environments aligned with the selected deployment model. Data location and processing controls are designed to meet security, compliance, and customer requirements.
When deployed in SaaS mode, certain data resides within HiddenLayer’s tenant-isolated infrastructure. In hybrid deployment models, some data may be processed locally within the customer environment while selected results or metadata are transmitted to the SaaS platform.
Platform Operational Data
Operational data is collected and protected to ensure secure access, maintain platform integrity, support compliance requirements, and provide auditable oversight of system activity.
AI Runtime Security
Runtime Security ingests and analyzes structured:
This data is used to reconstruct sessions, detect adversarial activity and policy violations, and apply runtime actions such as detect, redact, or block. Detection records include the triggering signals, related execution context, and applied policy outcome.
For customer-controlled deployments, monitoring and enforcement can be deployed within the customer environment. Customer data is not used for model training. Any contribution to detection enhancement requires explicit customer approval.
In the SaaS deployment model, detection data is retained for a rolling 30-day window. Following contract termination, all data is securely deleted within 60 days.
AI Supply Chain Security
Supply chain data is processed and protected to assess model integrity, provenance, licensing exposure, and deployment risk before models enter production environments without expanding intellectual property exposure. We intentionally work with structured metadata and security attributes that do not allow reconstruction of the model. This enables vulnerability detection, license transparency, provenance validation, and informed, risk-based deployment decisions while maintaining strict protection of proprietary model assets.
Raw model files are temporarily stored solely for processing and automatically deleted within 24 hours.
Model weights are not inspected, retained, or reused.
AI Discovery
AI Discovery data is processed and protected to provide visibility into AI-related assets across cloud environments, supporting governance, supply chain, inventory management, and risk oversight without expanding customer data exposure. We focus on asset-level metadata and configuration attributes necessary to identify and classify AI systems within your environment.
Source asset data is retained for the life of the customer relationship to support discovery visibility, continuous governance, and asset management.
AI Attack Simulation
AI Attack Simulation data is processed and protected to evaluate system prompt resilience, identify security gaps, and strengthen AI system defenses prior to deployment. Processing is limited to authorized testing inputs, structured analysis outputs, and product-generated security enhancements.
All AI Attack Simulation data is retained for 90 days unless otherwise contractually required. System prompts and associated artifacts are processed solely for analysis and defense improvement purposes.
Summary of Our Approach
AI security requires visibility, and that visibility must be handled responsibly. HiddenLayer is designed to provide the insight necessary to detect threats and assess model risk while maintaining clear data boundaries, defined retention practices, and strong access controls. Our approach is intended to give you the clarity, control, and confidence needed to manage AI risk within your own governance and compliance frameworks.