Legal

Privacy Policy

Effective October 1, 2026·Version 2.1

Effective Date: October 1, 2026 Last Updated: October 1, 2026

This Privacy Policy describes how ComplAI Solutions, LLLP, doing business as Garde1 ("Garde1," "we," "us," or "our"), collects, uses, discloses, and protects information when you use the Garde1 platform, websites, APIs, and related services (the "Services"). ComplAI Solutions, LLLP (Garde1) is pursuing Registered Provider Organization (RPO) authorization from the Cyber AB and provides CMMC readiness, mock-assessment, documentation, evidence-management, and assessor-preparation tooling for organizations in the U.S. Defense Industrial Base.

Questions may be sent to [email protected].

1. Scope

This Policy applies to Garde1-operated services, including garde1.com, app.garde1.com, assessor-preparation sharing surfaces, APIs, support channels, billing flows, and product communications.

This Policy does not govern customer-controlled systems, cloud tenants, identity providers, security tools, endpoints, email systems, file stores, or other third-party environments that you authorize Garde1 to connect to. Those systems remain governed by your own policies and third-party provider terms. Customer Data collected from those systems is processed to provide the Services.

2. Information We Collect

2.1 Account and User Information

We collect business contact and account information such as name, business email address, organization name, job title or role, optional phone number, authentication identifiers, user role, account status, and security settings such as multi-factor authentication enrollment metadata.

2.2 Customer Data from Authorized Connectors

When you authorize a connector, Garde1 may collect configuration, security, identity, device, vulnerability, audit, inventory, and compliance-relevant metadata from supported systems such as cloud providers, identity providers, endpoint-management tools, security platforms, ticketing systems, code repositories, and similar business systems.

Connector collection is intended to support scoping, readiness review, evidence organization, document generation, control review, shared-responsibility mapping, and mock-assessment workflows. The exact data collected depends on the connector, permissions granted, customer configuration, product plan, and enabled features.

Garde1 does not intentionally collect personal files, mailbox contents, chat messages, call recordings, or general business documents through connectors unless you upload or authorize specific content as evidence or the content is necessary to evidence a security configuration.

2.3 Documents and Evidence

You may upload or generate policies, procedures, system security plan content, diagrams, screenshots, contracts, training records, acknowledgments, remediation notes, plans of action, and other security or compliance evidence. These materials may contain personal information, security-sensitive information, proprietary business information, or other confidential content. You must not upload controlled unclassified information (CUI). The Services are not authorized to store or process CUI, and uploads that are flagged as CUI, or whose CUI status is uncertain, are refused.

2.4 Usage, Device, and Log Data

We collect technical and operational data such as IP address, approximate location derived from IP address, browser and device information, operating system, pages viewed, feature usage, timestamps, API request metadata, authentication events, errors, diagnostic logs, and audit logs of state-changing product actions.

2.5 Billing and Commercial Information

If you purchase a paid plan, payment processing is handled by our payment processor. We do not store full payment card numbers or card verification codes on Garde1 infrastructure. We may store billing contact information, subscription tier, invoice metadata, payment status, and limited card metadata supplied by the payment processor.

2.6 Support and Communications

If you contact us, respond to surveys, attend demos, participate in onboarding, or communicate with support, we collect the information you provide and related communication metadata.

3. How We Use Information

We use information to:

  • Provide, secure, monitor, maintain, troubleshoot, and improve the Services.
  • Authenticate users and enforce account security controls.
  • Build and maintain customer scoping, boundary, organization-profile, document, evidence, readiness, and mock-assessment workflows.
  • Generate and review Assessment Outputs, including SSP drafts, control-readiness materials, remediation plans, shared-responsibility views, and assessor-preparation packets.
  • Operate customer-authorized connectors and normalize connector results.
  • Respond to support requests and product communications.
  • Process billing, prevent fraud, and administer accounts.
  • Detect, investigate, and prevent security, abuse, integrity, and availability issues.
  • Comply with law, enforce agreements, and protect rights, safety, and property.
  • Improve product quality using aggregated or de-identified operational metrics, such as usage and performance data.

We do not sell Customer Data. We do not use Customer Data for cross-context behavioral advertising. Customer Data is not used to train or fine-tune any model, ours or a third party's.

4. AI and LLM Processing

Garde1 uses AI and large language model services to provide features such as evidence review, policy and SSP drafting, control-readiness explanations, in-app assistance, summarization, and mock-assessment support.

LLM prompts and outputs may include organization profile facts, scoping facts, connector findings, evidence excerpts, policy text, SSP text, control text, remediation notes, and user instructions when needed to provide the feature. AI outputs may be inaccurate, incomplete, or outdated and must be reviewed by the customer before use or reliance.

Customer Data is not used to train or fine-tune any model, ours or a third party's. We configure AI subprocessors under contractual restrictions that prohibit them from using Customer Data to train or fine-tune their models. Specific retention, region, and human-review controls depend on the configured provider and service tier and will be reflected in our current subprocessor and security materials.

5. How We Share Information

We share information only as needed to operate the Services, as directed by you, or as required by law:

  • With subprocessors that provide hosting, storage, identity, security, AI inference, payment, email, analytics, support, or similar services.
  • With authorized users in your organization according to their roles and permissions.
  • With authorized assessors, consultants, C3PAOs, primes, or other third parties when you direct us to share reports, bundles, links, exports, or workspace access.
  • With professional advisors, auditors, insurers, and legal counsel under confidentiality obligations.
  • With law enforcement, regulators, courts, or other parties when required by valid legal process or necessary to protect rights, safety, security, or property.
  • In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate protections.

We do not share Customer Data with third parties for their independent marketing.

6. Subprocessors

Garde1 uses subprocessors to operate the Services. The current subprocessor list is published at the canonical privacy or security page, or made available on request. Subprocessors may include infrastructure providers, identity providers, AI inference providers, payment processors, email providers, analytics providers for the marketing site, hosting providers, observability providers, and support tooling.

We will maintain a current list of material subprocessors and provide notice of material changes where required by contract or law.

7. Security

We use commercially reasonable technical and organizational safeguards designed to protect information processed by the Services. Safeguards may include encryption in transit, encryption at rest for supported storage systems, access controls, tenant-isolation controls, logging, monitoring, secrets management, least-privilege access, vulnerability management, backup and recovery practices, and personnel access restrictions.

No security program can guarantee perfect protection. You are responsible for securing your own systems, users, devices, credentials, networks, cloud tenants, third-party tools, and connector permissions.

8. Data Retention

We retain information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, support auditability, and preserve business records.

Retention periods vary by data type, product configuration, order form, legal obligations, and customer instructions. Customer Data associated with an active account is generally retained while the account is active. After termination, we may retain Customer Data for a limited period to support export, backup expiration, legal holds, security investigations, dispute resolution, and compliance obligations.

You may request deletion by contacting [email protected]. If information is controlled by a customer organization, we may route the request to that organization.

9. Cookies and Similar Technologies

The Garde1 application uses cookies and similar technologies that are necessary for authentication, security, session management, fraud prevention, and product operation.

The marketing site may use analytics technologies to understand traffic and improve content. Where required, we will provide notice and choices for non-essential analytics technologies. Browser settings may block some technologies, but disabling necessary cookies may prevent authentication or product use.

10. U.S. State Privacy Notice

Depending on where you live and how you interact with Garde1, you may have rights to know, access, correct, delete, port, restrict, opt out of certain processing, or appeal a privacy decision. To exercise privacy rights, contact [email protected] from the email address associated with your account.

For California residents, the categories of personal information we may collect are described in Section 2. The business and commercial purposes are described in Section 3. The categories of third parties to whom information may be disclosed are described in Sections 5 and 6. Retention is described in Section 8. We do not sell personal information or share personal information for cross-context behavioral advertising as those terms are used under California privacy law.

We do not use or disclose sensitive personal information for purposes that require a right to limit under California law, unless we provide a separate notice and choice.

We will not discriminate against you for exercising privacy rights.

11. International Users

The Services are designed for U.S.-based organizations supporting U.S. federal contracting and CMMC readiness. If you access the Services from outside the United States, you understand that information may be processed in the United States and other locations where we or our subprocessors operate. Additional data-transfer terms may apply if required by law or contract.

12. Children's Privacy

The Services are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child provided personal information to us, contact [email protected].

13. Changes to This Policy

We may update this Policy from time to time. The current authoritative Privacy Policy is published at the canonical Privacy URL. Material changes will be announced through the product, website, email, or other reasonable means where appropriate.

14. Contact

ComplAI Solutions, LLLP d/b/a Garde1
Nashville, Tennessee, USA
[email protected]