Book a call Start a run

Privacy Policy

Effective date:

This Privacy Policy explains how Zellic AI Inc dba V12 (V12, we, us, or our) collects, uses, discloses, retains, and protects information through V12.sh, our autonomous security agent and automated security platform, and related websites, software, application programming interfaces, tools, integrations, support, and services (together, the Service).

The short version is that we use information to run, secure, support, and improve the Service. V12 may, without further permission, use Usage Data and qualifying Derived Data to develop, improve, and commercialize current and future V12 products, services, and models, including through training and fine-tuning. V12 will not use raw, nonpublic Customer Materials or Results to train or fine-tune any AI model, or allow any third party to do so, unless the Customer expressly agrees. Section 5 explains this in detail.

Scope and roles

What this Policy covers

This Policy applies when V12 handles personal information through the Service, our website, account administration, billing, support, sales, or other business operations. It also explains our related practices for Customer Materials, Results, Usage Data, and Derived Data, even when that information is not personal information.

This Policy does not govern a third-party service that a Customer chooses and connects to V12. That service’s own terms and privacy policy govern its handling of information after the Customer directs V12 to send it there.

Controller and processor roles

V12 acts as a controller when we decide why and how to process information for our own business, including website, account, billing, security, support, analytics, and sales information.

When we process personal information in Customer Materials or Results on a Customer’s behalf, V12 acts as that Customer’s processor or service provider where applicable. The Customer decides what to submit and is responsible for required notices, permissions, and instructions. A signed Data Processing Addendum or Order Form controls if it sets different terms for covered processing.

Business use

The Service is for business and professional use. It is not intended for personal, family, or household use.

Key terms

Customer Materials means information a Customer or its users submit, connect, upload, transmit, or otherwise make available to the Service. It can include source code, repositories, files, dependencies, branches, commits, pull requests, patches, prompts, instructions, configuration, test data, organization memory, notes, messages, and related metadata.

Results means findings and other customer-specific material V12 produces through the Service, including severity and validity assessments, reports, explanations, proof-of-concept artifacts, proposed patches, test output, comments, annotations, and triage decisions. Results do not include a separate audit report or other deliverable provided by Zellic, Zenith, or another audit provider outside the V12 Service (Audit Deliverables). The separate agreement, statement of work, or other terms for the audit engagement govern Audit Deliverables.

Usage Data means technical and operational information about use of the Service, such as device and browser information, feature events, token and API activity, performance, latency, errors, consumption, and security logs. Usage Data does not include the substantive content of Customer Materials or Results. V12 may process limited excerpts of Customer Materials or Results as needed to secure, support, or troubleshoot the Service, but those excerpts remain Customer Materials or Results and are subject to Section 5.2.

Derived Data means information V12 creates by aggregating or deidentifying Customer Materials, Results, Usage Data, or use of the Service so that it cannot reasonably identify a Customer or person, or reveal, reconstruct, or reproduce a Customer’s nonpublic source code, unremediated findings, credentials, or other nonpublic Customer Materials or Results.

Information we collect

Account and business information

We collect names, business contact details, employer or organization, job title, account credentials, organization membership, roles, preferences, and other information used to create and manage accounts. We may receive business contact information directly, from an employer or administrator, from a referral, or from a public business source.

Billing and transaction information

We collect plan, order, billing contact, transaction, credit, tax, and payment-status information. Our payment providers process payment-card and bank information. We may receive limited payment details, such as the card type, last four digits, expiration date, billing address, and transaction status, but we do not need the full card number to operate the Service.

Customer Materials, Results, and workspace information

We collect the Customer Materials that a Customer submits or connects, the Results the Service produces, and workspace information such as organization memory, notes, comments, sharing settings, repository rules, and triage decisions. Customer Materials or Results may contain personal information if the Customer includes it.

We collect Usage Data automatically when someone visits our website or uses the Service. We may use cookies and similar technologies to keep users signed in, remember settings, secure the Service, diagnose problems, and understand use of the website and Service.

Communications and support

We collect information sent through support requests, sales conversations, surveys, feedback, incident reports, and other communications. We may keep records of those communications and the steps taken in response.

Integrations and other sources

If a Customer connects a repository, cloud service, developer tool, identity provider, or other integration, we receive the information and permissions needed to operate that connection. This can include account identifiers, repository metadata and content, branch or pull-request data, comments, and access tokens. We may also receive information from service providers, affiliates, security researchers, and public sources as permitted by law.

How we use information

Provide and operate the Service

We use information to create and administer accounts; authenticate users; connect repositories and other tools; analyze Customer Materials; generate Results; run tests and proof-of-concept artifacts in an analysis environment; store organization memory and triage decisions; provide support; process payments and credits; and otherwise carry out a Customer’s instructions.

Secure, support, and monitor the Service

We use information to protect accounts and systems; detect, investigate, prevent, and respond to vulnerabilities, fraud, abuse, misuse, harmful content, service failures, and other threats; enforce our agreements; troubleshoot problems; and maintain business, security, and audit records.

Measure and improve

We use information to measure quality, accuracy, performance, cost, safety, and use of the Service; test features; conduct research; and develop and improve current and future V12 systems and related security, developer, and artificial-intelligence products. Section 5 states the boundaries for training and generalized product improvement.

Communicate and manage our business

We use information to send service, security, billing, legal, support, and administrative messages; respond to requests; manage customer and vendor relationships; plan and operate our business; and send business or product updates where law allows. A recipient can opt out of marketing email through the message, but may still receive non-marketing messages needed for an account or the Service.

Comply with law

We use information to comply with legal obligations and lawful requests, establish or exercise legal rights, defend claims, complete corporate transactions, and protect V12, our customers, users, and others.

Product improvement, fine-tuning, and training

What V12 may use by default

V12 may, without further permission, use Usage Data and Derived Data that meets the definition and safeguards in Sections 2 and 5.3 to develop, improve, and commercialize current and future V12 products, services, and models. This includes research, design, benchmarking, validation, training, retraining, fine-tuning, grounding, alignment, testing, and evaluation of models, agents, classifiers, detectors, ranking systems, rules, and other automated systems.

V12 may create and use generalized datasets, evaluations, benchmarks, model weights, model state, detectors, rules, and other learnings from Usage Data and Derived Data. V12 may retain and use those items indefinitely, including after the underlying account closes.

Raw nonpublic Customer Materials and Results

V12 will not use raw, nonpublic Customer Materials or Results to train or fine-tune any AI model, or allow any third party to do so, unless the Customer expressly agrees. This restriction includes using the raw, nonpublic material to build a reusable training dataset.

V12 may process raw, nonpublic Customer Materials and Results as needed to provide, secure, support, and troubleshoot the Service; perform the requested analysis; measure quality, accuracy, performance, cost, safety, and use of the Service; and evaluate the specific run or feature.

A Customer may expressly agree in an Order Form, through a Service setting, by enabling a feature that clearly describes the use, or through another written agreement. A Customer can withdraw a revocable setting-based permission prospectively by turning the setting off. Withdrawal does not undo a use that was permitted before the change and does not require V12 to isolate, reverse, or unlearn information already incorporated into a dataset, evaluation, model, model state, model weights, detector, rule, or other improvement.

This restriction does not prevent V12 from using information that was already lawfully public through no breach by V12, information V12 obtained independently from a public source, or feedback that does not reveal nonpublic Customer Materials or Results.

Deidentification safeguards

We will not treat information as Derived Data if it can reasonably identify the Customer or a person, or if it can reveal, reconstruct, or reproduce nonpublic Customer Materials or Results. We do not use or disclose Derived Data in a way designed to reidentify a Customer or person.

Credentials and secrets

If V12 identifies an active credential or secret in Customer Materials, we may quarantine, redact, or delete it. We will not intentionally use the credential or secret itself as a training example after identifying it. We may use surrounding deidentified context or the fact that a secret was detected to improve secret detection, security analysis, and the Service.

Model providers and other service providers

Model and inference providers

The Service uses third-party model and inference providers. V12 may send Customer Materials, Results, and related instructions to those providers as needed to perform an analysis or other requested feature. Unless an enabled Service setting or Order Form says otherwise, V12 chooses the provider, model, routing, and standard provider arrangement used for a run.

We do not authorize a model or inference provider to use raw, nonpublic Customer Materials or Results to train or fine-tune its own models unless the Customer expressly agrees through the Service, an Order Form, or another written agreement. A provider may retain submitted data as allowed by V12’s arrangement with it, except to the extent an enabled Service setting or signed Order Form imposes stricter limits.

The Service may offer a Zero Data Retention (ZDR) setting. When a Customer enables an available ZDR setting, V12 routes covered requests only to providers whose applicable arrangement prohibits storing the submitted code and prompts or using them for training. ZDR does not prevent a provider from receiving and processing those materials to perform the requested run. The scope and any technical limits of the setting are those shown in the Service or an applicable Order Form. Other provider-specific routing, retention limits, or data restrictions apply only to the extent an enabled Service setting or signed Order Form expressly provides.

Other service providers

We use affiliates, cloud and hosting providers, payment processors, analytics and communications providers, security vendors, contractors, professional advisers, and other service providers to help run our business and the Service. We give them the information and access we reasonably determine they need for their role and require them to protect it through contract or other appropriate obligations.

Current information about material subprocessors is available in our documentation or on request.

Customer-connected services

A Customer may direct V12 to exchange information with a service the Customer chooses and controls. The Customer is responsible for that connection and its permissions. The third party’s own terms and privacy practices govern its use of information after V12 delivers it at the Customer’s direction.

How we disclose information

We may disclose information to the service providers described in Section 6; to our affiliates, personnel, contractors, and professional advisers who need it for the purposes in this Policy; to a Customer’s account owners, administrators, and authorized users; and to third parties at the Customer’s direction.

We may also disclose information when we reasonably believe disclosure is required by law or legal process; needed to protect rights, safety, systems, or the Service; needed to investigate fraud, abuse, or a security incident; or needed to enforce an agreement. If law allows, we will give the affected Customer notice before disclosing its nonpublic Customer Materials in response to legal process.

If V12 is involved in a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, information may be disclosed to participants and transferred as part of that transaction, subject to appropriate confidentiality protections.

We may disclose and use Derived Data for the purposes in this Policy. We do not sell personal information or share it for cross-context behavioral advertising or targeted advertising as those terms are defined by applicable U.S. state privacy laws.

Retention and deletion

Account, billing, and business records

We keep account information while the account is active and as reasonably needed afterward for billing, tax, audit, security, dispute, legal, and business-record purposes. The period depends on the type of record and applicable law.

Raw Customer Materials and Results

We keep raw Customer Materials and Results while an account is active and as needed to provide, secure, support, and troubleshoot the Service. After account closure, termination, or a valid deletion request, we delete them from active production systems within 30 days after the applicable export period ends or, if none applies, within 30 days after account closure, termination, or the request. Backup copies are deleted or overwritten through ordinary backup cycles within 90 days after deletion from active systems.

We may keep particular information longer when required by law; reasonably needed for security, abuse prevention, fraud investigation, dispute resolution, or legal claims; or retained at the Customer’s direction. These periods apply only to systems V12 controls. Provider-held copies are governed by Section 6.1, the applicable provider arrangement, and any provider retention limit in an enabled Service setting or signed Order Form. A signed Order Form or Data Processing Addendum may set a different period for the information it covers.

Usage Data, Derived Data, and trained state

We keep Usage Data for as long as reasonably needed for the purposes in this Policy. We may retain Derived Data and generalized datasets, evaluations, benchmarks, model weights, model state, detectors, rules, and other improvements indefinitely. Deleting raw Customer Materials or closing an account does not require V12 to identify, isolate, reverse, or unlearn information already incorporated into those items through a use permitted by this Policy or the applicable agreement.

Security and incidents

We maintain reasonable administrative, technical, and physical safeguards designed to protect information under our control. Our measures may include access controls, encryption, monitoring, logging, testing, incident response, and vendor review, as appropriate to the information and risk.

No system is completely secure. We cannot promise that unauthorized access, loss, misuse, or an attack will never occur. Customers are responsible for securing their own systems, repositories, credentials, users, and connections to the Service.

If V12 confirms unauthorized access to or disclosure of nonpublic Customer Materials under our control, we will notify the affected Customer without undue delay and provide information reasonably needed for the Customer to respond, consistent with law and legitimate security needs.

V12 and our service providers may process information in the United States and other countries where we or they operate. Those countries may have privacy laws different from the laws where a person lives. Where required, we use contractual or other safeguards for international transfers. A Data Processing Addendum with applicable transfer terms is available on request.

Where a law requires a legal basis, we process personal information as needed to perform a contract or take requested steps before entering one; for our legitimate interests in operating, securing, supporting, improving, and marketing our business and the Service; to comply with law; to protect vital interests; or with consent. The available basis depends on the information and context.

Privacy rights

Depending on where a person lives, that person may have the right to request access to, correction of, deletion of, or a copy of personal information; object to or restrict certain processing; withdraw consent; or complain to a privacy regulator. These rights are subject to applicable exceptions.

To make a request about information V12 controls, email [email protected]. We may ask for information needed to verify the request and may work with an authorized agent where law allows. We will not discriminate against a person for exercising a privacy right.

If personal information is contained in Customer Materials that V12 processes for a Customer, the request should be sent to that Customer. We will assist the Customer as required by the applicable agreement and law.

Children and restricted data

The Service is not directed to children, and a user must be at least 18 years old. We do not knowingly collect personal information from children through the Service. If you believe a child has provided personal information to V12, contact [email protected].

Unless a signed Order Form expressly permits it, Customers must not submit protected health information, payment-card data, government classified information, export-controlled technical data, biometric identifiers, or another specially regulated category through the Service.

Changes to this Policy

We may update this Policy as the Service and law change. We will post the updated Policy with a new effective date and give notice through the Service or by email when a change materially affects how we handle information.

If an update materially expands V12’s right to use raw nonpublic Customer Materials or Results already stored in the Service for generalized training or product improvement, that expanded use will apply to the stored material only after the Customer affirmatively accepts it or otherwise expressly agrees.

Contact

For privacy questions, requests, or complaints, contact:

Zellic AI Inc dba V12
[email protected]

Type to search.