Veldt LabsVeldt Labs
Platform
Runtime GovernanceFive verdicts in under 50ms — signed to a principal AuthorityApprove or block every action before it runs IdentityPortable, verifiable identity for every principal EvidenceSigned audit trail, mapped to 32 regulator packs Attack ChainsMulti-step attacks caught before they complete
Solutions
Enterprise AIInternal copilots and workflow agents Financial ServicesFraud, underwriting, and claims HealthcarePHI, human-in-the-loop, and HIPAA-safe clinical AI AI Agent SecuritySOC agents, red teams, and incident response Industrial & Defense AutonomyDrones, robots, SCADA, and cyber-physical systems Compliance & AuditRegulator packs, signed exports, and the auditor workspace
Resources
LearnConcepts, comparisons, and the KYA framework DocumentationDeploy and configure the Veldt runtime DevelopersSDKs, framework adapters, and API reference Research paper ↗ GitHub ↗
Plans Book a demo
Trust · Privacy

We collect only what we need.

Marketing site and product privacy in one place. Plain English. No dark patterns.

Last updated: 2026-07-09 v1.0

What this covers

This policy covers the Veldt Labs marketing site at veldtlabs.ai and the Veldt platform product. Handling of data our customers route through the platform is governed by the customer’s Data Processing Agreement (DPA). For details on how we protect that data once we hold it, see the security page.

What we collect on this website

  • Basic analytics. Page path, referrer, coarse geography (country-level), and user-agent string. First-party only. Retained 90 days, then deleted.
  • Contact form submissions. Name, work email, and message content. Used only to respond to your inquiry and, if you consent, to follow up.
  • Newsletter opt-ins. Email address and timestamp of opt-in. Retained until you unsubscribe.
  • No third-party ad trackers. No fingerprinting. No cross-site profiling.

What we do NOT collect

  • No cross-site tracking. We do not embed pixels or beacons for ad networks.
  • No selling data. Ever. We do not sell, rent, or trade personal information to third parties, under any definition.
  • No advertising cookies. We do not run advertising, so we have no need to profile visitors for it.
  • No unnecessary personal data. If we don’t need it to run the site or fulfill your request, we don’t ask for it.

Product data

When you use the Veldt platform, we act as a data processor for our customers. We handle only the data the customer routes through the platform: agent actions, evidence records, identity metadata, and configuration you provide.

Retention, deletion, access, sub-processor list, and international transfer terms for that data are governed by the customer’s DPA and order form. For how we protect it in flight and at rest, see the security page.

Your rights

You can exercise any of the rights below by writing to [email protected]. We’ll verify identity and respond within statutory deadlines.

  • Access, correction, deletionWrite to [email protected]
  • Data portabilityMachine-readable export on request
  • GDPR rightsAccess, rectification, erasure, restriction, portability, objection
  • CCPA rightsRight to know, delete, opt-out of sale (we don’t sell)
  • ComplaintsYou may lodge a complaint with your supervisory authority

Cookies

We use a single first-party session cookie. It exists only to keep the site usable during your visit. We do not set preference cookies (there are no preferences to remember) and we do not set advertising cookies (we do not advertise).

Legal bases (GDPR)

  • Legitimate interestSite analytics, security logging
  • ConsentNewsletter, marketing emails
  • ContractCustomer relationship data, billing
  • Legal obligationTax records, compliance retention

Data transfers

Servers are located in the United States and the European Union. When personal data is transferred out of the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and the UK IDTA where applicable, together with supplementary safeguards where required.

We do not transfer personal data to jurisdictions lacking an adequacy decision without an approved transfer mechanism in place.

Retention

Data typeRetention window
Site analytics90 days
Contact form submissions24 months
Newsletter opt-insUntil you unsubscribe
Product dataPer customer DPA
Security & access logs12 months
Signed audit recordsPer customer retention setting (up to 25 years)
Tax & billing records7 years (statutory)

Contact

For privacy questions, data subject requests, or DPA copies, please use the address below. We respond within statutory deadlines and typically much faster.

Privacy[email protected]
Security[email protected]
GeneralContact form
Veldt Labs Veldt Labs
The runtime governance layer for AI agents.
Platform
  • Runtime Governance
  • Authority
  • Identity
  • Evidence
  • Attack Chains
Solutions
  • Enterprise AI
  • Financial Services
  • Healthcare
  • AI Agent Security
  • Industrial & Defense Autonomy
  • Compliance & Audit
Learn
  • Glossary
  • Guides
  • Compare
  • Documentation
  • Architecture
  • Research paper
  • GitHub
  • PyPI
Company
  • Contact
  • Book a demo
  • LinkedIn
  • [email protected]
  • Plans
© 2026 Veldt Labs Inc. All rights reserved.
Privacy Terms Security