Privacy
Privacy
DETERMA is designed for metadata-first assessment and safe evaluation.
01
What we collect
For the initial assessment, DETERMA may collect scoped metadata such as repository names, pull request metadata, review and approval metadata, CI and status metadata, workflow descriptions, and AI usage summaries where available. For External Action Control evaluations, scoped metadata may additionally include external workflow descriptions, target-system and target-object identifiers, record identifiers, approval metadata, state and version metadata, and evidence fingerprints.
02
What we do not require by default
DETERMA does not require production credentials, write access, secrets, production blocking, source code, transcripts, payment details, or clinical data by default for the first assessment. External Action Control evaluations remain metadata-first: no live external-system writes and no production execution authority are requested by default.
03
How data is used
Data is used only to perform the agreed assessment, generate findings, produce the Governed AI Developer Score, and recommend whether GFDE Shadow Mode is appropriate.
04
Access and retention
Access is limited to the assessment team. Retention is governed by the agreed assessment scope and customer instructions.
05
Security posture
DETERMA starts with a metadata-first approach to reduce operational and security risk during evaluation.
06
Contact
For privacy or data handling questions, contact privacy@determa.ai.
This page is for early assessment engagements and may be updated as DETERMA expands its production offering.
