Skip to content
LyraShield AIOpen beta

Privacy · draft for approval

Privacy at LyraShield AI

This draft describes the current data flows and remains subject to founder and counsel approval before marketplace submission.

Data we process

The dashboard processes account, workspace membership, integration, scan, finding, evidence, approval, and audit records needed to provide release assurance. OAuth stores client, consent, refresh-token, and access-token records; tokens are not placed in prompts or configuration snippets.

Agent connections

Hosted MCP requests carry a short-lived OAuth bearer or an API key. Each OAuth connection is bound to one workspace. We record privacy-safe connection and error events without token values, prompts, targets, findings, or report contents.

Retention and sharing

Customer records are retained according to the account and service configuration. Public scorecards are explicitly privacy-bounded. We do not sell customer data.

Your choices

You can disconnect OAuth clients, revoke tokens, delete API keys, and request account or workspace deletion through the dashboard or support@lyrashieldai.com.

Security reports

Report suspected vulnerabilities through the security-reporting channel. Do not include credentials or customer data.