Privacy · draft for approval
Privacy at LyraShield AI
This draft describes the current data flows and remains subject to founder and counsel approval before marketplace submission.
Data we process
The dashboard processes account, workspace membership, integration, scan, finding, evidence, approval, and audit records needed to provide release assurance. OAuth stores client, consent, refresh-token, and access-token records; tokens are not placed in prompts or configuration snippets.
Agent connections
Hosted MCP requests carry a short-lived OAuth bearer or an API key. Each OAuth connection is bound to one workspace. We record privacy-safe connection and error events without token values, prompts, targets, findings, or report contents.
Retention and sharing
Customer records are retained according to the account and service configuration. Public scorecards are explicitly privacy-bounded. We do not sell customer data.
Your choices
You can disconnect OAuth clients, revoke tokens, delete API keys, and request account or workspace deletion through the dashboard or support@lyrashieldai.com.
Security reports
Report suspected vulnerabilities through the security-reporting channel. Do not include credentials or customer data.