Last updated: August 11, 2026
PrimeOutpost is a security program platform operated by SecurityBite. This policy covers primeoutpost.com, the marketing site you are reading now, and app.primeoutpost.com, the product itself.
It explains what we collect, why we collect it, how long we keep it, and who else touches it along the way. Anything unclear, ask at [email protected].
Account data: your email address, and your name if you choose to give one. Sign-in is passwordless, by emailed link or by a passkey registered to your device. The product has no password field, so there is no password for us to store or for anyone to steal.
Program data: everything your organization puts into the product. Roadmap items, risks, decisions, playbooks, framework mappings, and the context you answer during onboarding. It belongs to your organization, not to us.
Billing data: subscriptions run through Stripe. Card details go to Stripe and never reach our systems. We keep a thin local copy of the subscription itself, meaning the plan, its status, the billing period, and Stripe's identifiers. Amounts and invoices stay with Stripe.
Technical data: your account record holds no IP address and no user agent, because no such field exists in the database. Cloudflare sits in front of both domains and handles visitor IP addresses at its edge as part of delivering and protecting them. Our infrastructure logs are kept for 60 days.
Usage data: this marketing site uses Google Analytics to measure aggregate traffic. The product does not. There is no analytics, no error tracking, and no session recording inside the application.
To run and secure the service, to send the only two emails the product sends (your sign-in link, and an invitation when someone adds you to an organization), to take payment, and to see how this marketing site is performing in aggregate.
Your program data leaves our infrastructure in two cases, and only when someone in your organization asks. AI features are on by default, and nothing is sent until a member requests a generation: generating a playbook or a control mapping sends Anthropic your organization's context, meaning industry, regulations in scope, headcount band and tech stack, together with the titles and descriptions of the items being worked on. We record that a generation happened, never what was in it, and those records are deleted after 90 days. In addition, personal access tokens let a member connect a script or an AI assistant of their choice, which then reads the program on that member's behalf. What that assistant does with the data is governed by the member's agreement with its provider, not by us. Tokens are scoped to one organization, expire, and can be revoked at any time.
If you would rather have no AI at all, write to [email protected] and we switch it off for your organization
We do not sell personal data, we run no advertising or retargeting trackers on either domain, and we do not use your program data to train models.
A short list, each doing one job:
Amazon Web Services, in Ireland, hosts the application, stores this marketing site, and sends our email through SES. Neon runs the Postgres database holding your account and program data. Cloudflare provides DNS, CDN, bot protection, and the private network path into the application.
Stripe processes payments. Anthropic processes AI generations. Google Workspace receives mail sent to our addresses, and Google Analytics measures traffic on this marketing site.
Account and program data stay while your organization is active. If a subscription lapses the workspace turns read-only rather than being deleted, so your data remains reachable.
When an owner deletes an organization it is suspended straight away and stays recoverable for 30 days. After that a scheduled job removes it for good, cascading through every table that referenced it. One record outlives the deletion: a row holding the plan, dates and status of the account, carrying no name, no email address and no Stripe identifiers, kept so we can understand why organizations leave.
Shorter-lived records expire on their own. Sign-in links go when used or when they lapse, refresh tokens 30 days after expiry, the email send log after 30 days, AI generation records after 90 days, and infrastructure logs after 60.
This site's own code sets none. It is a static export with no server behind it.
Two other things do set cookies here. Google Analytics sets first-party cookies to count visits, and Cloudflare may set short-lived ones to tell browsers apart from bots.
The product sets two of its own, both first-party and httpOnly so no script can read them: a 15-minute access token and a 7-day refresh token. They exist only to keep you signed in.
Depending on where you live you may have the right to see the personal data we hold about you, correct it, export it, delete it, or object to or restrict what we do with it. Write to [email protected] and we will action it.
When this policy changes we update it here and change the date at the top. If a change is material we will email account holders rather than rely on anyone noticing.