Legal

Privacy Policy

Last Updated: September 2026

Our Approach to Privacy

We build security tooling for AI agents. This policy covers Declaw Secure Sandbox (our sandbox and guardrails platform). We collect as little data as possible and are transparent about what we do collect.

1. Declaw Secure Sandbox

When you use Declaw Secure Sandbox, your agent code runs inside isolated Firecracker microVMs. The guardrails pipeline (PII redaction, prompt injection defense, code security, toxicity detection, invisible text detection) runs inside each sandbox.

What we collect

  • Account information (email, API key)
  • Sandbox metadata (creation time, duration, resource usage)
  • Aggregate usage metrics (number of sandbox sessions, API calls)

What we do not collect

  • The code your agent executes inside the sandbox
  • The content of network requests made by your agent
  • PII or sensitive data processed by the guardrails pipeline
  • Audit logs generated inside your sandbox (these stay in your sandbox)

If you self-host Declaw, no data is sent to us at all. You control everything.

2. Contact

For privacy-related questions, email us at shivam@declaw.ai.