LEGAL & TRUST

Built for high-trust agent environments.

Last updated: August 13, 2026. This policy details how Ciwrl Technologies LLC d/b/a Spctre handles telemetry, rule configurations, and operational audit trails for autonomous agent systems.

Data Scope What we collect Minimization Telemetry boundaries Operations How data is used Ledger Retention & Redaction
Data Scope

Information captured for agent governance

Configured scope

Spctre (operated by Ciwrl Technologies LLC d/b/a Spctre) is a control plane for policy enforcement. To author, simulate, and verify policy decisions, we process the minimum necessary operational metadata:

Workspace & Organization Data

We collect profile data including your email, name, organization name, and workspace configurations required to manage administrative access, SAML/SCIM settings, and API authentication.

Policy Rules & Bundles

When you author and compile policy rules, we store the policy source code, environment scopes, change histories, pull requests, reviewer credentials, and cryptographic bundle hashes.

Agent Operational Traces

For each evaluated decision, we record the agent's identity, target connector (e.g., Stripe, GitHub), requested action (e.g., refund.create), system environment, policy decision outcome, and execution latency. Configured evidence integrations also retain the submitted source event with its mapping version alongside the canonical governance record.

Minimization

Telemetry boundaries and payload protection

Payload isolated

Configured Evidence Storage

Spctre stores the governance context required by the integration you configure. Generic evidence integrations retain submitted source events alongside mapped governance records, so use mappings and redaction to limit sensitive data before submission.

Local SDK Resolution

Local policy evaluation keeps decisions close to your runtime. Gateway and evidence integrations send the data required for the governance and audit workflow you configure.

Dynamic PII Masking

Our gateway supports standard regex-based redaction patterns, ensuring that identifiers (such as credit cards or SSNs) present in tool names or transaction arguments are masked prior to being logged.

Operations

How operational data is utilized

Internal only

Spctre uses operational data exclusively to deliver, maintain, and optimize the policy control plane. This includes:

Simulation Projections

Historical event headers are processed to simulate how a proposed policy modification would have changed decisions in the past, allowing you to dry-run rules safely.

Durable Audit Trails

Durable chains of custody are created to let compliance officers inspect which policy bundles allowed or blocked an action, when review requests were resolved, and by whom.

Operational Metrics

Calculating execution latencies, rate-limit thresholds, and workspace volume stats to guarantee that Spctre gateways meet the high-availability demands of autonomous system architectures.

Ledger Retention

Archival & Erasure Posture

  • Audit logs are retained according to your plan: 1 year on Team, 3 years on Business, and custom windows on Enterprise. Community workspaces store logs locally only.
  • Cryptographic policy bundle histories are preserved indefinitely to maintain audit chain validation.
  • Tenant database records can be fully purged within 30 days of workspace termination.
  • Redaction filters can be programmatically forced at the SDK border to prevent accidental transmission of private tokens.
Your Controls

Privacy settings and parameters

  • Toggle local evaluation versus gateway transmission using the Spctre CLI and SDK settings.
  • Designate specific environments (e.g., development workspaces) to operate on completely ephemeral logs.
  • Restrict administrator permission scopes using granular role-based access control (RBAC).
  • Export complete trace data in structured JSON format anytime via administrative endpoints.