Foxy Audit
← Back to home
On-device by design. The foxy-audit SDK computes every cryptographic commitment on your own infrastructure, before anything is sent to us. We structurally cannot see the raw text of your AI prompts or responses — not because of a policy promise, but because our servers have no field capable of storing them. See Section 3.
Foxy Audit is a Runtime Auditing and Security Management platform for AI systems — what Gartner's framework calls an "AI TRiSM" (Trust, Risk, and Security Management) platform. This Privacy Policy explains how Foxy Audit, a company incorporated in and operating from the Islamic Republic of Pakistan, collects, uses, and protects information in connection with the customer dashboard at app.foxyaudit.tech, the marketing site at foxyaudit.tech, the open-source foxy-audit SDK (MIT-licensed, published on PyPI), the desktop application, and the admin console (together, the "Service"). Where the desktop app's optional AI chat feature is used, prompts are sent directly from your device to the AI provider you configure (for example Anthropic, OpenAI, or a local model), using your own API key — Foxy Audit is not an intermediary for that traffic and does not receive it. Foxy Audit currently operates online without a registered physical office; this section will be updated with a registered legal entity name and address once formal SECP registration is complete.
It applies to workspace account holders, the individuals they invite to a workspace, and visitors to our sites. It does not separately govern the AI systems our customers operate — those remain the customer's own responsibility as data controller for their own end users.
A note on applicable law. Pakistan has not yet enacted a comprehensive personal data protection statute; the Personal Data Protection Bill remains in draft form before Parliament. In the interim, data-related conduct is primarily governed by the Prevention of Electronic Crimes Act, 2016 (as amended in 2025). Because we serve customers internationally, we have voluntarily built this Policy to the higher standard of the GDPR and comparable frameworks (see Sections 7 and 13–14) rather than waiting for Pakistani law to catch up, and we will update this section promptly once the Bill is enacted.
In short: The SDK hashes your prompts and responses on your own servers. Only the hash — never the content — reaches us.
Most AI observability and audit tools work by ingesting your prompts and responses onto their servers so they can be logged, searched, or reviewed. Foxy Audit is built the opposite way: it is designed as trust infrastructure that cannot leak what it never receives.
The foxy-audit SDK runs inside your own application, on your own infrastructure. When it observes an interaction, it computes a SHA-256 digest and a customer-keyed HMAC-SHA-256 Commitment of the prompt and response locally, in your own process, before anything is transmitted to us. Only the resulting Commitment, a policy tag, a token-count estimate, the model/agent name, and — if you enable it — client-side PII signal labels ever leave your environment. The plaintext does not.
Those Commitments are then chained on our servers into a tamper-evident audit ledger, so that you or an independent auditor can later verify that a given interaction occurred and matched a given policy outcome without our having held the underlying content at any point. This is enforced in our data model, not only described in this policy: our backend has no database field capable of storing a raw prompt or response.
In short: Account details, hashed keys, encrypted BYOK keys, ledger hashes, usage counts, and hashed security telemetry — never your prompts.
In short: Your prompts, your responses, your end users' data, and your BYOK key in plaintext, ever.
Where the General Data Protection Regulation applies, we rely on: performance of a contract, to provide the Service you have subscribed to; legitimate interests, for platform security, fraud prevention, and product improvement, balanced against your rights and freedoms; consent, for analytics cookies where required; and legal obligation, for tax, accounting, and regulatory record-keeping.
In short: Six categories of provider, each with one job: Google/OpenAI grade metadata, Paddle bills you, Payoneer pays us, Google handles optional sign-in, Brevo emails you, and our cloud host runs the servers. No one else touches your data.
We share a limited set of data with the following providers, strictly as necessary to deliver the Service:
We do not currently hold a SOC 2, ISO 27001, or comparable third-party attestation. Should this change, this section will be updated to reference the relevant report, together with a dedicated trust page.
In short: Ledger data lives as long as your workspace is active. Deleted workspaces are placed in a restricted, inaccessible state within 30 days of your request, and permanently erased on request — see below for how this works today.
Audit ledger. Records are retained for as long as your workspace remains active, so your compliance history stays intact and auditable. The complete ledger may be exported at any time through the Compliance Passport.
Security telemetry. Hashed IP addresses and user-agent strings are retained for 90 days by default and then purged automatically. Internal staff-action audit logs are retained for up to 365 days.
Cancellation and deletion are different actions. Cancelling a subscription ends billing at the end of the period already paid for and leaves the workspace open: an administrator can still sign in and generate the Compliance Passport described in Section 2. Deleting a workspace is the separate action described next, and it closes access.
Workspace deletion. Deleting a workspace from the dashboard immediately blocks further sign-in and API access for that workspace, and places its records in a restricted, inaccessible state. This action can be reversed by contacting us within 30 days if deletion was made in error. We are building an automated process to permanently purge data after that window; until it ships, permanent erasure is performed by our team on request, which you can make at any time through Section 18.
In short: TLS everywhere, hashed secrets, encrypted BYOK keys, database-enforced tenant isolation, and optional public blockchain anchoring for independent proof.
Multi-factor authentication. Available on an opt-in basis per account, using an emailed one-time passcode (six digits, single use, five-minute validity, stored only as a SHA-256 hash). Authenticator-app (TOTP) based MFA is not currently supported.
Enterprise single sign-on. Available on an opt-in basis per organization, using OpenID Connect (OIDC). SAML is not currently supported. An identity-provider connection is scoped to a verified email domain, and new users from that domain are provisioned into the correct organization only, on a just-in-time basis.
Administrative access. Our internal administrative console uses a session-signing secret distinct from that of the customer dashboard, supports an optional IP allow-list, and requires step-up authentication for sensitive actions. Every administrative action is recorded in a staff audit trail that is tamper-evident, independently verifiable: an entry that is edited, removed from the middle, or re-ordered breaks the chain, and because the chain's head is published to a public blockchain, so does an entry removed from the end. Entries recorded before the chain existed are not covered by it.
We use a small number of first-party cookies to maintain sign-in state and basic security on the dashboard (including a staff session cookie and a CSRF-protection cookie) — full detail, including exact retention periods, is in our Cookie Policy, not repeated here to avoid the two documents drifting out of sync. Our marketing site displays a geography-aware consent banner (opt-in in the EEA/UK, opt-out in jurisdictions such as the United States) prior to setting any optional first-party analytics cookie. We do not use third-party advertising or cross-site tracking cookies. See our Cookie Policy for full details.
In short: Your data is processed in the United States (our hosting infrastructure, Google, OpenAI, and Paddle) and the European Union (Brevo).
Based on the sub-processors listed in Section 8 and the region in which our own infrastructure runs, data is processed in the United States (our hosting provider, Google, OpenAI, and Paddle) and the European Union (Brevo). Where personal data is transferred from the EEA, UK, or Switzerland to the United States, we rely on the EU Standard Contractual Clauses, together with the UK International Data Transfer Addendum for UK transfers and Swiss Federal Act on Data Protection safeguards for Swiss transfers, as our transfer mechanisms. We do not process personal data in Pakistan — our operating company is incorporated there (Section 1), but no customer data is currently hosted or processed on Pakistani servers.
We do not limit these rights to any one region — the list below names the frameworks we specifically align with; if your home jurisdiction is not listed, the general commitment in the final paragraph of this section still applies to you in full.
Regardless of where you are located, on a verified request we will provide access to, correct, delete, or export your personal data, consistent with the architecture described in Section 3 (which structurally limits what we hold in the first place). We will respond to a verified request within 30 days (the standard period under GDPR Article 12; where a shorter period applies under other law, including certain U.S. state statutes, we will meet that shorter period). Such requests may be directed to us at privacy@foxyaudit.tech or as set out in Section 18.
In the event of a security incident that we determine is reasonably likely to result in unauthorized access to, or disclosure of, personal data we hold, we will notify affected workspace administrators without undue delay and in accordance with applicable law, together with a description of the nature of the incident and the steps being taken in response.
This section addresses incidents affecting Foxy Audit's own systems. It is distinct from the in-product policy-breach alerts your organization may configure to notify your own team when a logged AI interaction violates your organization's policy (see your Workspace notification preferences).
Children. The Service is intended for business use by adults and organizations; we do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us data, contact us and we will delete it.
Open source. The foxy-audit SDK is published under the MIT License. Reviewing its source — including the hashing and PII-detection logic described in Section 3 — is the fastest way to independently verify the data-minimization claims in this Policy, rather than taking our word for them.
We may update this Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. Material changes will be communicated to account holders by email or in-app notice prior to taking effect, and the version number and effective date above will be revised accordingly.
Questions regarding this Policy, or requests concerning personal data, may be directed to privacy@foxyaudit.tech.