Governance record
Privacy Policy
What Edgion Shield processes, what can enter the delayed public aggregate, and how optional AI processing is bounded.
Effective 11 July 20261. Data within your deployment
Edgion Shield processes the configuration and operational data required to run the service, including account identity, verified domains, DNS and origin configuration, mail metadata, security events, traffic analytics, audit records, and support communications. Customer traffic telemetry is designed to remain within the infrastructure the customer operates, subject to the public aggregate described below.
2. Delayed public telemetry
When the public telemetry feature is legally enabled, a server-side process may publish one delayed global aggregate. It can contain rounded request rate, blocked volume, latency, DNS measurements, country codes for sufficiently broad blocked-request clusters, and role-level topology health.
The public response does not include an IP address, domain, URL or path, DNS name, tenant, site, account, agent, origin, rule, hash, error, or raw log. A snapshot is withheld unless minimum contributor, visitor, delay, and customer-dominance thresholds pass. Suppression occurs before serialization; the browser does not receive hidden customer fields.
3. Optional AI processing
Account AI features are opt-in and disabled by default. When enabled for an eligible deployment, Edgion may send numeric aggregates, enums, and an ephemeral scope reference to OpenAI as an external processor. Raw logs, customer prompts, domains, site identifiers, and direct personal identifiers are excluded from the model input.
Production AI processing requires an approved OpenAI project with Zero Data Retention and uses non-storage requests. A privacy-preserving HMAC may be used as a safety identifier. Edgion stores the validated result, evidence, model and version, token usage, decision, actor, policy version, and execution outcome—not the raw prompt or raw provider response.
4. Authority and human oversight
Observe is read-only. Recommend requires owner or administrator approval before a supported action can execute. Autopilot operates only inside a time-limited delegation and can apply a temporary protection-raising overlay. It cannot change DNS, TLS, origins, accounts, permissions, billing, customer data, allow or deny lists, Geo or ASN policy, or arbitrary software and network commands.
5. Service providers and international processing
Infrastructure, email delivery, payment, support, and—when explicitly enabled—OpenAI may process the limited data required for their function. Their systems may operate in other countries. Edgion limits data by purpose, access role, contract, and the product boundaries described in this policy. Payment credentials are handled by the payment provider rather than Edgion Shield.
6. Retention and deletion
Traffic analytics follow the active published plan retention period unless a lawful administrator setting provides otherwise. Security, billing, abuse-prevention, and audit records may be retained longer when required for disputes, safety, or legal obligations. Expired AI overlays stop affecting policy; related audit evidence may remain for governance and incident review.
7. Security and choices
Edgion Shield uses tenant isolation, least-privilege access, verified administrative actions, and fail-closed execution boundaries. You may request access, correction, export, or deletion where applicable. Some billing, audit, abuse-prevention, or legal records may need to be retained, and requests are verified before data is disclosed or changed.