Safeguard
Legal

Privacy Policy

Your Privacy Matters to Us

We are committed to protecting your personal information and being transparent about how we collect, use, and safeguard your data.

Last Updated: September 3, 2026

Data Protection

Enterprise-grade security measures to protect your information

Encryption

End-to-end encryption for all data in transit and at rest

Your Control

Full control over your data with easy access and deletion options

GDPR Compliant

Fully compliant with international privacy regulations

Introduction

Safeguard ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website Safeguard, use our platform, or engage with our services.

We understand that you are trusting us with your information, and we take that responsibility seriously. This policy applies to all users of our SBOM Intelligence Suite, including SBOM 360, SBOM Hub, TPRM, and Open Source Manager products.

It also covers the software we distribute for you to install: the Safeguard and Safeguard Gold browser extensions, the Safeguard IDE extension for VS Code, Open VSX and JetBrains editors, the Safeguard command-line interface and local runner, the Safeguard desktop application, the Safeguard mobile application, the Safeguard Microsoft 365 add-in, and our SDKs, CI/CD actions and MCP server. Each of those is described by name in Clients You Install below, which sets out what it can access, what it sends to us, what it changes, and what it never does.

By accessing or using our services, you agree to this Privacy Policy. If you do not agree with the terms of this policy, please do not access our services.

Information We Collect

We collect information in the following ways:

Information You Provide Directly:

  • Account registration information (name, email address, company name, job title)
  • Payment and billing information (processed securely through our payment providers)
  • Communications you send to us (support requests, feedback, inquiries)
  • Information in SBOMs and security scans you upload to our platform
  • Profile information and preferences you set in your account

Information Collected Automatically:

  • Log data (IP address, browser type, operating system, referring URLs)
  • Device information (device type, unique device identifiers)
  • Usage data (features used, actions taken, time spent on pages)
  • Cookies and similar tracking technologies

Information from Third Parties:

  • Information from identity verification services
  • Information from business partners and integrations you authorize
  • Publicly available information about your organization

How We Use Your Information

We use the information we collect for the following purposes:

Service Delivery:

  • Provide, maintain, and improve our SBOM Intelligence Suite
  • Process transactions and send related information
  • Generate security reports, vulnerability assessments, and compliance documentation
  • Provide customer support and respond to your requests

Communication:

  • Send administrative information (updates, security alerts, support messages)
  • Send marketing communications (with your consent, where required)
  • Notify you about changes to our services or policies

Analytics and Improvement:

  • Understand how users interact with our services
  • Develop new products, services, and features
  • Conduct research and analysis to improve our offerings

Security and Compliance:

  • Detect, prevent, and address technical issues and security threats
  • Protect against fraudulent or illegal activity
  • Comply with legal obligations and enforce our terms

Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

Service Providers:

We engage trusted third-party companies to perform services on our behalf, such as:

  • Cloud hosting and infrastructure (AWS, Google Cloud)
  • Payment processing
  • Analytics and monitoring
  • Customer support tools

Business Transfers:

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

Legal Requirements:

We may disclose your information if required by law or in response to valid requests by public authorities (e.g., court orders, government requests).

With Your Consent:

We may share your information with third parties when you explicitly consent to such sharing.

Aggregated or De-identified Data:

We may share aggregated or de-identified information that cannot reasonably be used to identify you.

Connectors and AI Assistants

Safeguard publishes connectors that let an AI assistant — such as Claude or ChatGPT — call our platform on your behalf. This section describes exactly what those connectors process, and applies in addition to the rest of this policy.

What a connector can access:

  • Repository identifiers and metadata: repository URLs, owner and repository names, branches, tags, and commit references
  • Software Bills of Materials (SBOMs) and dependency data, including package names, versions, licences, and supplier information
  • Vulnerabilities, findings, and remediation records associated with your projects
  • Project, product, organization, and tenant identifiers used to scope a request to your account
  • Scan jobs and scan history, including status, timing, and outcome
  • The account identity you authorize the connection with (name, email address, and organization membership)

What a connector never receives:

  • Your source code file contents. Scanning reads a repository to build an SBOM; the connector returns findings and metadata, not code. This limit describes connectors. Some of the software you install does send code that you select or scan — the IDE extension and the command-line interface both do — and each says so plainly in Clients You Install below.
  • Credentials or access tokens. Integration secrets are stored in our credential vault and referenced indirectly; they are never returned in a connector response or placed in an AI assistant's conversation.

Processing by AI assistants:

When you use a connector, the data listed above is returned to the AI assistant you connected, and is then handled under that provider's privacy policy and data-retention terms — not ours. Safeguard does not control how a third-party assistant stores or trains on conversation content. Review your provider's policy before connecting an account that holds sensitive repository data.

AI processing within Safeguard:

We use large language models to interpret natural-language queries, summarise findings, and generate remediation guidance. Where this involves a third-party model provider, that provider is listed as a subprocessor below and is contractually prohibited from training on your data.

Subprocessors:

A current list of subprocessors — including cloud infrastructure, AI model providers, and analytics vendors — is available at safeguard.sh/company/subprocessors or on request to privacy@safeguard.sh. We provide advance notice of material changes to this list.

Revoking access:

You can disconnect a connector at any time from your AI assistant's settings and from the Integrations page in your Safeguard account. Revoking access stops further data from being returned; it does not delete data already held by the AI assistant provider.

Clients You Install

Most of this policy describes our website and the Safeguard platform you use at app.safeguard.sh. This part describes the software we distribute for you to install and run on your own device or in your own infrastructure: the Safeguard and Safeguard Gold browser extensions, the Safeguard IDE extension for VS Code, Open VSX and JetBrains editors, the Safeguard command-line interface and local runner, the Safeguard desktop application, the Safeguard mobile application, the Safeguard Microsoft 365 add-in, and the automation clients (MCP server, SDKs, and CI/CD actions).

Each entry below answers the same four questions:

  • What it can access — what the software is able to read on your device
  • What it sends to Safeguard — what leaves your device, and where it goes next
  • What it writes or changes — anything it modifies on your device or in your account
  • What it never does — limits that hold whatever settings you choose

Rules that apply to every client:

  • A client that reaches your organization's data requires you to be signed in to a Safeguard account, and stops sending when you sign out. The one client that works without an account — the Safeguard Gold catalog panel — says so in its entry.
  • No client sells your information, uses it to serve advertising, or discloses it to a third party for that third party's own purposes.
  • Where a client sends content to a large language model — to answer a question, explain a finding, or draft a fix — that content is handled as described in Connectors and AI Assistants above, including the subprocessor list published at safeguard.sh/company/subprocessors.
  • Uninstalling a client ends all collection by it. Information already received by your Safeguard tenant is governed by Data Retention below, and can be deleted from your account.
  • We distribute these clients only through the marketplaces and download pages listed at safeguard.sh/download. A copy obtained anywhere else is not ours.
  • If a client's behaviour and this text ever disagree, that is a defect in one or the other. Report it to privacy@safeguard.sh and we will correct whichever is wrong.

Browser Extensions

We publish two browser extensions, on the Chrome Web Store, Microsoft Edge Add-ons and Firefox Browser Add-ons. They are separate installations with different access, and neither one includes the other's permissions.

Safeguard — the side panel

A panel for asking questions about your own findings, projects and compliance posture, and optionally for letting an assistant read and operate the tabs you group with it.

What it can access:

  • The session cookies for app.safeguard.sh and api.safeguard.sh that your browser already holds. The panel never asks for your password.
  • Two values in browser local storage on app.safeguard.sh — your user record and your active organization list — copied into extension storage by a content script that runs on app.safeguard.sh and nowhere else.
  • The tabs you explicitly add to a Safeguard tab group, and only after you grant page access. That permission is optional, is not requested at installation, and can be withdrawn at any time from your browser's extension settings.
  • Files and photos you attach to a question.

What it sends to Safeguard:

  • Your questions, your attachments, and the resulting conversation.
  • Your account identity, tenant, and organization scope, so that an answer covers your data and no one else's.
  • When you attach a tab, or turn browser mode on: the text content of that page; the browser console messages and the list of network requests for that page, when the assistant reads them; and an image of the tab captured after each step, so the assistant can see the page as well as read it. Only the two most recent images of a run are kept in the conversation.
  • Content sent for an answer is processed by Safeguard and then by the model provider that serves your deployment, as described in Connectors and AI Assistants above.

What it writes or changes:

  • With browser mode's control setting enabled, it clicks, types, scrolls, navigates, and opens or closes tabs — inside the Safeguard tab group only. Control works through your browser's debugging interface, which is why the browser displays a notification bar while it is active.
  • It stores your panel preferences and the copied session values in extension storage on your device.
  • Signing out from the panel clears those stored values and the safeguard.sh session cookies, which signs the browser out of Safeguard.

What it never does:

  • It does not read, capture, or transmit any tab outside the Safeguard tab group. Reading a page and capturing an image of it are gated the same way.
  • It does not run a content script on any website other than app.safeguard.sh. That script reads two known keys and writes nothing to the page.
  • It does not collect your browsing history, your bookmarks, your form entries, or the contents of pages you have not attached.
  • It does not operate any page until you turn control on, and it does not act outside the tab group when you do.

Safeguard Gold — the catalog panel

A panel for searching the public Safeguard Gold open source catalog: package verdicts, CVEs, KEV entries, health grades and advisories.

What it can access:

  • The Gold catalog at gold.safeguard.sh.
  • If you grant the optional permission, the address of the package page you are viewing on npm, PyPI, crates.io, pkg.go.dev, RubyGems, Packagist, NuGet, Maven Central, Docker Hub or GitHub — so that the panel can show you the verdict for the package you are already looking at.

What it sends to Safeguard:

  • Your search terms, and the package name and ecosystem read from that address.
  • Nothing else. The Gold catalog is public: this panel needs no account, and what you search is not attached to a Safeguard tenant or to your identity.

What it writes or changes:

  • Your recent searches and panel preferences, stored on your device. It does not modify any page you visit.

What it never does:

  • It does not read the contents of any page, does not read cookies, and sends nothing about a page you visit beyond the package identifier contained in its address.
  • It does not require, and cannot reach, your Safeguard account data.

IDE Extensions

The Safeguard IDE extension is published on the Visual Studio Marketplace, on Open VSX (for Cursor, Windsurf, VSCodium and compatible editors), and on the JetBrains Marketplace (for IntelliJ IDEA, PyCharm, WebStorm, GoLand, Rider and related IDEs). All three builds behave as described here.

What it can access:

  • The file open in your editor, and the text you have selected, when you run a scan, review, explanation, or fix command.
  • Your project's dependency manifests — package.json, requirements.txt, go.mod, pom.xml, build.gradle, Cargo.toml, Gemfile, composer.json and their equivalents.
  • Your workspace source tree, for the asset discovery described below. Dependency directories such as node_modules, vendor, build output and virtual environments are excluded.
  • Environment files in your project root (.env and its variants), read only to identify which AI providers and model identifiers a project is configured to use.
  • Audio, when you use voice input, and any file you attach to the assistant.

What it sends to Safeguard:

  • The contents of the file or the selection you scan, together with your question, when you run one of those commands.
  • Dependency names and versions from the manifests it scans.
  • Asset discovery records. For each framework, AI model, database, service, API endpoint, or MCP server it recognises in your project, it sends the asset type and name, the file path and line number where it was found, a short excerpt of the surrounding code, and the names — never the values — of environment variables referenced nearby.
  • From environment files: the AI provider names and model identifiers found, and the path of the file. It records that a provider key is present; it does not record the key.
  • Your account identity and tenant scope.
  • Content sent for AI features — explanations, fixes, assistant answers — is processed by Safeguard and then by the model provider that serves your deployment.

Scanning that happens without a command:

Some scanning is automatic, and you should know which:

  • Dependency manifests are scanned when you open one, when you switch to it, and shortly after you edit it, so that inline annotations stay current. If scan-on-save is enabled, saving a manifest scans it again.
  • Asset discovery runs shortly after the editor starts, every thirty minutes thereafter, and a few seconds after you save a source file.
  • Neither runs until you have signed in and your tenant is set; both stop when you sign out.
  • A full project scan at startup is off unless you enable it in the extension's settings.

What it writes or changes:

  • Fixes, dependency version bumps and code snippets, written into your files — only the ones you accept.
  • Inline annotations and diagnostics in the editor.
  • Your access token and tenant, held in your editor's own credential storage, and a local log you can open from the editor's output panel.

What it never does:

  • It does not upload your repository as a whole. A scan sends the file or the selection concerned; discovery sends excerpts, paths and identifiers, not whole files.
  • It does not send the value of any API key, password, token or other secret, including from the environment files it reads.
  • It does not record your keystrokes, and it does not send anything while you are signed out.

CLI and Local Runner

The Safeguard command-line interface is installed from cli.safeguard.sh and runs on your machine or in your build environment. The local runner is the same binary in a long-running mode, which accepts scan work from your Safeguard tenant and executes it locally. A Kubernetes operator packages the runner for self-hosted deployments.

What it can access:

  • The directory you point it at, and the files inside it. Scanning reads your dependency manifests, your lock files and, for code scanning, your source files.
  • Container images and registries you name, using the credentials configured on that machine.
  • In agent mode, the files under the working directory you started it in — reading them, and writing the ones it is asked to change.
  • Your configuration file and any Safeguard credentials stored on that machine.

What it sends to Safeguard:

  • The results of a scan: the SBOM, the dependency and vulnerability data, licences, supplier information, and scan metadata such as timing and outcome.
  • In agent mode, the contents of the files it reads in order to carry out your instruction, sent to your platform's agent endpoint and from there to the model provider that serves your deployment.
  • When run as a local runner: a poll for pending jobs, the status of each job it claims, and the results and result files for the jobs it completes.
  • Your account identity and tenant scope on every authenticated call.

What it writes or changes:

  • Output files you ask for — SBOMs, reports, SARIF and JUnit results — at the paths you specify.
  • Fixes and dependency upgrades in your project, when you run a remediation command or approve a change in agent mode.
  • A local configuration and credential file, and local logs.

What it never does:

  • It does not scan or transmit anything outside the directory you point it at.
  • It does not upload your source tree in order to run a dependency scan. The analysis happens on your machine and the findings are what leave it.
  • It does not send results anywhere while unauthenticated. A scan run without credentials writes its output locally and transmits nothing.
  • The local runner accepts work only from your own tenant, and only the jobs it has claimed. It opens no inbound port and accepts no connection from us.

Desktop Application

The Safeguard desktop application for Windows, macOS and Linux loads the Safeguard web application alongside a local panel that can scan projects, run commands, host MCP servers, and carry out tasks on your device. It is the most capable client we ship and the one that reaches furthest into your machine, so this entry is the longest. It is currently released as a beta.

What it can access:

  • Folders you grant it through your operating system's own folder picker. Every file operation is checked against that list, and a path outside it is refused.
  • A fixed list of programs it is allowed to run: the Safeguard CLI, git, docker, npm, yarn, pnpm, python, python3 and node.
  • Your screen, and mouse and keyboard control, when you enable computer use. Permission is granted per application, and banking, cryptocurrency, password manager and trading applications are blocked by default.
  • MCP servers you start from the panel — the bundled Safeguard server, and any external server you connect it to.
  • The Safeguard web application, which it loads in its main view. That view is restricted to safeguard.sh addresses, and external links open in your ordinary browser.

What it sends to Safeguard:

  • Scan results. Scanning runs on your device through the bundled command-line binary; what leaves the machine is the SBOM, dependency and vulnerability data it produces, not your source files.
  • Tasks you type into the panel, and what the agent needs in order to carry them out.
  • Anything you do inside the Safeguard web application it displays, exactly as if you had opened that application in a browser.
  • Your account identity and tenant scope, and a version check against our update feed.

What it writes or changes:

  • Files inside the folders you have granted, when a task or a fix you approved changes them.
  • Screenshots taken before and after each computer-use action, written to a log folder inside the application's own data directory on your device.
  • Application settings, scheduled tasks, and your MCP server configuration.
  • Application updates, checked for at launch and every four hours.

What it never does:

  • It does not read files outside the folders you have granted, and it cannot add a folder silently — your operating system's picker is the only way to grant one.
  • It does not upload the computer-use screenshots. They are written to the local log folder for you to review or delete.
  • It does not take mouse or keyboard control until you enable computer use for a named application, and it asks for your approval before an action it judges destructive.
  • It does not run arbitrary programs. A command outside the allowlist above is refused, whatever asked for it.

Mobile Application

The Safeguard mobile application is a native shell that displays the Safeguard search page. It is currently a beta, distributed as an Android package from safeguard.sh/download; the App Store and Google Play listings are not yet publicly released. When they are, the App Privacy label and the Data safety form published there will describe the same behaviour set out here.

What it can access:

  • Your microphone, when you use voice input in search.
  • Your camera and photo library, when you attach a photo or a file to a question.
  • Network access, to load the Safeguard web application.

What it sends to Safeguard:

  • What you enter in the Safeguard search page it displays: your questions, your attachments, and any voice recording you choose to make.
  • Your sign-in credentials, entered into Safeguard's own login page rendered inside the application. The application does not implement its own login and does not read what you type into that page.
  • Your account identity and tenant scope, as part of the session that page establishes.

What it writes or changes:

  • Session cookies and web view storage on your device, so that you are not asked to sign in each time you open it. Signing out, or clearing the application's data, removes them.

What it never does:

  • It does not access your contacts, your calendar, your messages, your precise location, or any file you have not attached.
  • It does not use the microphone or the camera except while you are actively recording or attaching, and your operating system asks for your permission before either is used.
  • It does not track you across other applications or websites, and it contains no advertising or third-party analytics software.

Microsoft 365 Add-in

Not yet released. The Safeguard add-in for Microsoft 365 is in development. This entry is published in advance so that the description exists before the add-in does, and it will be revised to match the released build before that build is listed. Nothing described here is collecting anything today.

The add-in runs as a task pane inside Excel, Word, PowerPoint and Outlook, hosted from app.safeguard.sh. It signs you in with your Microsoft identity where single sign-on is available in your tenant, and otherwise through a sign-in page opened in a dialog.

What it can access:

  • The document, workbook, presentation or email message you have open, at the moment you ask the add-in to act on it — a selection, a sheet, or the body of the message in front of you.
  • Your Microsoft account identity, for sign-in.

What it sends to Safeguard:

  • The content you ask it to act on, and your instruction.
  • Your Safeguard account identity and tenant scope.
  • Content sent for an answer is processed by Safeguard and then by the model provider that serves your deployment.

What it writes or changes:

  • Text or content it inserts into the document or the message you are editing, when you accept it.
  • Your add-in preferences.

What it never does:

  • It does not read your mailbox, your files, or your calendar in the background. It reads what is in front of you, when you ask it to.
  • It does not send anything while you are signed out, and it keeps no copy of your document.

Automation Clients

These clients run in your own pipelines and tooling rather than on a personal device, and they send what your configuration tells them to send.

MCP server

Our hosted MCP server at mcp.safeguard.sh lets an AI assistant operate the Safeguard platform on your behalf. What it exposes, what it returns, and what an assistant provider then does with the result are described in Connectors and AI Assistants above, which applies to it in full. The same server is bundled with the desktop application, where it runs locally.

SDKs

Our Python, TypeScript, Go, Java and Rust SDKs are libraries you build into your own software. They send what your code asks them to send, authenticated with the API key you supply. They collect nothing on their own account, add no telemetry, and report no usage back to us beyond the API calls your code makes.

CI/CD actions

Our GitHub Action, GitLab CI templates and equivalent integrations run a scan inside your pipeline and fail the build against the policy you set.

  • They read the directory of the repository being built, to find its dependency manifests.
  • They send the dependency names and versions found, and receive the verdicts. The Gold scan action queries the public Gold catalog and needs no account; the platform actions authenticate with the token you configure and record the scan against your tenant.
  • They write their results into your build — a check result, a job summary, and SARIF or JUnit output where you have asked for it.
  • They do not send your source code, your build logs, your environment variables, or your repository secrets.

Webhooks and event streams

Where you configure Safeguard to deliver events to your own endpoint or stream, data flows from us to you. We send the event payload you subscribed to, and we read nothing back from the destination.

Data Security

We implement robust security measures to protect your information:

Technical Safeguards:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Regular security assessments and penetration testing
  • Multi-factor authentication options
  • Role-based access controls

Organizational Measures:

  • Employee security training and awareness programs
  • Background checks for employees with data access
  • Incident response procedures
  • Regular security audits and compliance reviews

Infrastructure Security:

  • SOC 2 Type II (audit in progress) data centers
  • Redundant systems and regular backups
  • 24/7 security monitoring and alerting
  • Network segmentation and firewalls

While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

Data Retention

We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Account Data:

Retained for the duration of your account and for a reasonable period thereafter for legal and business purposes.

Usage Data:

Generally retained for 24 months for analytics purposes, then aggregated or deleted.

Security Scan Data:

SBOMs, vulnerability records, and findings are retained for the life of the project they belong to, so that you can compare a scan against its history. Deleting a project deletes its SBOMs, findings, and scan history.

Repository and Integration Data:

Repository metadata (URLs, branches, tags) is retained for as long as the integration that references it exists. Deleting an integration removes its stored repository metadata and credentials. Scan job records — status, timing, and outcome — are retained for 13 months and then deleted.

Credentials:

Integration credentials (personal access tokens, app passwords, registry keys) are held in an encrypted vault and deleted immediately when you remove the integration or rotate the secret.

Communication Records:

Support tickets and communications are retained for 5 years for quality assurance and legal purposes.

How to delete data:

Projects, integrations, and scan history can be deleted from your account at any time via the Safeguard app, the API, or a connector. To request deletion of everything associated with your account, email privacy@safeguard.sh. When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal purposes.

Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

Access and Portability:

You can request a copy of the personal information we hold about you in a structured, commonly used format.

Correction:

You can request that we correct inaccurate or incomplete personal information.

Deletion:

You can request that we delete your personal information, subject to certain exceptions.

Restriction:

You can request that we restrict the processing of your personal information in certain circumstances.

Objection:

You can object to our processing of your personal information for direct marketing purposes.

Withdraw Consent:

Where we rely on consent to process your information, you can withdraw that consent at any time.

To exercise these rights, please contact us at privacy@safeguard.sh or through your account settings.

We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.

Cookies and Tracking

We use cookies and similar technologies to enhance your experience:

Essential Cookies:

Required for the operation of our website and services. These cannot be disabled.

Analytics Cookies:

Help us understand how visitors interact with our website. We use this information to improve our services.

Functional Cookies:

Enable enhanced functionality and personalization, such as remembering your preferences.

Marketing Cookies:

Used to deliver relevant advertisements and track campaign effectiveness. These are only used with your consent.

Managing Cookies:

You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our services.

We also use similar technologies such as web beacons, pixels, and local storage to collect information and improve our services.

International Data Transfers

Safeguard is based in the United States. If you are accessing our services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries.

Safeguards for International Transfers:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements with our service providers
  • Privacy Shield certification where applicable
  • Binding Corporate Rules for intra-group transfers

We ensure that any international transfers of personal data are made in compliance with applicable data protection laws and with appropriate safeguards in place.

Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16.

If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information as soon as possible.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at privacy@safeguard.sh so that we can take appropriate action.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.

Notification of Changes:

  • We will post the updated policy on this page with a new "Last Updated" date
  • For material changes, we will notify you by email or through a prominent notice on our website
  • We encourage you to review this policy periodically

Your continued use of our services after any changes indicates your acceptance of the updated Privacy Policy.

Questions About Privacy?

If you have any questions about this Privacy Policy or our data practices, please contact us.

Email

privacy@safeguard.sh

Mail

Safeguard Privacy Team 7779 Topaz Circle Dublin, CA 94568

For GDPR-related inquiries, you may also contact our Data Protection Officer at dpo@safeguard.sh

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.