Privacy

Public inquiry data stays separate from assessment evidence.

Effective September 2, 2026. This notice covers the public website, anonymous readiness screen, and high-level business inquiries.

What the consultation intake collects

When you submit the consultation form, Left Out Security receives and stores the name, business email, company, high-level description of system authority and reach, business decision or deadline, optional Founding Five interest, referral or campaign source, consent version and time, submission time, and an intake receipt identifier. The form is limited to non-sensitive business information used to determine fit and next steps.

The intake may also process bounded request metadata, including a one-way abuse-prevention representation derived from the network address used to submit the form. The public response does not expose that value, and the intake does not use it as assessment evidence.

Anonymous readiness-screen session

The Agentic Assurance Readiness Screen stores only fifteen enumerated evidence and bounded-context selections, model versions, the current question, a random anonymous session identifier, start and expiry times, and completion state in this browser tab’s sessionStorage. The screen does not request a name, email, company, free text, file, URL, credential, or assessment evidence. Session data is not placed in the page URL, cookie, persistent browser storage, analytics, or console, and it expires within 24 hours or is removed when you restart or clear the screen.

When the results page opens with a complete session, the browser sends exactly the fifteen bounded evidence and context answer pairs, their question versions, and the model versions to a same-origin Left Out Security classifier. The server recalculates the immediate result in memory and does not persist or log the answer payload or create an identified record. No name, email, company, free text, file, URL, credential, client evidence, or browser-session identifier is included in that request.

Do not send assessment evidence through the public form or ordinary inquiry email. Do not submit passwords, keys, tokens, production credentials, source code, customer data, logs, confidential architecture, regulated information, or repository and cloud-console access.

Hosting and intake providers

Providers supporting website hosting, secure intake processing, database operations, email, security, and business administration may process information needed to deliver and protect these functions. Standard request information may include IP address, user agent, requested URL, timestamps, and security or diagnostic logs. This site does not currently load a public behavioral advertising tracker.

How inquiry information is used

Inquiry information is used to evaluate fit, respond to the request, determine whether a consultation is warranted, manage the Founding Five and standard assessment pipeline, prevent abuse, maintain business records, and meet legal or security obligations. Selecting Founding Five interest does not reserve a slot or create an engagement.

Retention

Consultation intake records are scheduled for deletion after 18 months unless they are deleted earlier, become part of an active client or accounting record governed by a different documented requirement, or must be retained for a legal, dispute, fraud-prevention, or security purpose. Rate-limit records expire on a shorter operational schedule.

Assessment evidence

Client evidence is not accepted through the public website. Any later assessment evidence requires accepted written scope, authorization, handling terms, and an approved evidence channel. See the Evidence Handling Standard.

Disclosure and sale

Information is not sold. It may be disclosed when reasonably necessary to operate the service, protect rights or security, comply with law, or complete an authorized business transfer.

Your requests

To request access, correction, or deletion, email security@leftoutsecurity.com. Some records may need to be retained where required or justified.

Security and changes

Reasonable safeguards are used, but no internet, hosting, database, or email service can promise absolute security. This notice may change as the website and operating model mature. Material updates will receive a revised effective date.