Who we are
Argus DSPM ("Argus", "we") provides a data security posture management platform. For personal data described in this policy, we act as the data controllerin respect of our website visitors and the people who administer a customer account, and as adata processor in respect of any personal data contained within a customer's cloud environment.
Argus is operated by a company in formation. Until incorporation completes we publish the trading name above rather than a registered entity, and you can reach a human at the addresses at the foot of this page. We will publish the registered entity and address here as soon as they exist.
The distinction that matters most
Argus is a scanning product, so the obvious worry is that we accumulate copies of your sensitive data. We do not, and the architecture is what prevents it rather than a promise.
The scanning agent runs inside your own cloud account. It reads objects there, classifies them there, and discards the content. What crosses the boundary to our control plane is a structured finding: a count, a category, a confidence score, a resource identifier, a configuration fact such as whether encryption is enabled. Raw bytes, file contents and the matched values themselves stay in your environment and are never transmitted to, stored by, or visible to us.
A practical consequence: if your S3 bucket contains 12,000 social security numbers, we learn that the bucket contains 12,000 items classified as social security numbers. We do not learn, and cannot retrieve, any of those numbers.
What we collect
When you contact us
Our contact form collects your name, email address, and optionally your company, phone number, what you are looking for, a free-text description of your environment, and a file you choose to attach. We use this to reply to you and to assess whether Argus fits your needs. The form also contains a hidden field that humans never see; if it is filled in we treat the submission as automated and discard it.
Please do not attach production credentials, live configuration exports or actual customer data to a contact form. An architecture diagram is useful; a secrets file is not.
When you use the platform
To operate an account we hold the account holder's name, email address, hashed password, job title, timezone, role assignments, and multi-factor authentication enrolment data. We record authentication events and an audit log of actions taken in the product, including who performed them and what changed.
We also hold the findings your agent reports (as described above), the cloud account identifiers and resource metadata needed to attribute them, and the configuration you create in the product: policies, remediation workflows, approvals and their outcomes.
On this website
This marketing site runs no analytics, no advertising trackers and no third-party scripts. We do not set cookies here. The only thing stored in your browser is your light or dark theme preference, kept in local storage on your own device, which we never read and which is not transmitted anywhere.
Why we are allowed to hold it
- Contract - operating an account for a customer who has asked us to.
- Legitimate interests - replying to an enquiry you sent us, keeping the service secure, preventing abuse, and maintaining an audit trail. We consider these balanced against your interests because the data is minimal and directly connected to a service you approached us about.
- Legal obligation - retaining records we are required to keep.
Where we act as a processor for a customer, the customer determines the purpose and our instructions come from them.
Who else sees it
We use a small number of service providers to run Argus. Each is listed individually, with what it processes and where, on our sub-processors page. We maintain that list so it can be checked rather than assumed, and we will publish changes to it before they take effect.
We do not sell personal data, and we do not share it for advertising or cross-context behavioural advertising. We have never done so.
How long we keep it
| Data | Retention |
|---|---|
| Contact form enquiries | 24 months from last contact, then deleted |
| Account and profile data | For the life of the account, then deleted within 30 days of closure |
| Findings and scan results | For the life of the account; deleted with the tenant |
| Audit log | 400 days, then purged automatically |
| Backups | Rolling window; deleted records age out as backups rotate |
The audit log window is deliberately longer than a year so that an annual compliance review can look back across a full previous period. It is a compliance decision, not a storage one.
Where it is processed
Customer data scanned by the agent is processed in your own cloud account, in the regions you deploy into. It does not move.
Findings, account data and the control plane are currently hosted inFalkenstein, Germany. We are moving the control plane to United States infrastructure, and will update this page and thesub-processors page before that move happens. Either way, the data your agent scans stays in your own environment and is not part of the move.
Where personal data is transferred internationally, we rely on the appropriate safeguards for that transfer, including standard contractual clauses where required.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to object to or restrict how we use it, to receive it in a portable format, and to withdraw consent where we relied on it. If you are in California, you additionally have the right not to be discriminated against for exercising these rights; note again that we do not sell or share personal data.
Email privacy@argusdspm.com and we will respond within 30 days. We will ask you to verify your identity first, because handing account data to whoever asks for it would be its own privacy failure.
If you are an end user whose personal data sits inside a customer's cloud environment, we are processing it on that customer's behalf. Please direct your request to them; if you reach us instead, we will forward it and tell you we have.
If you are in the UK or EEA and we have not resolved your concern, you have the right to complain to your local supervisory authority.
Security
Our technical and organisational measures are described in detail on thesecurity page, including encryption, access control, tenant isolation and how to report a vulnerability. If you believe you have found one, please emailhello@argusdspm.com rather than filing a public issue.
Children
Argus is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes
If we change this policy materially, we will update the date at the top of this page and, for changes that affect how we handle customer data, notify account administrators by email before the change takes effect.
Contact
Privacy questions and rights requests: privacy@argusdspm.com. Everything else: hello@argusdspm.com.