Privacy Policy
WitnessOps privacy policy.
Last updated: August 2026
Site scope
WitnessOps is a public informational and verification surface for governed security operations, signed receipts, and explicit trust boundaries.
Most proof artifacts exposed through WitnessOps are public verification materials designed to be readable, downloadable, and independently verifiable.
Data we receive
If you contact WitnessOps, we receive the information you choose to provide, including name, email address, organization, and message content.
When you submit a question through Ask WitnessOps, the question reaches the WitnessOps server. For eligible questions, it may be sent to the OpenAI Responses API with file search limited to approved public WitnessOps material. The provider request sets store: false; this does not itself mean zero data retention, and provider retention may still apply.
The application-level provider event log excludes question and response bodies. It retains only coarse request metadata for troubleshooting: provider request ID, response status, duration, and error class.
Do not include secrets, credentials, confidential information, customer or system data, or personal data in an Ask WitnessOps question.
The contact handoff does not automatically copy your Ask WitnessOps question. Contact details and the note you choose to enter are submitted only when you explicitly submit the contact form.
After mailbox confirmation for a review request, the browser may hold a narrowed request record in session storage. That record contains only the request reference, confirmation time, language, fixed request kind, and source path. It excludes the email address, note, verification code, issuance and thread identifiers, assessment identifiers, URL, and price, and follows the browser's session-storage lifecycle.
Operational systems may also generate minimal server and delivery logs required to maintain availability and security.
Public rate-limited routes may hold a short-lived, instance-local request counter keyed by client IP. The counter stops affecting access after its request window and is removed by periodic cleanup or process restart.
Public website analytics
Public information pages use Cloudflare Web Analytics to measure document loads and page performance, including visits from the EU. The beacon sends measurements to Cloudflare. This integration does not send contact-form fields or Ask WitnessOps messages as analytics events.
The beacon is not loaded on admin pages, authentication callbacks, private delivery and assessment routes, or the browser-based check and proofpack tools. Local and preview hosts are excluded. Pages with an active beacon use full-document navigation so its listeners do not continue into private pages. Automatic client-side route tracking is disabled. These measurements do not establish navigation clicks, individual visitor identity, or time spent on the site.
See Cloudflare Web Analytics for the provider's measurement approach.
How data is used
Submitted information is used strictly for:
- responding to inquiries and support requests
- handling vulnerability disclosures
- providing bounded Ask WitnessOps guidance from approved public material
- operating and securing the service
- limiting abusive or unusually high request volumes
WitnessOps does not treat published verification artifacts as private or confidential submissions.
Verification artifacts
Proof artifacts published through WitnessOps are public by design.
Do not include:
- secrets
- credentials
- personal data
in any artifact intended for publication, verification, or redistribution.
Retention
Authenticated External Exposure Early Access
The authenticated workspace stores account identity mappings, workspace membership, saved hostnames and completed observation sources. These saved observations are private workspace data, not public verification artifacts. They are unsigned. Opening a public /check result does not automatically import it into a workspace.
First-party product events record bounded action names, user/workspace/asset/run IDs, check IDs where applicable, timestamps and an app event version. They do not include hostnames, raw evidence, source bodies or feedback comments. Events help us understand activation and repeat use; they are behavior records, not security evidence. A PDF export event records the print action being requested, not confirmation that a file was saved.
Optional result and comparison feedback stores the submitted answer and comment separately from completed evidence. Do not include secrets or confidential information in feedback. Authorized WitnessOps operators may review it to improve the product.
No automatic retention period or deletion job is implemented for authenticated Early Access data yet. Signing out does not delete it, and rerunning does not rewrite previous completed sources. Contact WitnessOps about access or removal; a removal request is not a promise of automatic or immediate deletion.
Public site and correspondence
Submitted information is retained only as long as necessary for:
- correspondence
- operational integrity
- security
- legal obligations
Short-lived abuse-control counters are retained only for the active rate-limit window and periodic cleanup interval.