Privacy & Data Governance Policy
Effective Date: March 2026 · Version 1.2
1. Foundational Commitment: Zero Client Data Training
At Alector Lab ("Company", "we", "us", "our"), we operate under a strict enterprise covenant: We never utilize client operational data, video streams, documents, telemetry, or system outputs to pre-train, fine-tune, or improve general foundation models or third-party artificial intelligence systems without explicit written consent.
2. Information We Collect
We collect information strictly necessary to deliver engineering services, evaluate architectural feasibility, and operate client-contracted software:
- Direct Inquiries: Contact information, organization details, system throughput constraints, and project specifications submitted via our intake channels.
- Technical Telemetry: In managed deployments, anonymized performance metrics including pipeline latency, inference frames-per-second, memory allocation, and error status codes.
- Website Analytics: Privacy-preserving aggregated traffic statistics without invasive third-party cross-site tracking cookies.
3. Deployment Topology & Isolation
Our default engineering standard deploys all AI models, agent orchestrators, and vector databases within isolated, client-owned Virtual Private Clouds (VPC) or client-specified bare-metal infrastructure. Data processing occurs strictly within the client boundary.
4. Data Security Standards
All data in transit is encrypted using TLS 1.3 or higher. All data at rest across vector indices, model cache layers, and databases is encrypted using AES-256. Access to client staging environments requires multi-factor authentication (MFA) and is governed by strict principle-of-least-privilege (PoLP).
5. Contacting the Security Team
For security audits, vulnerability disclosures, or inquiries regarding data processing addenda (DPA), please contact our security team at security@alectorlab.com.