Data Sovereignty & Privacy Policy
IronGap Technologies — Operator of Vault-OS Sovereign Enclaves
IronGap Technologies operates on a fundamental principle: your data never leaves your physical hardware. Vault-OS is an air-gapped on-premises cognitive enclave. We do not collect, monitor, inspect, transmit, or monetize customer documents, model inferences, chat transcripts, vector embeddings, or user identities. Once deployed, the appliance has zero outbound egress.
Scope of This Policy & Architecture Overview
This Privacy Policy applies to the official web services of IronGap Technologies (including iron-gap.com, client onboarding portals, and software license administration) and the offline operational principles governing the Vault-OS cognitive computing appliance.
Unlike multi-tenant cloud AI APIs that process customer prompts on external servers, Vault-OS runs 100% locally on your dedicated bare-metal silicon, virtual hypervisors, or sealed hardware enclaves.
Website & Client Portal Data Collection
When you interact with our commercial website or provision a client enclave account, we collect only the minimal data strictly required to manage your software subscription and issue cryptographic licenses:
- Account Information: Full name, organizational email address, company name, and department/role.
- Cryptographic Credentials: Master password hashes (hashed using scrypt/bcrypt with unique salts; plaintext passwords are never stored or transmitted).
- Google OAuth Authentication: When using Google Sign-In, we receive your email and verified name to authenticate your account. We do not request or access your Google Drive, contacts, emails, or personal files.
- Hardware Telemetry Keys: Customer-provided hardware fingerprint identifiers (such as TPM 2.0 endorsement keys or CPU UUIDs) provided solely to sign your offline activation license.
On-Premises Vault-OS Operational Isolation
Inside the customer’s deployed Vault-OS environment:
All PDFs, legal discovery docs, and text files indexed into local PostgreSQL/pgvector remain stored inside customer-encrypted volumes with zero cloud copies.
Local LLMs (Llama 3, Mixtral, Qwen, DeepSeek, Gemma) execute directly on host GPUs (NVIDIA TensorRT / vLLM) with zero telemetry sent to model creators or IronGap.
The Serialized Advisory Lock Burn Protocol
Vault-OS incorporates a military-grade cryptographic wiping sequence known as the Burn Protocol. Initiating an enclave purge triggers a serialized Postgres advisory lock (ID: 9999) that performs:
- Immediate session revocation and cryptographic token invalidation.
- Cascading TRUNCATE across all document collections, chat messages, embeddings, and workspace indexes.
- Low-level file system unlink (fs.rmSync) across physical disk buffers.
- Cryptographic key shredding, leaving storage sectors permanently unrecoverable even under forensic hardware extraction.
International Regulatory Compliance
Because Vault-OS eliminates cloud data transmission entirely, it intrinsically complies with the strictest global data sovereignty regulations:
- GDPR (EU Data Protection Regulation): Satisfies data localization, strict purpose limitation, and Article 17 "Right to be Forgotten" through the one-click Burn Protocol.
- HIPAA / HITECH (Healthcare): Protected Health Information (PHI) never leaves hospital/clinical networks; zero Business Associate Agreement (BAA) cloud exposure.
- ITAR & Defense Standards: Qualified for aerospace, defense, and national security environments where processing on commercial clouds is prohibited by law.
- SOC 2 Type II & ISO 27001 Alignment: Zero external dependencies, immutable audit logging, and strict role-based access control (RBAC).
Third-Party Data Disclosures & Subprocessors
IronGap Technologies does not sell, rent, lease, or share customer data under any circumstance.
For our marketing and licensing portal (iron-gap.com), we utilize only tier-1 infrastructure providers bound by rigorous confidentiality agreements (Vercel for static edge hosting, Supabase for authenticated portal sessions, and Resend for transactional verification emails). None of these providers have access to customer on-premise Vault-OS deployments.
Data Subject Rights & Contact Information
You possess the right to inspect, correct, export, or delete any account profile data stored on our commercial portal. To exercise your rights or request compliance audits, contact our security officer directly: