Privacy Policy
This privacy notice for Triad Secure Inc. ("Triad Secure," "we," "us," or "our") describes how and why we collect, store, use, and share ("process") information when you use our services ("Services"), such as when you:
- Visit our website at www.triadsecure.com, or any website of ours that links to this privacy notice.
- Use the Triad Secure platform at app.triad-secure.com, including its security operations, threat detection, investigation, ticketing, and reporting features.
- Engage with us in other related ways, including sales, support, advisory meetings, marketing, or events such as webinars.
Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have questions or concerns, contact us at info@triadsecure.com.
SUMMARY OF KEY POINTS
What personal information do we process? When you visit, use, or navigate our Services, we process personal information depending on how you interact with us, the choices you make, and the features you use. This is largely limited to your name, contact information, account and sign-in information, payment information handled by our payment processor, and information about how you use the Services.
Do we process data on behalf of our customers? Yes. Our customers, typically managed security service providers and the organizations they protect, connect their own systems to Triad Secure. We process that data on their behalf and under their instructions. See section 3.
Do we use data from Google? If you or your organization connects Google sign-in or Google Workspace, we access only what the features you enable require, and our use complies with Google's Limited Use requirements. See section 4.
Do we use AI? Yes. AI models analyze security data to help our customers investigate and respond to threats. Data is never used to train AI models. See section 5.
Do we sell your information? No. We do not sell personal information and do not use customer data for advertising.
How do we keep your information safe? We use organizational and technical measures designed to protect your information, including encryption in transit and at rest. No system is perfectly secure, and we cannot guarantee that unauthorized parties will never defeat those measures.
What are your rights? Depending on where you live, you may have rights regarding your personal information. The easiest way to exercise them is to email info@triadsecure.com.
TABLE OF CONTENTS
- WHAT INFORMATION DO WE COLLECT?
- HOW DO WE PROCESS YOUR INFORMATION?
- HOW DO WE HANDLE DATA WE PROCESS FOR OUR CUSTOMERS?
- HOW DO WE USE DATA FROM GOOGLE?
- HOW DO WE USE ARTIFICIAL INTELLIGENCE?
- WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?
- IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
- HOW LONG DO WE KEEP YOUR INFORMATION?
- HOW DO WE KEEP YOUR INFORMATION SAFE?
- DO WE COLLECT INFORMATION FROM MINORS?
- WHAT ARE YOUR PRIVACY RIGHTS?
- CONTROLS FOR DO-NOT-TRACK FEATURES
- DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
- DO WE MAKE UPDATES TO THIS NOTICE?
- HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
- HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
1. WHAT INFORMATION DO WE COLLECT?
Information you provide to us. We collect personal information you give us when you request information about our Services, sign up for a trial, create or are invited to an account, contact support, or otherwise communicate with us. This may include:
- Your first and last name.
- Your email address and phone number.
- Your job title and the name of your organization.
- Account and sign-in information, such as your password (stored only as a one-way hash), multi-factor authentication settings, and passkeys.
- Information you choose to add to your profile or include in support requests.
Sign-in through another provider. If you sign in with Microsoft or Google, we receive your name, email address, and an account identifier from that provider. We use these only to sign you in and to link the sign-in to your Triad Secure account.
Calendar connection. If you choose to connect your Google or Microsoft calendar, we read your upcoming events to show them on your dashboard. You can disconnect it at any time under Linked accounts in your profile settings, and we delete the stored credentials. We also disconnect it when your account is deactivated.
Payment data. Payments are processed by Stripe, Inc. Stripe collects your payment card details directly; we do not receive or store full card numbers or security codes. We receive limited information from Stripe, such as the card brand, the last four digits, the billing contact, and the status of payments. Stripe's privacy notice is available at https://stripe.com/privacy.
All personal information you provide to us must be true, complete, and accurate, and you must tell us of any changes.
Information collected automatically. When you visit or use the Services, we automatically collect certain technical information. It does not directly reveal your identity, but may include:
- Log and usage data: your IP address, browser type and settings, dates and times of access, pages viewed, actions taken in the Services, and error reports. We use this to operate, secure, and troubleshoot the Services, and to maintain audit records of activity in customer accounts.
- Device data: the type of device, operating system, and browser you use to access the Services.
- Approximate location: a general location (such as country or city) derived from your IP address, used for security purposes such as detecting unusual sign-ins. We do not collect precise device location.
- Cookies: we use cookies that are necessary to keep you signed in, protect your session, and remember your preferences. We do not use advertising or cross-site tracking cookies in the Triad Secure platform.
2. HOW DO WE PROCESS YOUR INFORMATION?
We process personal information for the following purposes:
- To create and manage accounts, and to authenticate users, including multi-factor authentication.
- To provide the Services, including the features our customers configure.
- To respond to inquiries and provide support.
- To send administrative information, such as security notices, invitations, billing notices, and changes to our terms and policies.
- To manage subscriptions, trials, and payments.
- To protect the Services, including fraud prevention, abuse detection, and monitoring for security threats.
- To understand how the Services are used so we can maintain and improve them.
- To send marketing communications, in line with your preferences. You can opt out of marketing emails at any time.
- To comply with legal obligations and enforce our terms.
We process your information only when we have a valid legal reason to do so, such as to perform our contract with you or your organization, to meet legal obligations, for our legitimate interests in operating and securing the Services, or with your consent.
3. HOW DO WE HANDLE DATA WE PROCESS FOR OUR CUSTOMERS?
Our customers connect their own systems to Triad Secure, such as security tools, identity providers, cloud accounts, email systems, and ticketing systems. Through those connections we process security events, alerts, logs, asset and identity records, email messages in mailboxes a customer designates, and related data ("Customer Data"). Customer Data may contain personal information about the customer's employees, users, or customers.
We process Customer Data on behalf of, and under the instructions of, the customer that connected it, as described in our agreement with that customer. The customer decides which systems to connect and which data to send. Customer Data is kept separate between customers.
If your personal information is contained in Customer Data, the organization that provided it to us is responsible for it, and you should direct privacy questions and requests to that organization. We will assist our customers in responding to such requests.
4. HOW DO WE USE DATA FROM GOOGLE?
This section applies when you or your organization connects Google sign-in or Google Workspace, including Gmail, to Triad Secure.
What we access, and why
- Google sign-in: your name, email address, and Google account identifier, to sign you in and link the sign-in to your Triad Secure account.
- Google Calendar (read-only), only if you choose to connect your calendar: we read your upcoming events to show them on your Triad Secure dashboard. We do not create, change, or delete events.
- Google Workspace directory (read-only): whether the person connecting your organization's Google Workspace is an administrator of it, and the names and email addresses of users and groups. We use this only to confirm that an authorized administrator approved the connection and to let your administrator choose which mailboxes Triad Secure uses.
- Gmail, only for mailboxes your organization's administrator configures:
- Sending: we send security notifications, invitations, ticket updates, and alerts from the addresses your organization configures.
- Reading and labeling: for mailboxes your organization designates as inbound (for example, a mailbox where employees report suspected phishing, or one that receives ticket replies), we read new messages, create alerts or ticket updates from them, and label messages we have processed.
- Settings: we read a mailbox's send-as settings to confirm that an address is allowed to send.
We do not access mailboxes your administrator has not configured, and we use data obtained from Google only to provide and secure these features.
Automated analysis: messages from inbound mailboxes may be analyzed by AI models, as described in section 5, to classify and summarize security events for your organization.
Sharing: we do not sell data obtained from Google APIs or use it for advertising. We share it only with service providers that host and operate Triad Secure on our behalf under contracts that restrict its use to providing our Services, as described in section 6; when required by law; or as part of a merger or acquisition, with notice to you.
Human access: our personnel do not read data obtained from Google APIs except with your organization's permission (for example, in a support request), when necessary for security purposes such as investigating abuse, or to comply with the law.
Storage and retention: data obtained from Google APIs is encrypted in transit and at rest, and access credentials are stored encrypted. When your organization disconnects Google Workspace or closes its account, we delete its Google access credentials and the email messages and attachments we retrieved from Gmail within 30 days, except copies held in backups, which are deleted on our regular backup cycle. Alerts, tickets, and investigation records created from those messages are part of your organization's Customer Data and are kept as described in section 8, with the text copied from the messages removed. Security indicators extracted from them, such as suspicious links, domains, and sender addresses, are kept as part of those records.
Your controls: you can disconnect your own Google account under Linked accounts in your Triad Secure profile settings, which revokes our access at Google and deletes the stored credentials. Your administrator can disconnect Google Workspace in Triad Secure at any time and can revoke our access in the Google Admin console. You can remove Triad Secure's access to your Google account at https://myaccount.google.com/permissions. To ask us to delete data obtained from Google, email info@triadsecure.com.
Limited Use: Triad Secure's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. HOW DO WE USE ARTIFICIAL INTELLIGENCE?
The Services use AI models to analyze Customer Data and help our customers investigate and respond to threats. Examples include triaging alerts, analyzing emails reported as phishing, summarizing investigations, and answering questions about a customer's security data. We also create embeddings (numeric representations of text) to power search across a customer's data.
Model providers. By default, we use AI models provided by Anthropic and OpenAI, including OpenAI for embeddings. We access these models through commercial agreements under which the providers do not use our inputs or outputs to train their models. They process the data only to return results to us and retain it only for limited periods for abuse monitoring and legal compliance, as described in their commercial terms.
Your own provider. A customer may instead connect its own account with a supported model provider ("bring your own key"), such as Anthropic, OpenAI, or Microsoft Azure OpenAI, or a model it hosts itself. In that case, the customer's data is sent to the provider the customer chooses, under the customer's own agreement with that provider.
No training. We do not use Customer Data, or data obtained from Google APIs, to develop, improve, or train generalized AI or machine-learning models.
AI output is provided to help security professionals make decisions. It can be wrong, and our customers remain responsible for decisions and actions taken on their behalf.
6. WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?
Service providers. We share information with vendors that perform services for us under contracts that require them to protect it and use it only as we instruct. The categories are:
- Cloud hosting, databases, and data storage.
- AI model providers, as described in section 5.
- Email delivery and communication tools.
- Payment processing (Stripe).
- Identity and sign-in providers, such as Microsoft and Google, when you choose to sign in with them.
- Customer relationship management, sales, and marketing tools.
- Monitoring, logging, and security tools.
- Finance, accounting, and professional advisers.
A current list of our subprocessors is available on request at info@triadsecure.com.
Within your organization and its service provider. If your organization uses Triad Secure through a managed security service provider, information in your organization's account is available to authorized users at that provider, and the reverse, as configured by them.
Business transfers. We may share or transfer information in connection with a merger, sale of company assets, financing, or acquisition of all or part of our business.
Legal requirements. We may disclose information if required by law, or if we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
Our servers are located in the United States. Our service providers may process information in other countries. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States, whose data protection laws may differ from those where you live.
Where information from the European Union, the European Economic Area, the United Kingdom, or Switzerland is transferred outside those regions, we rely on standard contractual clauses or other transfer mechanisms approved under applicable law.
8. HOW LONG DO WE KEEP YOUR INFORMATION?
We keep personal information only as long as necessary for the purposes in this notice, unless a longer period is required or permitted by law.
- Account information is kept while your account is active, and deleted after you or your organization request deletion, or after two years of inactivity.
- Billing and security records may be kept for up to seven years to meet legal, tax, and audit requirements.
- Customer Data is kept according to the customer's agreement with us and the retention settings the customer chooses, and is deleted after the customer's account ends, as described in that agreement.
- Data obtained from Google is deleted as described in section 4.
When we no longer have a legitimate business need to process information, we delete or anonymize it. If that is not immediately possible, for example because it is stored in backups, we store it securely and isolate it from further processing until deletion is possible.
9. HOW DO WE KEEP YOUR INFORMATION SAFE?
We use technical and organizational measures designed to protect the information we process, including encryption in transit and at rest, encrypted storage of access credentials, access controls based on least privilege, multi-factor authentication for our personnel and users, separation of each customer's data, and logging and monitoring of access. Triad Secure maintains a SOC 2 Type II report, which is available to customers and prospective customers under a nondisclosure agreement. Despite these safeguards, no electronic transmission or storage technology is 100% secure, and we cannot guarantee that unauthorized parties will never defeat them. You should access the Services only from a secure environment.
10. DO WE COLLECT INFORMATION FROM MINORS?
The Services are intended for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected such information, we will deactivate the account and promptly delete the information. If you become aware of any such data, contact us at info@triadsecure.com.
11. WHAT ARE YOUR PRIVACY RIGHTS?
You can access, correct, update, or delete information you have provided to us, or limit how we use it:
- Through your account settings. If you have an account, you can review and change much of your profile information in the Services.
- By email. Contact us at info@triadsecure.com and tell us clearly which information you want to access, change, or delete.
- Marketing emails. You can opt out of marketing emails at any time by using the unsubscribe link in any such email or by contacting us. We will still send you service messages, such as security notices and changes to our terms.
- SMS messages. If you receive text messages from us, you can stop them at any time by replying "STOP."
For any request, we may ask for information to verify your identity. We will respond as soon as reasonably practicable.
If your information is part of Customer Data, please direct your request to the organization that provided it to us, as described in section 3.
12. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers offer a Do-Not-Track ("DNT") setting. No uniform standard for recognizing DNT signals has been finalized, so we do not currently respond to them. If a standard is adopted that we must follow, we will describe our practice in a revised version of this notice.
13. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
Residents of certain U.S. states, including California, Virginia, Colorado, Connecticut, and Utah, have additional rights under their state privacy laws. Subject to the exceptions in those laws, these may include the right to:
- Know and access the categories and specific pieces of personal information we collect about you.
- Correct inaccurate personal information.
- Delete personal information.
- Obtain a copy of your personal information in a portable format.
- Opt out of the sale of personal information, targeted advertising, or certain profiling. We do not sell personal information or use it for targeted advertising.
- Not be discriminated against for exercising these rights.
We collect the categories of information described in section 1 for the business purposes described in section 2. We do not use or disclose sensitive personal information for purposes other than providing the Services.
To make a request, email info@triadsecure.com. We will verify your identity before responding, and may ask for additional information to do so. You may use an authorized agent to make a request on your behalf, with proof of authorization. We will respond within 45 days, and if we need more time we will tell you why. If we decline your request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state attorney general.
14. DO WE MAKE UPDATES TO THIS NOTICE?
We may update this privacy notice from time to time. The updated version will be indicated by a new "Last updated" date and will be effective when it is published. If we make material changes, we will notify you by posting a notice in the Services or by sending you a notification.
15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, email us at info@triadsecure.com.
16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Depending on the laws where you live, you may have the right to request access to the personal information we collect from you, change it, or delete it. To make a request, email info@triadsecure.com.
