Back to Theodolite
Theodolite by vCSO.ai

Privacy Policy

How we collect, use, and protect your information
Effective: March 2026

Introduction

vCSO.ai, Inc. (“Company,” “we,” “us,” or “our”) operates the Theodolite cybersecurity decision-making platform, accessible at app.theodolite.io (the “Service”). This Privacy Policy describes how we collect, use, store, share, and protect information when you use our Service.

By accessing or using Theodolite, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.

Information We Collect

Account Information

When you create an account or are invited to the beta program, we collect your name, email address, company name, and job title.

Cloud Account & Infrastructure Data

To provide our scanning and assessment services, you may connect cloud provider accounts (AWS, Azure, GCP). When you do, we access infrastructure configuration data, security posture information, and compliance-related metadata necessary to perform our scans. We access only the resources and permissions you explicitly authorize.

Sensitive Data Discovery Results

Our data discovery features scan your connected storage (S3, Azure Blob, GCS, and local filesystems) to identify sensitive data such as personally identifiable information (PII), protected health information (PHI), financial records, and credentials. We process this data to generate classification results and risk assessments. We do not store the underlying sensitive data itself — only the metadata, classifications, and findings.

Vulnerability & Compliance Data

When you import vulnerability scan reports (Nessus, OpenVAS) or complete compliance assessments (SOC 2, ISO 27001, NIST CSF), we process and store that data to generate risk quantification outputs, compliance scoring, and recommendations.

Usage Data

We automatically collect information about how you interact with the Service, including pages visited, features used, session duration, browser type, device information, IP address, and referring URLs.

Feedback & Communications

When you provide feedback, submit bug reports, or communicate with us, we collect the content of those communications.

How We Use Your Information

PurposeData Used
Provide and operate the ServiceAccount info, cloud data, scan results, compliance data
Generate risk quantification and compliance assessmentsVulnerability data, infrastructure data, assessment responses
Identify sensitive data in your environmentsConnected storage metadata and classifications
Improve and develop the ServiceUsage data, feedback, aggregated analytics
Communicate with you about the ServiceAccount info, email address
Ensure security and prevent abuseUsage data, IP addresses, access logs
Comply with legal obligationsAs required by applicable law

Data Sharing & Disclosure

We do not sell your personal information. We do not share your data with third parties for their marketing purposes. We may share information only in these limited circumstances:

  • Service providers: We use trusted third-party providers for infrastructure hosting, analytics, and email delivery. These providers are contractually bound to use your data only as directed by us and to maintain appropriate security measures.
  • Legal requirements: We may disclose information when required by law, subpoena, court order, or government request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction, subject to the same privacy protections described here.
  • With your consent: We may share information with your explicit permission.

Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Policy. Specific retention periods:

  • Account data: Retained for the duration of your account plus 30 days after deletion request.
  • Scan results and assessments: Retained for the duration of your account. Deleted within 30 days of account termination or upon written request.
  • Sensitive data discovery results: Classification metadata is retained for the duration of your account. The underlying sensitive data scanned is not stored by us.
  • Usage and analytics data: Retained in aggregated, de-identified form for up to 24 months.
  • Communications and feedback: Retained for the duration of the business relationship plus 12 months.

You may request deletion of your data at any time by contacting us. We will process deletion requests within 30 days, except where retention is required by law.

Data Security

We implement reasonable administrative, technical, and physical safeguards to protect your information, including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls and authentication for all internal systems
  • Regular security assessments and monitoring
  • Incident response procedures with 72-hour breach notification
  • Employee security training and background checks

While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information.
  • Deletion: Request deletion of your personal information, subject to legal retention requirements.
  • Portability: Request your data in a structured, machine-readable format.
  • Restriction: Request restriction of processing in certain circumstances.
  • Objection: Object to processing based on legitimate interests.
  • Withdrawal of consent: Withdraw consent at any time, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at the address below. We will respond within 30 days (or sooner where required by law).

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected, the sources, business purposes, and third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Right to Limit Use of Sensitive Information: You may limit our use of sensitive personal information to what is necessary for the Service.

To submit a request, contact us at privacy@vcso.ai. We will verify your identity before processing any request. You may designate an authorized agent to make a request on your behalf.

European Privacy Rights (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR), including the rights listed in “Your Rights” above. Additionally:

  • You have the right to lodge a complaint with your local data protection authority.
  • Where we rely on consent, you may withdraw it at any time.
  • We will provide information about automated decision-making and profiling, if applicable.

For GDPR-related inquiries, contact our Data Protection contact at privacy@vcso.ai.

International Data Transfers

Theodolite is operated from the United States. If you are accessing the Service from outside the United States, your information will be transferred to and processed in the United States. We implement appropriate safeguards for international transfers, including Standard Contractual Clauses (SCCs) where required.

Children's Privacy

Theodolite is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will delete it promptly. If you believe a child has provided us with personal information, please contact us immediately.

Cookies & Tracking Technologies

We use the following types of cookies and similar technologies:

  • Essential cookies: Required for the Service to function (authentication, session management, security). These cannot be disabled.
  • Analytics cookies: Help us understand how the Service is used to improve performance and features. You may opt out of these.

We do not use advertising cookies or third-party tracking for behavioral advertising. You can manage cookie preferences through your browser settings.

Third-Party Services

The Service may integrate with third-party cloud providers (AWS, Azure, GCP), project management tools (Jira), and other services at your direction. When you connect these services, their respective privacy policies govern their handling of your data. We encourage you to review those policies. We access third-party services only with your explicit authorization and only to the extent necessary to provide our Service.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy on this page and updating the “Effective” date. For significant changes, we will provide notice through the Service or by email. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.

Contact Us

If you have questions about this Privacy Policy, want to exercise your rights, or have a privacy concern, contact us:

vCSO.ai, Inc.

Email: privacy@vcso.ai

Website: www.vcso.ai

For GDPR or CCPA-specific requests, please include “Privacy Request” in the subject line and specify the right you wish to exercise.