EmergentOS · Legal

Security Statement

Effective June 2, 2026

How EmergentOS protects the security and privacy of your data

ProviderEmergentOS Inc, a Delaware corporation
AudienceCustomers, prospects, and partners (external-facing)
Contactinfo@emergentos.ai
Websitewww.emergentos.ai

1. Our Commitment

EmergentOS Inc is committed to protecting the security and privacy of your data. As a decision-intelligence platform that processes sensitive executive information, such as messages, calendar entries, and strategic decisions, we treat security as a foundational requirement, not an afterthought. This document summarises our security practices for customers, prospects, and partners.

2. Architecture

3. Access Controls

4. Data Handling

5. Infrastructure

6. Decision Provenance

Every decision record in EmergentOS includes a SHA-256 content hash linked in a chain to previous records. This provides a tamper-evident audit trail because any modification to historical records would break the hash chain. Decision records can be exported as signed PDFs with cryptographic verification for inclusion in board packs, regulatory filings, and audit documentation.

7. Compliance

StandardStatusDetails
GDPR / UK GDPRCompliantPrivacy Policy, Data Processing Addendum with SCCs/IDTA, and data-retention controls in place
Google API Limited UseCompliantPrivacy Policy includes the required Limited Use disclosures
CCPA / CPRACompliantPrivacy rights documented; no sale of personal information
Cyber EssentialsIn progressUK government-backed baseline security certification
Independent penetration testIn progressIndependent third-party assessment
SOC 2 Type IPlanned (2026)Service Organisation Control audit
ISO 27001Planned (2027)Full information-security management-system certification

8. Incident Response

We maintain a documented Incident Response Plan with defined severity levels, escalation procedures, and communication protocols. In the event of a confirmed security incident affecting customer data, we will notify affected customers without undue delay, consistent with applicable law and our Data Processing Addendum, with the nature of the incident, the data affected, the likely consequences, and the measures we have taken.

9. Responsible Disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a vulnerability in the EmergentOS Service, please report it to info@emergentos.ai. We aim to acknowledge receipt promptly, provide an initial assessment, and keep you informed of remediation progress. We will not take legal action against good-faith security researchers who follow responsible-disclosure practices.

10. Contact

General, security, and privacy contactinfo@emergentos.ai
Websitewww.emergentos.ai
ProviderEmergentOS Inc