cirra

Legal

Privacy Policy

Data minimization isn't a compliance afterthought at Cirra — it's how the product is architected. This policy explains what we collect, why, and what never leaves your environment.

Effective date: July 20, 2026

1. Scope

This policy describes how Cirra (“we”, “us”) handles information in two contexts: visitors to this website, and customers who deploy the Cirra Capacity Autopilot product in their own infrastructure.

The product is customer-hosted by design. It runs inside your Kubernetes or Slurm environment, and raw telemetry and cluster topology can remain entirely within your environment.

2. Information we collect on this website

We collect information you choose to send us — for example, your name, email address, company, and message when you contact us about a pilot or request our security package.

We collect standard technical logs (IP address, browser type, pages visited) to operate and secure the site. We do not sell personal information, and we do not use third-party advertising trackers.

3. Information the product processes

Cirra Capacity Autopilot is built on a data-minimization principle. By design, it does not collect source code, prompts, model weights, training datasets, request payloads, or secrets.

The product observes Kubernetes object metadata, Slurm job and node state, Prometheus-compatible metrics, and NVIDIA DCGM GPU telemetry to model workloads and physical resources. Kubernetes labels are collected only through a customer-configured allowlist, because labels can contain sensitive naming conventions.

Workload and tenant identifiers are used only as necessary for attribution, and customers may hash or pseudonymize them. Local-only operation and aggregate-only export modes are available, including a fully air-gapped report mode.

4. How we use information

Website information is used to respond to inquiries, evaluate pilot fit, and send communications you have requested.

Product data is used to construct the cluster model, generate and verify action plans, and produce the reports your team approves. An optional management plane handles licensing, software updates, and aggregate health only — no raw telemetry is required to leave your environment.

5. Sharing

We do not sell personal information. We share information only with service providers who help us operate the website and business (under confidentiality obligations), when required by law, or in connection with a corporate transaction with notice to affected parties.

6. Security

All network traffic uses TLS, with customer-managed certificates supported. Data at rest is encrypted with customer- or deployment-managed keys. Egress from the product is deny-by-default with an explicit allowlist.

Access is role-based, credentials are never logged, and an append-only audit ledger records policy changes, plan generation, approvals, mutations, and rollbacks. Release artifacts are signed, with SBOMs and vulnerability scanning as part of our supply-chain controls.

7. Retention

Website inquiry data is retained only as long as needed for the purpose it was provided.

Product retention defaults are customer-configurable: raw high-frequency metrics are kept 7–14 days locally; normalized features 90 days for a pilot; workload profiles and forecasts for the contract duration; and action plans and outcomes as append-only audit records. Sensitive workload content is not collected at all.

8. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or export personal information we hold about you, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. We will respond within the timeframes required by applicable law.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the effective date below, and, where appropriate, communicated directly to customers.

Want the deeper technical story behind these commitments?

Safety & trust