PPacket Pilot← Packet Pilot
LEGAL

Privacy Policy

Last updated 2026-09-05

Packet Pilot LLC (“we”) sets out below how personal information and customer data are handled across the Packet Pilot series (Silent Security Agent, AI Agent Evidence Proof, Network Change Certification and PP-TSA) and packet-pilot.net (together, the “Service”).

1. Information we collect

In providing the Service we collect the following.

  • Account information: email address, name or contact person, company or organisation, and a hash of your password.
  • Billing information: plan, contract period and payment status. We never hold the credit card number itself; it is processed by our payment provider.
  • Service usage data: API request metadata, audit logs, access timestamps, IP address and User-Agent.
  • Data handled by each product, as set out in section 2.
  • The content of your enquiries and the contact details you give with them.

2. Data handled by each product

The products differ in the data they touch. None of them collects beyond the scope defined in advance.

  • PP-TSA: we receive only the fingerprint (hash) of your data, the hash algorithm and the request metadata. There is no path by which the content of the original data reaches us.
  • AEP: we store, as proof, the sources an AI agent consulted, its decisions, the approver, the time and the configuration. Credentials such as passwords, authentication codes, API keys and access tokens are never included in proof or in notifications. Collection is limited to the signed-in organisation and the permissions granted to it; we do not collect or publish data outside that scope.
  • NCC: observation is carried out only against authenticated targets, within the scope permitted by a signed job. We do not probe outside that scope. What we collect is the network state before and after the change, and the result of the fixed-rule evaluation.
  • SSA: we handle communication facts observed on the network (metadata for TLS, DNS, HTTP, SMB, Kerberos and the like), signals, findings, incidents and evidence data.

SSA runs in the environment of the partner that licenses it under an OEM or licensing agreement. The controller of data observed in that environment is that partner, and our involvement is limited to what is set out in our contract with them.

3. Purposes of use

  • Providing, maintaining and improving the Service.
  • Identity verification, authentication and prevention of misuse.
  • Billing, payment and contract administration.
  • Investigating faults and responding to security incidents.
  • Answering enquiries and sending necessary notices.
  • Complying with legal obligations.

4. Disclosure to third parties

We do not disclose the information we collect to third parties, except in the following cases.

  • Where you have consented.
  • Where required by law, or in response to a lawful request from a court or public authority.
  • Where necessary to protect a person’s life, body or property and it is difficult to obtain consent.
  • Where we engage a subcontractor within the scope necessary to achieve the purposes of use (payment processing, cloud infrastructure and similar). We require subcontractors to apply safeguards equivalent to this policy and we supervise them.

5. Subcontractors and transfers outside Japan

The Service runs on cloud infrastructure, parts of which may be located outside Japan. Where personal data is handled by a subcontractor outside Japan, we take the measures required by law.

6. Retention periods

  • Account and billing information: retained after the contract ends for the period required by law (seven years for accounting records) and then deleted.
  • Audit logs and service usage data: retained during the contract and for a defined period after it ends.
  • Issued certificates and timestamps: retained after cancellation so that they remain verifiable.

7. Security measures

To prevent leakage, loss or damage of the information we hold, we apply the following.

  • Least-privilege access, with use restricted to what each permission allows.
  • Two-factor authentication.
  • API key management. A complete API key is shown only at issue and is never shown again. If a key is lost, a new one is issued and the old one revoked.
  • Audit logging and encryption in transit.

8. Cookies and local storage

packet-pilot.net uses browser local storage to remember display preferences such as the selected language. We do not run third-party tracking for advertising purposes.

9. Access, correction and suspension of use

You may request disclosure, correction, addition, deletion or suspension of use of the personal data we hold about you. Contact us at the address in section 11. We will verify your identity and respond without undue delay, as required by law.

10. Changes to this policy

If we change this policy, we will publish the revised version on this page. For material changes we will also notify you at your registered email address.

11. Contact

Operator
Packet Pilot LLC (Packet Pilot合同会社)
Email
product.support@packet-pilot.net