Legal

Privacy policy

Last updated: September 23, 2026

01Overview

Armature, Inc. ("Armature", "we", "us") helps software products get discovered and used by AI coding agents. This policy explains what personal data we collect, how we use it and what choices you have.

This policy covers four separate things. Each one handles data in a different way, so each one has its own section. A section applies only to the thing it names. It never applies to the other three.

Website
You visit armature.tech, read the leaderboards, the library or the blog, send us a form or book a call. Section 02 applies.
Readiness scanner
You use the free Agent Discoverability Readiness scanner to test a public website. Section 03 applies.
Discoverability service
Your company pays us to run the Agent Discoverability service. This service needs no data from you. Section 04 applies.
Armature platform
You or your company use MCP Analytics, MCP & CLI Evals or AI Traffic in the Armature app. Section 05 applies. The platform is the only part of Armature that receives data from your systems.

Section 06 covers the contact details of the people we do business with. Sections 07 to 16 apply to all four, but only to the data that sections 02 to 06 describe.

If you use a product that one of our customers built, that customer's privacy policy applies to you. Please contact that customer first.

02Website

Scope: this section applies only to your visits to armature.tech and leaderboards.armature.tech, including the leaderboards, the library, the blog and our forms. It does not apply to the scanner, the Agent Discoverability service or the Armature platform.

Traffic data: we measure traffic with Vercel Analytics, which stores no identifier on your device. We also record page views and clicks with PostHog, without a person profile. Section 14 explains both.

Forms: when you send us the contact form or a leaderboard form, we receive what you type in it, such as your email address, your company and your message. The form sends it to our team's Slack workspace, and we use it to reply to you.

Calls: when you book a call, the Cal.com scheduler collects the details you enter, such as your name and your email address.

Advertising measurement: we load the X advertising pixel and the LinkedIn Insight Tag so we can measure campaigns we run on X and LinkedIn. These tags may set cookies or similar identifiers and send visit data to X or LinkedIn. When you send us a contact form or a lead form, or book a call, we also report that a contact was completed. We report it without the content of your message or your email address.

03Agent Discoverability Readiness scanner

Scope: this section applies only to the free Agent Discoverability Readiness scanner at armature.tech/agent-readiness. The scanner needs no account. It is separate from the Agent Discoverability service and from the Armature platform, and their sections do not apply to it.

When you submit a domain, Armature makes bounded read-only requests to that public website, linked public documentation, and fixed public registries. We follow robots rules. We also honor the ArmatureDiscoverabilityScanner: disallow and legacy AgentReadinessScanner: disallow opt-out directives. We do not sign in or submit credentials.

Exa is a web search provider. For Exa checks, we send the canonical public domain, a derived brand name, and fixed search text. We run two general searches and nine fixed directory searches. We do not send raw page bodies to Exa.

The latest complete result can appear on a public domain result page and in the public Agent Discoverability leaderboard. The page shows the public domain, test outcomes, public evidence, corrective actions, and scan time. It does not publish visitor identity, network data, raw artifacts, or scanner secrets.

A result page may request the public domain icon from Google's favicon service. The request uses a no-referrer policy.

We use a signed essential cookie to limit abuse. It contains a random identifier and issue time. It is not an account and is not used for advertising. We also keep one-way network and requester keys, and may use a server-validated bot challenge. Browser code never receives the raw network address, signing secrets, or scanner backend address.

Completed scan data and HTTP metadata are kept for at most 90 days. Raw scan artifacts expire after 7 days. Scan events expire after 24 hours. The public result cache expires after 24 hours. Access and security logs expire after 30 days. Encrypted backups expire within 90 days. To stop future scans or ask for deletion, email privacy@armature.tech. We verify control of the domain without asking for credentials.

04Agent Discoverability service

Scope: this section applies only to the Agent Discoverability service, the growth service that we run for a company for a monthly fee. It does not apply to the website, the scanner or the Armature platform.

The service needs no data from you. We do not ask for access to your systems, your code, your accounts, your analytics or your users' data, and we do not receive any of them. You install nothing, and you connect nothing to Armature.

We test from the outside. Our coding agents run in our own isolated sandboxes, on test repositories that we own. They read only public information, such as your public website, your public documentation, package registries and the public web. No test runs in your codebase or on your production systems.

We test coding agents from providers such as Anthropic, OpenAI, Cursor, Meta and xAI. Other AI models act as the user and score the results. All these models receive only our test tasks, our test repositories and public information. They receive nothing from you.

The results show which products coding agents choose, yours and others. They contain no personal data. We also write drafts for you, such as guides or documentation pages. Your team reviews every draft, and you decide what to publish.

The only personal data that the service uses is the contact details of the people we work with, such as their names and work email addresses. Section 06 covers that data.

If you later decide to share data with us, for example a traffic report, we first agree in writing on what you share and how we use it. That agreement then applies to that data. If your company also uses the Armature platform, section 05 applies to that use, and only to that use.

05Armature platform

Scope: this section applies only if you or your company use the Armature app at app.armature.tech or eu.armature.tech. The app runs MCP Analytics and MCP & CLI Evals, our Agent Usability products, and AI Traffic, which is in private beta. This section does not apply to the website, the scanner or the Agent Discoverability service.

The platform is the only part of Armature that receives data from your systems. It receives this data only after you install our software development kit (SDK) or our package.

Account data: when you create an account, we collect your name, your email address and your workspace details.

Billing data: Stripe processes payments. We receive the billing status and invoices, and we never store card numbers.

Session data: customers install our SDK in their MCP (Model Context Protocol) servers, Claude Connectors or ChatGPT Apps. The SDK sends us agent session data, such as tool calls, user intents and agent output. Detection models scan this data and redact personal information and secrets by default, before anything reaches storage.

Eval data: we store the eval suites that you define and the runs they produce. In a run, real agents replay workflows against your MCP server or command-line interface (CLI), and we store the resulting transcripts and scores.

AI Traffic data: our package on your server sends us data about requests from AI crawlers and other bots. For each request, it sends the time, host, path, method, status, user agent and source IP address. It removes query strings, and it does not collect cookies, request bodies or authorization headers. We use the IP address to check the crawler, and then we discard it. We may keep a keyed hash of it to detect abuse.

Usage data: we record how you use the Armature app with privacy-preserving product analytics. The app also loads the X pixel when you visit it or create an account.

For session data, eval data and AI Traffic data, we act as a processor. We process that data on behalf of our customer, who decides what to send. If you are an end user of a customer's product, that customer's privacy policy applies to you, and you should contact them first.

06People we do business with

Scope: this section applies to the people we deal with at customers, prospects, partners and suppliers, for all our products, including the Agent Discoverability service.

We keep their contact details, such as their name, work email address, company and job title. We also keep our emails and messages, our notes from calls, and the contracts and invoices.

We get these details from you, from your colleagues, or from public professional sources such as company websites and LinkedIn.

We use them to talk with you, to do the work we agreed on, to send invoices and to keep business records. We keep them in our email, calendar, customer relationship management (CRM), note and accounting tools.

07How we use data

We use personal data only for these purposes:

  • To provide and run our products. In the Armature platform, this includes running AI models that rebuild, classify and score sessions.
  • To bill customers and manage accounts.
  • To answer your messages and support requests.
  • To secure our products and prevent abuse.
  • To improve our products.
  • To measure advertising campaigns we run on X and LinkedIn. We do this on the website and in the Armature app only.

We do not sell personal data.

09Subprocessors

We share data only with the providers we need to run our products. The last column shows which products use each provider.

ProviderWhat it doesUsed by
Amazon Web ServicesCloud infrastructure and storage, in EU and US regions.Scanner, discoverability service, platform
SupabaseDatabases and authentication, in EU and US regions.Scanner, discoverability service, platform
VercelHosts the website, the scanner and the front end of the app.Website, scanner, platform
E2BIsolated sandboxes where agents run for evals and for discoverability tests.Discoverability service, platform
Daytona, BlaxelIsolated sandboxes where agents run for discoverability tests.Discoverability service
Anthropic, OpenAIIn the platform, AI models that classify and score sessions. In the discoverability service, the coding agents that we test and the models that run the tests, with no data from you.Discoverability service, platform
GoogleIn the platform, AI models that classify and score sessions. In the discoverability service, models that run the tests, with no data from you. On scanner result pages, the favicon service.Scanner, discoverability service, platform
Cursor, Meta, xAICoding agents and models that we test, with no data from you.Discoverability service
ExaWeb searches for the scanner checks.Scanner
CloudflareBot checks on our forms and on the scanner.Website, scanner
XAdvertising measurement for campaigns we run on X.Website, platform
LinkedInAdvertising measurement for campaigns we run on LinkedIn.Website
StripePayment processing.Platform
PostHogAnonymous interaction analytics for the website, and product analytics for the app.Website, platform
SlackDelivers form messages to our team, and alerts to customer workspaces when the customer sets them up.Website, platform
ResendTransactional email, such as sign-in and account messages.Platform
Customer.ioProduct and marketing email to registered users.Platform
Cal.comScheduling when you book a call from the website.Website

We may also disclose information when the law requires it.

10Hosting and transfers

The Armature platform runs in two regions: an EU-based hosting region and a US-based hosting region. Customers choose where their workspace lives when they sign up. Data in an EU workspace is stored and processed in the EU.

The website, the scanner and the Agent Discoverability service run on our providers' infrastructure in the US and the EU.

Where personal data is transferred outside the EEA or the UK, we rely on Standard Contractual Clauses or equivalent safeguards.

11Retention

  • Scanner: section 03 lists the retention periods.
  • Agent Discoverability service: the service holds no data from you. We keep the contact details of the people we work with as described below.
  • Business contacts: we keep contact details while we work together, and after that as long as we need them for our records or as the law requires.
  • Armature platform: account data is kept while your account is active. Session data is kept for the retention period of your plan: 7 days on the free plan and a custom period on custom plans. AI Traffic keeps raw events for 30 days by default. When you delete your account or ask us to delete data, we remove it from production promptly and from backups within 90 days.

12Security

  • We encrypt data in transit and at rest.
  • In the Armature platform, we redact personal data and secrets by default, before storage.
  • We control access with multi-factor authentication and audit logs.
  • We keep secrets in a managed secret store.
  • We keep development and production in separate environments.

No system is perfectly secure. If you find a vulnerability, report it to security@armature.tech and we will work with you in good faith.

13Your rights

Depending on where you live, you can ask to access, correct, export or delete your personal data, and object to or restrict some processing. Email privacy@armature.tech and we will respond within 30 days. You can also complain to your local supervisory authority.

If you are an end user of a customer's product, contact that customer first and we will support their response.

14Cookies

Website: the website uses Vercel Analytics, which sets no cookie. It also uses two advertising tags, the X pixel and the LinkedIn Insight Tag, so we can measure campaigns we run on X and LinkedIn. These tags may set first-party or third-party cookies. In the EU, the EEA, the UK and Switzerland, they load only after you accept them in the cookie banner. Everywhere else, they load by default. You can change your choice at any time with the Cookie settings link in the footer of every page.

PostHog product analytics records page views and interactions such as clicks, filters, searches and opened runs, with no person profile and no session replay. Until you accept the cookie banner, it keeps nothing on your device. After you accept, an anonymous identifier is stored in your browser's local storage so that return visits count once. Search text is not recorded.

We also set technical cookies. arm_region only records whether the banner must be shown. __Host-lb_view lets the leaderboard pages load run details: it holds a random value and its issue time, and it expires after 12 hours. A private results page that we share with a customer sets a signed access cookie after you enter its password. If you book a call, the Cal.com scheduler opens on the page and uses its own functional cookies.

Scanner: the scanner uses one essential cookie, which section 03 describes. It loads no advertising tags.

Armature platform: the Armature app uses essential cookies for authentication, and the same X pixel when you visit the app or create an account.

15Children

Our products are business tools. They are not directed at children under 16, and we do not knowingly collect their data.

16Changes and contact

We will update this policy when our practices change, and we will change the date at the top. For material changes, we will notify customers by email or in the product.

Entity
Armature, Inc.