This Privacy Policy explains how Legacy Edge Private Limited, operating under the brand Nyraxis ("Nyraxis", "we", "us"), collects, uses, and protects personal data when you use nyraxis.io and the Nyraxis platform (the "Service").
1. Who we are
Nyraxis is an AI agent security platform offering red-team scans, inline governance, trace observability, and compliance reporting. The Service is operated by Legacy Edge Private Limited, a private limited company incorporated in India. Nyraxis is the trading brand; Legacy Edge Private Limited is the legal entity and data controller for the personal data described in this policy.
2. What we collect
- Account data: name, email address, password hash or SSO identity, and authentication metadata (sessions, passkeys, 2FA settings) when you create an account.
- Organization data: organization name, team members, roles, and workspace configuration.
- Customer content: agent traces, prompts, outputs, and events you choose to send to the Service via our SDKs or API, and the results of red-team scans you run through the platform.
- Billing data: subscription status and transaction records. Payment card details are processed by our payment provider (Polar.sh); we never see or store full card numbers.
- Usage and analytics data: product usage events, pages visited, and technical metadata (IP address, browser type), collected via PostHog and Sentry.
- Communications: emails you send us and demo bookings made through Cal.com.
3. How we use data
- To provide, operate, and secure the Service, including storing and analyzing the traces and scan results you send us.
- To authenticate you and enforce organization-level access controls.
- To process subscriptions and payments.
- To send transactional email (invites, alerts, receipts) via Amazon SES.
- To understand product usage, fix errors, and improve the Service.
- To respond to support and legal requests.
We do not sell personal data. We do not use your customer content (traces, prompts, outputs, scan results) to train models.
4. Subprocessors
We use the following third-party processors to deliver the Service:
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Cloud hosting and database | EU |
| AWS Bedrock | LLM processing for red-team scan simulation and evaluation | US |
| Amazon SES | Transactional email | US |
| Polar.sh | Payments and subscriptions | — |
| Google Workspace | Corporate email | — |
| PostHog | Product analytics | — |
| Sentry | Error monitoring | — |
| Cal.com | Demo scheduling | — |
| OpenAI | Optional LLM features, only where enabled | — |
5. Where your data is stored
Our primary infrastructure is hosted on AWS in the EU (Ireland). Account data, organization data, traces, and scan results are stored there. Two processing paths involve processors outside the EU, and we disclose them plainly:
- Red-team scan simulation and evaluation uses AWS Bedrock. Content sent for a scan is processed there to produce attack payloads and evaluations.
- Transactional email is delivered through Amazon SES.
Where personal data is transferred outside the EU/EEA, we rely on the contractual safeguards provided by these processors (such as standard contractual clauses).
6. Retention and deletion
Agent traces and outputs are retained according to the retention settings of your workspace. Account and billing records are kept for as long as your account is active and as required by applicable law. You can request deletion of your account and associated data at any time by writing to harsh@nyraxis.io; we will confirm completion once the request is processed.
7. Cookies and analytics
We use a small number of cookies and similar technologies: strictly necessary cookies for authentication and session management, and analytics identifiers used by PostHog to understand product usage. We do not use advertising cookies or cross-site tracking.
8. Your rights
If you are in the EU/EEA or UK, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Request erasure of your data ("right to be forgotten").
- Receive your data in a portable format.
- Object to or restrict certain processing, including analytics.
- Lodge a complaint with your local supervisory authority.
To exercise any of these rights, email harsh@nyraxis.io. We respond within a reasonable timeframe and no later than required by applicable law. Where Nyraxis processes customer content on behalf of a business customer, that customer is the data controller and we act as processor; end-user requests relating to such content should be directed to the relevant customer.
9. Security
We protect data with encryption in transit (TLS) and at rest, organization-scoped data isolation, hashed API keys, and secrets held in dedicated cloud secrets management. See our Security page for details. No method of transmission or storage is perfectly secure; we work continuously to protect your data and will notify affected users of a personal data breach where required by law.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with an updated date, and where appropriate we will notify account holders by email.
12. Contact
Questions or requests about this policy: harsh@nyraxis.io. You can also reach the founder directly at harsh@nyraxis.io.