Aletheia Privacy Notice
Effective: v1.4 general availability. Last updated: 2026-09-06.
Arbiter Security ("we", "us") provides Aletheia, a local-first binary reverse-engineering and vulnerability-research product. This notice applies to the Aletheia desktop application, cloud bridge, account and billing surfaces, and product support.
Data we process
| Category | Examples | Treatment |
|---|---|---|
| Account data | Clerk user identifier, email and organization metadata | Used for authentication, tenancy and support |
| Billing data | Stripe customer/subscription identifiers, plan and webhook event IDs | Stripe processes payment-card data; Aletheia does not store card numbers |
| Customer binaries | Files selected in the signed desktop for local analysis | Stored in an encrypted local vault and processed by a local Docker worker; never transmitted to Aletheia's cloud |
| Derived evidence | Tool calls, findings, decompilation or trace evidence, proof records and run metadata | Tenant-scoped; expires after 30 days unless deleted sooner |
| Agent requests | Prompts and selected derived tool output needed for a requested model operation | Sent to the model provider selected or configured for the session |
| Product analytics | Session lifecycle, binary format/architecture and size bucket, agent turn counts, navigation events, opaque account ID | Manual PostHog events; no file names, binary bytes, function names or conversation content; can be disabled in Settings |
| Diagnostics | JavaScript error class, application version, and numeric locations in bundled code | Raw error messages, customer paths, source excerpts, breadcrumbs, performance traces, session replay and UI recording are excluded |
| Support records | Messages and attachments a user deliberately sends to support | Used to answer and audit the request |
Do not send binaries, proof bytes, credentials or exploit details through an ordinary support email unless support has provided an approved secure channel.
Why we process data
We process data to provide and secure the service, authenticate users, enforce tenant isolation and quotas, perform requested analysis, maintain machine-checkable evidence, bill customers, respond to support and security requests, and improve reliability. Depending on location and context, the legal basis is performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where required.
Local-first and cloud processing
Production analysis requires the signed desktop and Docker. A selected binary is encrypted in an OS-keychain-bound local vault. It is decrypted only into an owner-only ephemeral session directory immediately before a signed, pinned, networkless local worker starts, and the plaintext is removed when that worker terminates. The browser product cannot upload or analyze binaries by itself.
The cloud control plane receives the binary hash, bounded operational metadata, and policy-approved derived evidence needed for authentication, orchestration, continuation, synchronization, and proof management. Raw binaries, recognizable binary fragments, file names, and local paths are not transmitted to Aletheia's cloud and are prohibited from production evidence storage, logs, metrics, traces, and model prompts.
The analysis model may receive prompts and derived analysis context through the configured provider. Provider choice and zero-data-retention requirements are enforced by deployment and session policy where configured. Users should review the terms of their selected model provider.
Service providers
We use service providers for authentication (Clerk), billing (Stripe), hosting and database infrastructure, selected model inference, opt-out product analytics (PostHog), and privacy-limited error reporting (Sentry). Providers may process data in other countries under their contractual transfer safeguards.
We do not sell customer data. Arbiter Security does not use customer binaries to train models. Processing by a user-selected model provider is governed by that provider's terms. We do not permit advertising profiling from binary-analysis content.
Retention and deletion
Local plaintext analysis copies are ephemeral. Derived cloud evidence expires after 30 days. Users can export or delete individual runs and purge Aletheia account data from Settings. In the signed desktop, account purge first stops local analysis and deletes the encrypted local vault, crash-leftover plaintext, and native vault/device keys. The cloud then cancels an active Aletheia subscription, disconnects local nodes, deletes enrolled device identities, enrollment authority, evidence and API keys, and anonymizes the service identity. A browser can perform the cloud portion but cannot erase a vault on an offline desktop; that local vault must be purged from the desktop.
Payment records required for tax, accounting, fraud prevention or dispute handling are retained as a documented exception. Encrypted backups age out within 30 days; deleted data is not returned to active service after restoration.
See Data retention and Data deletion and export for exact operational rules.
Security
We use authenticated tenant boundaries, least-privilege service roles, encrypted transport, signed desktop updates, a pinned networkless local Docker worker, ephemeral local plaintext storage, database-backed purge fences, and auditable evidence/proof records. No security measure eliminates all risk. Report suspected issues using the security disclosure process.
Your choices and rights
Depending on applicable law, users may request access, correction, export, restriction, objection or deletion. Product analytics can be disabled in Settings. Individual evidence runs can be exported or deleted without closing the account. Requests can be sent to [email protected]; identity may need to be verified before action is taken.
Contact and changes
Privacy questions: [email protected].
We will date material changes and provide notice where required. A new use of customer binaries or analysis content requires a policy update and product review before deployment.