> For the complete documentation index, see [llms.txt](https://docs.nullify.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.nullify.ai/more-info/data-handling-policy.md).

# Data Handling Policy

Nullify processes the minimum customer data needed to detect, triage, and remediate security findings. This includes source code and metadata from connected repositories, dependency and container inventories, cloud configuration retrieved through least-privilege roles, and the organizational context you provide during onboarding. Data is encrypted in transit and at rest, scoped to your tenant, and access is restricted to the systems and personnel required to operate the platform. Findings, remediation history, and supporting context are retained for the lifetime of your tenant and removed in line with the retention schedules and deletion processes described in our legal documentation. Nullify does not sell customer data or use it to train models for other customers.

## Data subject rights

Nullify supports data-subject access and erasure requests. A tenant administrator can export the personal data Nullify holds for a user, or request its erasure, through the Admin surface — see the [Admin API](/api-reference/api-reference/api-admin.md) or contact support to action a request.

Please see our [legal documentation here](https://www.nullify.ai/legal).

For GDPR compliance inquiries, including Records of Processing Activities, data retention schedules, breach notification procedures, and data subject rights, contact <support@nullify.ai>.
