Skip to content

Legal

Privacy policy

This policy explains what CISO Express, Inc. does with personal data when you visit ciso.express, create a workspace, or use Sentinel inside your Slack or Microsoft Teams workspace. Last updated October 1, 2026.

CISO Express, Inc. (“CISO Express”, “we”, “us”) is the data controller for personal data collected through this marketing website and through our own business operations. When Sentinel runs inside your workspace, we act as a data processor on your instructions and your organisation is the controller of the directory and message data involved.

1. Personal data we collect

We collect three categories of personal data:

  • Website and signup data. Your work email address, company name, company size range, the frameworks you select, the page you submitted from, and standard server logs (IP address, user agent, timestamp) generated when you load a page.
  • Product data (processor role). If your organisation connects Sentinel, we process the workspace directory (names, email addresses, job titles, team membership), the messages Sentinel exchanges with your people, the security issues it tracks, and the evidence it collects. We process this only to provide the service and only on your organisation’s documented instructions.
  • Business contact data. Names, business email addresses, phone numbers and meeting notes for customers, prospects, vendors and partners we deal with directly.

We do not collect special category data, we do not buy personal data from data brokers, and we do not use cookies for advertising or cross-site tracking on this website.

2. Why we process it, and our legal bases

  • To create a workspace or respond to a contact request — legitimate interests in responding to a business enquiry, and consent where you explicitly opted in to product updates.
  • To provide and secure the Sentinel service — performance of our contract with your organisation.
  • To detect, investigate and prevent security incidents and abuse — legitimate interests and legal obligations.
  • To meet accounting, tax and regulatory duties — legal obligation.
  • To improve the product — legitimate interests, using aggregated or de-identified usage data. We never use customer content to train foundation models.

3. Automated decision-making

Sentinel prioritises and routes security issues using rules and machine learning. It does not make decisions with legal or similarly significant effects about individuals, and it does not evaluate employee performance. Escalations are time-based and configurable by your administrators, and every automated action is logged and reviewable.

4. Sharing and sub-processors

We share personal data only with a short list of sub-processors that help us run the service — cloud hosting and storage, a model provider under a zero-retention and no-training agreement, transactional email delivery, and error monitoring. Each is bound by a written agreement with confidentiality, security and data protection obligations. We also disclose data where legally required, and we will tell you before responding to a government request unless we are prohibited from doing so.

A current sub-processor list, our DPA and our security documentation are available on request from security@ciso.express. Enterprise customers receive 30 days notice before a new sub-processor is added to their plan.

5. International transfers

We host primarily in the United States and the European Union. Where personal data leaves the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with a transfer risk assessment. Enterprise plans can pin storage and processing to a chosen region.

6. Retention

  • Signup submissions are retained for 24 months from the last interaction, or until you ask us to delete them.
  • Product data is retained for the term of your agreement, then deleted within 7 days of a verified deletion request unless a legal hold applies.
  • Message content inside the product is retained according to the window your administrators configure, which can be as short as 30 days.
  • Server logs are retained for 90 days. Audit logs of agent and administrator actions are retained for the duration of the agreement plus 12 months, because auditors require it.

7. Security

We protect personal data with encryption in transit (TLS 1.3) and at rest (AES-256), envelope encryption for integration tokens, mandatory hardware-backed MFA for our staff, least-privilege access with just-in-time elevation, and immutable audit logging. Our security page describes the scopes Sentinel requests in Slack and Microsoft Teams, and what it deliberately cannot do.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to receive it in a portable format, and to withdraw consent at any time. You may also have the right not to receive discriminatory treatment for exercising these rights, and the right to appeal a decision we make about a request.

Email hello@ciso.express and we will respond within 30 days. If your organisation is our customer, please contact your administrator first — as a processor we usually have to route individual requests through them.

If you are in the EU or UK and think we have handled your data badly, you have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to fix it first.

9. Cookies

This website sets only what it needs to function: no advertising cookies, no cross-site tracking pixels and no third-party analytics that sell data. If that changes, we will ask for consent before anything non-essential loads.

10. Children

This website and the Sentinel product are intended for businesses. They are not directed at children, and we do not knowingly collect personal data from anyone under 16.

11. Changes to this policy

When we make a material change we will update the date at the top of this page and, for customers, notify your administrators by email at least 14 days before the change takes effect.

12. Contact

Privacy questions and requests: hello@ciso.express. Security questions and vulnerability reports: security@ciso.express. You can also write to CISO Express, Inc., attention: Privacy, using the address provided in your agreement.