SageIT_AM · Privacy

Privacy Policy

Version 1 · last updated 2026-07-01

What this product is

SageIT_AM is AI-native IT Asset Management for enterprises. It inventories hardware, software, SaaS, cloud, and contract assets and governs reclamation. It is not a healthcare application and does not collect or process protected health information (PHI). No HIPAA or BAA obligation applies.

Data we process

Asset metadata (asset tags, names, locations, ownership), business contact data for asset owners and requesters (work email), usage signals (login and activity timestamps), and contract/SaaS entitlement data. The dev and preview environments are populated with synthetic sample data only — no real or realistic SSN, DOB, MRN, or NPI appears anywhere in fixtures, seeds, or exports.

Tenant scoping and access

All data is tenant-scoped. Every query, route, and AI tool resolves through tenant context, and cross-tenant access is denied at the server. Administrative access to tenant data is audited.

AI activity

Model calls run backend-only through the app's AI gateway; model keys are never held in the browser. Prompts and traces are referenced by SHA-256 hash — no PHI, secrets, or unnecessary personal data is stored in prompts, traces, or logs. AI prepares recommendations; a human approves every system-of-record change at the value boundary. An AI activity log records purpose, model, mode, and latency (metadata only).

Security

Passwords are hashed with a slow key-derivation function and never stored in plaintext. Authentication cookies are httpOnly, Secure, and SameSite. Transport uses TLS. Secrets live in the environment or a secret store, never in client bundles or code.

Retention and your choices

Retention is configured by your tenant administrator and audited. Exported asset registers contain business asset data only — no PHI columns. For access, correction, or deletion requests in this deployment, contact your tenant administrator.