Privacy

Last updated 21 June 2026 · general information about our data practices, not legal advice

About Oversight

Oversight is an AI-governance dashboard operated by Veyruna and provided to client organisations as part of a Veyruna engagement. This statement explains what data Oversight holds, where it is stored, and how it is protected. It is general information about our practices, not legal advice.

What we hold

Account data: the email address you sign in with, and any passkey (WebAuthn) credentials you register. Sign-in is passwordless and invitation-only.

Your governance data: the information your organisation enters or imports, including your AI agent registry, governance findings, posture and audit-readiness scores, remediation notes and evidence files, and any MCP tokens you mint. This is your operational data, held so the dashboard can show it back to you.

Where it is stored

All data is stored in Sydney, Australia (AWS ap-southeast-2, via Supabase) and runs in the Sydney region. It does not leave Australian infrastructure in the normal course of operation.

Tenant isolation

Oversight is multi-tenant. Every record is scoped to your organisation and enforced by Postgres Row-Level Security, so your organisation's members only ever see your organisation's data. Evidence files are kept in a private store and are downloaded only through short-lived, access-checked signed URLs.

Who can access your data

Your authorised organisation members, according to their role (administrator or viewer). Veyruna, as the operator, may access data to administer the service, provide support, and maintain security. We do not sell your data or share it with advertising networks.

AI assistant access (MCP tokens)

If you connect an AI assistant to Oversight using an MCP token, that token resolves to your organisation (and optionally a specific agent identity) and is restricted to a read-only or read-write scope you choose. Every action a token takes is logged with the tool used, the resource touched, and the time, so you have a per-agent audit trail. Tokens are stored only as a SHA-256 hash, never in clear text.

Cookies and analytics

Oversight sets a session cookie so you stay signed in. It runs no advertising trackers.

Retention and deletion

Your data is retained for the duration of your engagement. On request, or on termination of the engagement, your data can be exported to you and deleted. Standard server request logs are kept by our hosting provider for operation and abuse prevention.

Security

Protections include Row-Level Security tenant isolation, hashed MCP tokens, short-lived signed URLs for evidence files, passwordless sign-in, and Australian data residency. No system is perfectly secure, but client isolation is treated as sacrosanct.

Contact

Privacy questions can be raised with Veyruna at veyruna.com.

See also our Terms of Service.