Privacy
Last updated 21 June 2026 · general information about our data practices, not legal advice
About Oversight
Oversight is an AI-governance dashboard operated by Veyruna and provided to client organisations as part of a Veyruna engagement. This statement explains what data Oversight holds, where it is stored, and how it is protected. It is general information about our practices, not legal advice.
What we hold
Account data: the email address you sign in with, and any passkey (WebAuthn) credentials you register. Sign-in is passwordless and invitation-only.
Your governance data: the information your organisation enters or imports, including your AI agent registry, governance findings, posture and audit-readiness scores, remediation notes and evidence files, and any MCP tokens you mint. This is your operational data, held so the dashboard can show it back to you.
Where it is stored
All data is stored in Sydney, Australia (AWS ap-southeast-2, via Supabase) and runs in the Sydney region. It does not leave Australian infrastructure in the normal course of operation.
Tenant isolation
Oversight is multi-tenant. Every record is scoped to your organisation and enforced by Postgres Row-Level Security, so your organisation's members only ever see your organisation's data. Evidence files are kept in a private store and are downloaded only through short-lived, access-checked signed URLs.
Who can access your data
Your authorised organisation members, according to their role (administrator or viewer). Veyruna, as the operator, may access data to administer the service, provide support, and maintain security. We do not sell your data or share it with advertising networks.
AI assistant access (MCP tokens)
If you connect an AI assistant to Oversight using an MCP token, that token resolves to your organisation (and optionally a specific agent identity) and is restricted to a read-only or read-write scope you choose. Every action a token takes is logged with the tool used, the resource touched, and the time, so you have a per-agent audit trail. Tokens are stored only as a SHA-256 hash, never in clear text.
Cookies and analytics
Oversight sets a session cookie so you stay signed in. It runs no advertising trackers.
Retention and deletion
Your data is retained for the duration of your engagement. On request, or on termination of the engagement, your data can be exported to you and deleted. Standard server request logs are kept by our hosting provider for operation and abuse prevention.
Security
Protections include Row-Level Security tenant isolation, hashed MCP tokens, short-lived signed URLs for evidence files, passwordless sign-in, and Australian data residency. No system is perfectly secure, but client isolation is treated as sacrosanct.
Contact
Privacy questions can be raised with Veyruna at veyruna.com.
See also our Terms of Service.