Cloakmint, Inc. ("the Company," "we," "us," or "our") operates the website cloakmint.com (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
Cloakmint builds AI-driven threat detection and alert triage software for cloud security and SOC teams. Our core service processes cloud security event data submitted by customer teams -- including CloudTrail logs, SIEM alert feeds, and API activity streams -- to correlate signals into confirmed incidents and close false positives before they consume analyst time. This policy explains our practices with respect to both our marketing website and our product platform.
We are based at 1201 New York Avenue NW, Suite 800, Washington, DC 20005 and can be reached at [email protected].
1. Information We Collect
1.1 Information You Provide
We collect information you submit directly, including:
- Contact details (name, email, phone) when you fill out a form, request a demo, or subscribe to updates;
- Company information you choose to share (employer, role, cloud environment context);
- The content of any messages you send us.
1.2 Cloud Security Event Data (Platform Customers)
When you use the Cloakmint platform, you submit cloud security telemetry -- log events, alert data, API activity, and related metadata from your cloud environment. This data is processed solely to generate alert correlations, incident groupings, and false-positive dismissal recommendations for your security team. We do not use your cloud event data to train machine learning models without your explicit written consent. Customer event data is logically isolated per account, retained for the period specified in your subscription tier (30 days on Starter, 90 days on Team, configurable on Enterprise), and is never sold or shared with third parties outside of the service provider relationships described in Section 4.
1.3 Information Collected Automatically
When you visit cloakmint.com, we automatically collect limited technical information:
- IP address and approximate location (city/region level);
- Browser type, operating system, device class;
- Pages visited, referring URLs, time on page;
- Cookie and similar identifiers (see Section 5).
1.4 We Do Not Knowingly Collect Children's Data
cloakmint.com is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
2. How We Use Information
We use the information we collect to:
- Respond to inquiries and provide requested information about Cloakmint's alert triage and threat detection capabilities;
- Operate, maintain, and improve the Service, including the correlation engine and false-positive detection models;
- Deliver the platform service to authenticated customers (processing event data to generate incident correlation outputs);
- Send service updates and (with your consent where required) marketing communications;
- Detect, investigate, and prevent fraud or abuse of the platform;
- Comply with legal obligations.
We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see your state's section below.
3. Sharing of Information
We share personal information only with:
- Service providers acting on our behalf (e.g., cloud infrastructure hosting, email delivery, product analytics) under contractual confidentiality terms;
- Authorities, when required by law or to protect rights, safety, or property;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal information to third parties.
4. Cookies and Tracking
We use cookies and similar technologies to operate the site, remember preferences, and measure usage. For details and choices, see our Cookie Policy.
5. Data Retention
We retain personal information only as long as needed for the purposes described, to comply with legal or accounting obligations, and to resolve disputes. Inactive marketing-list contacts are purged after 24 months. Server access logs are retained 90 days, then aggregated. Customer event data retention periods are governed by subscription tier as described in Section 1.2 and in the applicable subscription agreement.
6. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including TLS 1.3 encryption in transit, AES-256 encryption at rest, restricted-access databases, and least-privilege access controls. Customer event data is processed in-region and isolated per account. No system is perfectly secure; we cannot guarantee absolute security.
7. Your General Rights
Depending on your jurisdiction, you may have rights including access, correction, deletion, and the ability to limit certain processing. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.
8. SOC and Cloud Security Regulatory Context
Cloakmint's platform is designed for cloud security operations and SOC teams. Customers who operate in regulated environments (such as financial services teams subject to GLBA, or government contractors with data handling obligations) remain responsible for their own compliance obligations with respect to the event data they submit to the platform. Cloakmint provides data handling documentation and audit log exports to support customers' internal compliance review processes. We do not represent that the platform is HIPAA-compliant or FedRAMP-authorized; customers with those requirements should contact us to discuss their specific needs before deploying.
9. District of Columbia Residents
The District of Columbia does not currently have a comprehensive consumer privacy statute. As a matter of policy, we extend the following baseline rights to all U.S. residents regardless of state of residence.
9.1 Baseline Rights
- Right to Know: request the categories of personal information we have collected about you.
- Right to Delete: request deletion of personal information you have provided.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt Out of Marketing: unsubscribe from marketing emails or opt out via the link in each marketing message.
9.2 How to Exercise
Email [email protected] with a description of your request and enough detail for us to verify your identity. We respond within 45 days.
9.3 Sector-Specific Rights
If you are protected by federal sector laws (e.g., HIPAA, GLBA, FERPA), those laws may give you additional rights with respect to data covered by them.
10. California Visitors
If you are a California resident visiting from another state, you may also exercise the rights granted under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. We do not sell personal information and do not "share" personal information for cross-context behavioral advertising.
To submit a CCPA / CPRA request, email [email protected] with the subject line "California Privacy Request."
11. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.
12. Contact
Questions, requests, or complaints can be sent to:
Cloakmint, Inc.1201 New York Avenue NW, Suite 800
Washington, DC 20005
Email: [email protected]
Phone: +1 (202) 449-0231