• Agentic AI
    Attribution Agent Identity Secretless AI Tool Call Security
    Workload IAM
    Connection Security Identity Federation Secretless Infrastructure Zero-Touch Operations Quantum-Safe Connections
    Kubernetes
    mTLS Without a Service Mesh SPIFFE Without SPIRE Machine Identity
    Agentic AI
    attribution Attribution north_east Trace every AI action back to the human who initiated it. fingerprint Agent Identity north_east Give every agent its own cryptographic identity and permissions. key_off Secretless AI north_east Agents reach tools and data without ever holding a credential. policy Tool Call Security north_east Inspect and authorize every tool call in real time.
    Workload IAM
    lock Connection Security north_east Authenticate and encrypt every workload connection, automatically. hub Identity Federation north_east Bridge workload identities across clouds, clusters, and providers. vpn_key_off Secretless Infrastructure north_east Replace static secrets with short-lived, attested identities. autorenew Zero-Touch Operations north_east Issue, rotate, and revoke identities with no human in the loop. enhanced_encryption Quantum-Safe Connections north_east Post-quantum cryptography on every connection, today.
    Kubernetes
    sync_lock mTLS Without a Service Mesh north_east Mutual TLS between pods with no sidecars and no mesh to run. verified_user SPIFFE Without SPIRE north_east SPIFFE-compatible identities without operating SPIRE servers. memory Machine Identity north_east A cryptographic identity for every VM, container, and process.
    Not sure where to start? Talk to us arrow_forward
  • Pricing
  • Docs
  • Blog
Talk to us Start Free
Talk to us
Start Free

Riptides Privacy Policy

Last updated: Jun 12, 2026.


This Privacy Policy explains how Riptides Labs, Inc. (“Riptides,” “we,” “us”) collects, uses, and discloses personal data in connection with our websites, the Console, and the Agent Software. It also explains the rights available to individuals under applicable data protection laws, including the EU/UK GDPR.

1. Two roles: controller and processor

We handle personal data in two distinct capacities, and different rules apply to each.

(a) Where we act as a controller. For personal data we collect about visitors, prospects, account holders, and Users — for example, signup and contact details, billing information, website and product usage, and marketing communications — we are the controller, and this Privacy Policy governs that processing.

(b) Where we act as a processor. When a customer deploys the Agent Software and uses the Console, the Agent Software transmits Telemetry and operational data to the Console. To the extent that data contains personal data, we process it on behalf of and under the instructions of the customer (the controller), and that processing is governed by the Data Processing Addendum (DPA) between us and the customer — not by this Privacy Policy. If you are an individual whose data is processed because your employer or another organization uses Riptides, please direct privacy requests to that organization in the first instance.

2. Personal data we collect (as controller)

  • Account and contact data: name, work email, phone, organization, role, and credentials you create.
  • Billing data: where you purchase a paid plan, billing contact and transaction details (payment card data is handled by our payment processor; we do not store full card numbers).
  • Website and product usage data: IP address, device and browser information, pages viewed, actions taken, timestamps, referral data, and similar diagnostic data, collected via the website and the Console.
  • Communications and support data: messages, support requests, and related metadata when you contact us.
  • Marketing data: preferences and engagement with our communications and events.

3. Telemetry from the Agent Software

The Agent Software transmits Telemetry to the Console, which may include operational, diagnostic, configuration, usage, and security-related data about the Agent Software and the environment in which it runs.

To the extent Telemetry includes personal data, the role analysis in Section 1 applies: data we use to operate, secure, and improve our own Service is processed as controller; data we process on the customer’s behalf is governed by the DPA.

4. How we use personal data and our legal bases

We use personal data (as controller) to: provide, operate, secure, and maintain the Service; create and administer accounts; process payments; provide support; communicate about the Service, including security and operational notices; send marketing where permitted; analyze and improve the Service; detect, prevent, and investigate fraud, abuse, and security incidents; and comply with legal obligations.

Where the GDPR applies, our legal bases are: performance of a contract (providing the Service and managing accounts); legitimate interests (securing and improving the Service, B2B marketing, fraud prevention — balanced against your rights); consent (certain marketing and non-essential cookies, which you may withdraw); and legal obligation (tax, accounting, and compliance).

5. Cookies and similar technologies

We use strictly necessary cookies to operate the website and Console (for example, authentication and security). Subject to consent where required, we may use functional and analytics cookies to understand and improve usage.

6. How we share personal data

We share personal data with:

  • Service providers / sub-processors that help us operate the Service (e.g., cloud hosting, payment processing, analytics, support, email), under contracts requiring appropriate protection. A current list of sub-processors is available on request.
  • Affiliates, including our Hungarian subsidiary Riptides Kft., for operating the Service consistent with this Policy.
  • Legal and safety disclosures where required by law or to protect rights, safety, or the integrity of the Service.
  • Business transfers in connection with a merger, acquisition, financing, or sale of assets, with notice as required.

We do not sell personal data, and we do not share it for cross-context behavioral advertising.

7. International transfers

We are based in the United States and operate through affiliates including in Hungary. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, principally the European Commission’s Standard Contractual Clauses (and the UK Addendum / Swiss addendum as applicable), together with supplementary measures where needed.

8. Retention

We retain personal data only as long as necessary for the purposes described, then delete or anonymize it, except where longer retention is required for legal, accounting, security, or dispute-resolution purposes. Retention of customer-controlled Telemetry processed on a customer’s behalf is governed by the DPA and the customer’s instructions.

9. Security

We maintain technical and organizational measures designed to protect personal data appropriate to the risk. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Customers are responsible for security within their own infrastructure as described in the Terms of Service.

10. Your rights

Depending on where you are, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent at any time. You may also lodge a complaint with a supervisory authority — in the EU, your local data protection authority (in Hungary, the NAIH).

To exercise rights, contact privacy@riptides.io. Where we process your data on a customer’s behalf (processor role), we will refer your request to that customer.

11. Children

The Service is a business product not directed to children and is not intended for anyone under 18. We do not knowingly collect personal data from children.

12. Changes to this Policy

We may update this Policy. For material changes we will provide notice (for example, by email or a prominent notice) before they take effect and update the “Last updated” date.

13. Contact

Riptides Labs, Inc.

1111B S Governors Ave STE 28385

Dover, DE 19904

privacy@riptides.io

Riptides is a unified identity fabric for access control and secure communication across workloads, services, and AI agents.

Solutions

Attribution Agent Identity Secretless AI Tool Call Security Connection Security Identity Federation Secretless Infrastructure Zero-Touch Operations Quantum-Safe Connections mTLS Without a Service Mesh SPIFFE Without SPIRE Machine Identity

Company

Pricing Blog Talk to us RSS Privacy Policy Terms of Service

Contact

Github X Linkedin

Copyright © 2026 Riptides Labs. All rights reserved.