S.I.R.T.

Privacy Policy

Last updated: April 2026

What We Collect

S.I.R.T. does not collect or store personal information.

We use Vercel Analytics for anonymous, cookie-free usage statistics. Vercel Analytics records page views and anonymous interaction events (e.g. checklist generated, file downloaded). No personally identifiable information is captured. No cookies are set by S.I.R.T.

Data We Do Not Collect

  • ·No account registration or login
  • ·No name, email, or contact information
  • ·No incident data, security stack configurations, or generated checklist content
  • ·No LLM API keys - keys are session-only and never logged or stored on our servers
  • ·No payment information

Your API Key

If you use the API-powered checklist generator, you provide your own LLM API key. That key is:

  • ·Stored in your browser's sessionStorage only
  • ·Cleared automatically when you close your tab
  • ·Used solely to authenticate a single LLM API call on your behalf
  • ·Never logged, stored, or transmitted to any service other than your chosen LLM provider

Your Files

Files you upload to S.I.R.T. (org-sec-stack.md, incident-type.md) are processed entirely in your browser. A structured prompt derived from that data is sent to your LLM provider. Your original files are not stored by S.I.R.T. at any point and are never transmitted to any server.

Third-Party Services

S.I.R.T. interacts with the following third-party services:

  • ·Vercelvercel.com — hosting and serverless functions
  • ·Anthropicanthropic.com — optional LLM provider
  • ·OpenAIopenai.com — optional LLM provider
  • ·Googlegoogle.com — optional LLM provider (Gemini)
  • ·Mistralmistral.ai — optional LLM provider
  • ·Vercel Analyticsanonymous usage statistics

Only the LLM provider you select receives any request data. Each service has its own privacy policy.

Session Storage

S.I.R.T. uses browser sessionStorage to hold your API key, provider selection, and generated output during your session. All sessionStorage data is cleared automatically when you close your browser tab. It is never transmitted to S.I.R.T.'s servers.

Cookies

S.I.R.T. does not set cookies.

Contact

For privacy-related questions, open an issue at github.com/mello-io/SIRT.

Changes to This Policy

This policy may be updated as the product evolves. The "Last updated" date above reflects the most recent revision.