Privacy Policy

Last updated: July 2026

This Privacy Policy explains what information Origin (“we”) collects, how we use it, and the choices you have. Origin is the evidence layer for high-consequence AI agents. It enforces runtime policy before an AI agent takes a side effect, routes every tool call through a controlled proxy, and produces a tamper-evident, hash-chained evidence package showing what an agent did, why it was allowed, and who owned the risk — so teams can get high-consequence agents through security review. Origin is currently available through a founder-led pilot program. The prototype runs; it is not production SaaS. By using Origin, you agree to this Policy.

Information we collect

How we use information

Human-in-the-loop controls

Risky actions do not execute silently. When a policy decision returns require-approval, the action is held at the proxy and routed to a named risk owner, whose approval or denial is recorded in the audit log alongside the action. Scope and budget limits bound blast radius before an action runs, and a kill switch can pause a workflow or revoke a scope without redeploying the agent. These controls are part of the record: the evidence package reflects who owned the risk and what they decided.

Append-only, hash-chained audit logs

The audit log is append-only and hash-chained, so the record of what the Service evaluated, allowed, and recorded is tamper-evident and replayable. Its purpose is to provide evidence and accountability for each agent action. Audit access is scoped to the workflow it belongs to and subject to the applicable controls.

How we share information

We do not sell your personal information. We share it only with: (a) sub-processors that help us run the Service (for example, hosting, identity, and infrastructure providers) under appropriate confidentiality and security obligations; (b) authorities when required by law; and (c) a successor in the event of a merger or acquisition, subject to this Policy. A current list of sub-processors is available on request and is referenced in the Data Processing Agreement (DPA).

Security

We use technical and organizational measures designed to protect your information, including least-privilege (need-to-know) access, encryption in transit, and append-only, hash-chained audit logs of policy and tool-call activity. Access to workflow data and audit logs is scoped to the workflow it belongs to and subject to the applicable controls. Origin is responsible for the software controls it provides; you remain responsible for the agents and tools you connect. No method of transmission or storage is perfectly secure. A DPA and a security review are available on request.

Data retention and deletion

We retain information for the life of the engagement and as required by law. Audit logs are append-only and may be retained as the evidentiary record of policy and tool-call activity. Retention windows applied during the pilot are defaults; the finalized retention terms are set in the DPA. To request removal of your account or associated data, contact us using the details below.

Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us using the details below. You may also have the right to lodge a complaint with your local data-protection authority.

Cookies and analytics

We use only essential cookies and local storage needed to keep you signed in and operate the Service. We also use Google Analytics configured in Consent Mode v2 with analytics_storage denied by default, so no non-essential analytics or advertising cookies are set unless you grant consent.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information.

Origin's role

Origin provides policy enforcement, evidence, and decision-support records — not legal or compliance certification. We use “tamper-evident” to mean alteration is detectable by replay and digest checks, and “review-ready” to mean built for review rather than already accepted. The customer remains responsible for the agents and tools they connect and for the decisions made using Origin's records.

Changes

We may update this Policy. If we make material changes, we will take reasonable steps to notify you and update the “Last updated” date above.

Contact

Questions about privacy? Reach us at bohueilin@gmail.com or through the contact section of our website.