Agentbeam
Legal

Privacy Policy

Last updated: January 1, 2026

Agentbeam is built local-first: by default, the activity it records about your AI agents stays on your machine. This policy explains what we collect when you use our website, our local agent runtime, our browser extension, and — if your team opts in — our cloud dashboard, and why.

1. General

1.1 The website agentbeam.com, together with the Agentbeam local runtime recorder, the Beam Sentinel browser extension, our command-line tools, and our optional cloud dashboard for teams (collectively, the “Platform”) are operated by AISOLO Technologies Private Limited [CIN: U62099MH2023PTC403351] (“Agentbeam”, “we”, “us” or “our”), a company incorporated under the Companies Act, having its registered office at 1003, Kamdhenu Commerz, Sector 14, Kharghar 410210, Navi Mumbai, Maharashtra, India.

1.2 Agentbeam is a security and observability layer for AI coding agents. It records agent shell commands, file changes, tool calls and network activity, flags risky actions with evidence attached, and scans MCP server configurations and SKILL.md files before you run them (“Service”). Agentbeam is designed for individual developers and teams today, and is built to the evidentiary and access-control standard that enterprise security and compliance teams require.

1.3 This Privacy Policy applies to anyone who browses the website, installs the local runtime recorder or browser extension, or creates an account on our cloud dashboard (“you”, “your”, “User”).

1.4 By using, browsing or accessing the Platform, you agree to the collection, use, disclosure and storage of your information as described in this Privacy Policy and our Terms of Service.

1.5 You may withdraw consent for optional data collection (such as cloud sync or product analytics) at any time by adjusting your settings or writing to us at [email protected]. Withdrawing consent for data required to operate a feature may mean that feature is no longer available to you.

1.6 The Platform is not directed at, and we do not knowingly collect personal information from, individuals under the age of 16.

2. Local-first by default, cloud where you opt in

Agentbeam is architected so that the most sensitive data it handles — the content of agent shell commands, file diffs, and tool-call arguments — is recorded to local files on your own machine by default, and is never transmitted to us unless you explicitly enable a cloud feature.

2.1 Local runtime recorder

The runtime recorder and the SKILL.md / MCP config scanner write activity logs and scan reports to a local directory on your device. We do not receive, store, or have access to this data unless you choose to export it or send it to us (for example, when attaching evidence to a support request).

2.2 Cloud dashboard (team & organization accounts)

Teams that create an organization on our cloud dashboard can opt in to sync policy configuration, aggregated findings, and fleet-level visibility across their developers' machines. When enabled, the specific events, rule matches and metadata your organization's policy is configured to sync are transmitted to our cloud infrastructure and associated with your organization's account. Local recording continues in parallel and remains the source of truth on each machine.

2.3 Browser extension (Beam Sentinel)

The Beam Sentinel browser extension checks prompts and actions on supported AI assistant websites against a local rule set before they are sent. Checks run in your browser; the extension does not transmit the content it inspects to us. It stores a rolling local history of recent checks (enabled/disabled state, counts, and short redacted previews) in your browser's local storage, which never leaves your device.

2.4 We do not sell the data described in this section, and we do not use it to train third-party foundation models.

3. Information we collect

The categories of information we collect depend on how you use the Platform:

CategoryExamplesWhen it's collected
Account informationName, email address, password or SSO identifier, organization nameCreating a cloud dashboard account
Billing informationBilling address, plan tier; card details are handled directly by our payment processor and not stored by usSubscribing to a paid plan
Synced agent activityRule matches, event metadata, timestamps, host and repository names — only the fields your organization's policy is configured to syncUsing the cloud dashboard with sync enabled
Website usage dataPages viewed, referrer, approximate location, device/browser typeBrowsing agentbeam.com (see Cookies below)
Support communicationsAnything you send us, including logs or evidence you choose to attachContacting support or reporting a bug

We do not require the content of your source code, prompts, or agent outputs to operate the local recorder, and the cloud dashboard only receives what your policy explicitly syncs.

4. How we use information

  • To create and give you access to your account on the cloud dashboard
  • To provide the Service, including fleet visibility, policy sync, and evidence export for organizations that opt in
  • To process payments and manage subscriptions
  • To send account, billing and security notifications
  • To provide customer support and respond to requests
  • To maintain and improve the reliability, security and performance of the Platform
  • To detect, investigate and prevent fraud, abuse and security incidents
  • To send product updates and marketing communications, only where you have opted in, and always with an unsubscribe option
  • To comply with legal obligations and respond to lawful requests from public authorities

5. Disclosure and sub-processors

We do not sell your personal information. We share information only with:

  • Infrastructure and hosting providers that store cloud dashboard data on our behalf, under contractual confidentiality and security obligations
  • Payment processors, to process subscription payments
  • Website analytics providers (Google Analytics and PostHog) for aggregated usage measurement — see Section 6
  • Professional advisors (legal, accounting) where necessary
  • Law enforcement or regulators, where required by law or to protect the rights, safety or property of Agentbeam, our users, or the public
  • A successor entity, in the event of a merger, acquisition or asset sale, subject to this Privacy Policy continuing to apply

6. Cookies and website analytics

agentbeam.com uses a small number of cookies and similar technologies for essential site function and to understand aggregate traffic — never to build advertising profiles of individual visitors.

  • Google Analytics — page views and referral sources, in aggregate
  • PostHog — product analytics on the marketing site, using a randomly generated, non-identifying device ID stored in your browser

Neither the local runtime recorder, the browser extension, nor our command-line tools set tracking cookies. You can block or clear cookies in your browser settings at any time; doing so does not affect your ability to use the local recorder, scanner, or browser extension.

7. Retention and deletion

Locally recorded activity is retained on your own device under your control — you can configure retention or delete it at any time using the Platform's local tooling; we have no access to it and no ability to delete it remotely.

Cloud dashboard account and synced activity data is retained for as long as your organization's account is active, and for up to 45 days after account deletion to allow for recovery from accidental deletion, after which it is permanently deleted, subject to any longer retention required by law (for example, billing records).

8. Security

We use industry-standard technical and organizational measures — encryption in transit, access controls, and least-privilege principles — to protect information transmitted to our cloud infrastructure. No method of transmission or storage is 100% secure; if you become aware of a security issue affecting the Platform, please report it to [email protected].

9. Open-source components

Certain components of Agentbeam — including parts of our scanning heuristics and integrations — are released as open source. If you run a self-hosted or open-source build, this Privacy Policy applies only to the extent you connect that build to our website or cloud dashboard; data you never send us is never in our possession. The license terms applicable to each open-source component are published alongside that component's source.

10. International data transfers

We are headquartered in India and may process data using service providers located in other countries, including the United States. Where we transfer personal data internationally, we rely on appropriate safeguards such as standard contractual clauses, consistent with the requirements described in our GDPR Compliance page.

11. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. See our Data Rights page for the full list of rights and how to exercise them.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified via the Platform or by email to registered account holders before they take effect. Continued use of the Platform after an update constitutes acceptance of the revised policy.

13. Contact and redressal

Questions, grievances or complaints about this Privacy Policy can be sent to our grievance officer:

  • Designation: Grievance Officer
  • Email: [email protected]
  • Registered office: AISOLO Technologies Private Limited, 1003, Kamdhenu Commerz, Sector 14, Kharghar 410210, Navi Mumbai, Maharashtra, India

For general support, write to [email protected].