Cridenty Guard — Processing of technical security signals
Cridenty Platform
Current version: V1
English translation provided for convenience. In case of discrepancy, the French version shall prevail.
1. Purpose
Cridenty Guard / Agent Guard is intended to verify that AI tools, software agents, scripts and technical environments remain within the scope authorized by the organization.
These processing activities support security, AI agent governance, detection of out-of-scope actions and the construction of control policies adapted to the customer’s context.
2. Nature of processed data
Depending on the configuration chosen by the customer, Cridenty Guard may process technical runtime signals such as:
- process events,
- actions performed by an AI tool, software agent or script,
- policy decisions,
- risk scores and technical classifications,
- pseudonymized actor, machine or environment identifiers,
- normalized paths,
- target fingerprints.
These signals are treated as potential personal data whenever an indirect link to a natural person is reasonably possible.
The exact list of collected signals, their granularity and collection options are configurable and documented on a customer-by-customer basis, including in the applicable technical appendix or contractual documentation.
3. What Cridenty Guard does not do
Cridenty Guard is not intended for:
- HR monitoring,
- assessment of individual productivity,
- commercial or advertising profiling,
- reading file contents by default.
Scores, correlations and classifications produced by Cridenty Guard are technical security signals intended to assess whether an action complies with a policy, not to assess a person’s performance, behavior or productivity.
4. Minimization measures
Cridenty Guard applies minimization measures adapted to the sensitivity of processed signals, including:
- pseudonymization of identifiers where possible,
- path normalization,
- hashing or HMAC of targets when verification does not require the clear value,
- short retention of raw signals, configurable per customer, generally 7 to 30 days by default,
- separation between raw signals, alerts, aggregates and exportable proofs,
- restricted access for authorized persons only.
5. Automated decision and human review
Policy decisions produced by Cridenty Guard are technical signals intended to help validate, block or escalate an action according to the rules configured by the customer.
Where a Guard decision may produce a legal effect or significantly affect a person, the customer must provide an appropriate possibility for human review, explanation and challenge in its context.
6. Customer responsibility
For Guard signals processed in a customer environment, the customer is the controller within the meaning of GDPR and Cridenty acts as a processor, except for Cridenty’s own processing activities determined for the security, operation or management of its platform.
The customer configures policies, authorized scopes, applicable retention periods and information rules for the users concerned.
When Cridenty Guard is deployed in a customer environment, the customer is responsible for verifying that this configuration is appropriate for its internal, contractual, employment-related and regulatory obligations.
When Guard is deployed by an employer in France, the customer must in particular assess prior employee information obligations, consultation of the CSE where required, framing through an IT charter or internal policy, and documentation of the applicable legal basis.
7. Additional references
Information relating to data protection, retention periods and hosting is detailed in the Privacy Policy / GDPR, Data Retention Policy, Legal Notice and the applicable DPA where Cridenty acts as a processor.