1. Scope
This Privacy Policy applies to the CutoverGrid website, application, assessments, integrations, support interactions, and commercial communications. A customer agreement or data processing agreement may provide additional terms for a specific organization.
When an organization provides access to CutoverGrid, that organization controls its workspace, authorized users, repository scope, retention configuration, and integration permissions.
2. Information we handle
Account and organization information
We process names, work email addresses, roles, organization names, authentication identifiers, workspace membership, access roles, and preferences required to provide and secure the service.
Service and support information
We process assessment configuration, user actions, support messages, demo requests, integration settings, audit events, and service communications.
Repository and technical information
At customer direction, CutoverGrid processes selected repository contents, commit identifiers, manifests, lockfiles, configuration, dependency information, ownership records, test definitions, infrastructure files, and analysis findings. Repository scope is controlled through the connected source provider.
Website and device information
We process basic request, browser, device, security, and usage data necessary to operate the website, prevent abuse, understand service performance, and maintain reliable access.
3. How we use information
- Provide, secure, maintain, and improve CutoverGrid services.
- Authenticate users and enforce workspace permissions.
- Run repository assessments and produce evidence-backed findings.
- Synchronize authorized migration work with connected systems.
- Respond to requests, provide support, and communicate service information.
- Detect security threats, investigate misuse, and maintain audit records.
- Meet contractual, legal, tax, and compliance obligations.
4. Repository data and analysis
Repository access is read only by default. Assessments use commit-pinned source snapshots to make findings reproducible. Analysis runs inside controlled worker environments with tenant-aware isolation, resource limits, restricted network behavior, and no package lifecycle scripts by default.
Customers can configure source retention, including zero-retention processing. In zero-retention operation, source content is removed after the analysis job completes while structured findings and evidence references are retained according to workspace policy.
6. Retention and deletion
Account, workspace, assessment, audit, and support information is retained for the period required to provide the service, meet contractual requirements, resolve disputes, maintain security, and satisfy legal obligations. Repository source retention follows customer configuration and deployment policy.
Authorized workspace administrators can request or perform customer-controlled deletion. Backup copies expire through controlled backup lifecycles unless a legal obligation requires preservation.
7. Security
CutoverGrid applies technical and organizational safeguards including encrypted credential storage, least-privilege access, short-lived tokens where supported, tenant isolation, ephemeral analysis workers, restricted networking, audit logging, configurable retention, and controlled deletion. No system can guarantee absolute security; we continuously evaluate and improve the controls protecting service information.
Report security matters to security@cutovergrid.com.
8. Privacy choices and rights
Depending on applicable law, individuals may request access, correction, deletion, portability, restriction, or objection regarding personal information. Users may also update account details, manage workspace access, disconnect integrations, and control non-essential cookies.
Where CutoverGrid processes personal information on behalf of a customer, requests concerning that workspace should first be directed to the customer that controls it.
9. International processing
Information may be processed in locations where CutoverGrid and its service providers operate. When required, appropriate contractual and legal transfer safeguards are used.
10. Policy changes
Material updates are communicated through the service or the contact information associated with an account. The effective date at the top identifies the current policy version.
11. Contact
Questions and privacy requests can be sent to info@cutovergrid.com. Security reports can be sent to security@cutovergrid.com.