Legal
Data Handling & Security
Last Updated: August 2026
Core Philosophy
- Insight-Aware, Not Data-Retentive: We prioritize extracting human understanding and organizational knowledge over the long-term retention of your raw information.
- Transient Processing: We interact with your data only when necessary to perform analysis. Repository context is processed transiently; manually submitted challenge text may be retained with the challenge record.
Definitions
Source Identifiers
The repositories and development tools that you explicitly connect to Ninchi. LMS and document-workspace integrations are not currently available.
Source Data
Repository context that Ninchi analyzes, plus supported plain-text or code excerpts that an authorized user manually submits. Native PDF, DOCX, LMS, and cloud-document ingestion are not currently available.
Derived Information
Proprietary analytics (e.g., Ninchi Scores, knowledge maps) created by our engine that do not contain raw Source Data.
How Ninchi Works
- Trigger: A supported repository change occurs, or an authorized user manually submits a supported text or code excerpt.
- Analysis: The system securely accesses the relevant Source Data subset to generate context-aware questions or evaluations.
- Response: The assigned user provides an answer.
- Evaluation: Ninchi evaluates the response against the current context.
- Retention: Repository context is processed transiently. Manually submitted challenge text may be retained with the challenge record.
What We Do NOT Store
What We DO Store
Security & Compliance
SOC 2 Type 1: Ninchi has completed a SOC 2 Type 1 attestation. Our compliance posture is continuously monitored with Vanta and Drata, and audit logs and compliance metadata are reviewed to verify our internal controls. A SOC 2 Type 2 observation period is underway; we do not claim Type 2 attestation until that engagement completes.
Prospective enterprise customers may request access to the SOC 2 Type 1 report via our Trust Center (access is gated and reviewed). For help, email support@ninchi.ai. The report is managed in Vanta and is not published as a public download.
Infrastructure
- Encryption in transit (TLS) and at rest (AES-256)
- Secure cloud infrastructure (AWS) with strict access controls
- Private networking for backend services
- Secure secret management and least-privilege service accounts
Enterprise Deployment: Dedicated deployment options, including dedicated VPCs and isolated tenant environments, can be arranged under an Enterprise agreement to satisfy strict data residency and egress requirements.
AI & Model Usage
- Zero-Training Pledge: We do not train external AI models (including foundational or third-party models) on any customer Source Data.
- Data Siloing: Your data is never shared across organizations. Analysis is strictly focused on patterns and understanding within your specific environment, not on proprietary logic transfer.
Proprietary Analytics
- Ninchi Score: A transparent, difficulty-weighted record of demonstrated understanding. It is Derived Information — a summary of verified interactions with your organization's work, not a measure of anyone's ability or intelligence, and not a copy of your raw input.
- Knowledge Maps: Visual representations of organizational understanding. These are generated from aggregated metadata and contain no raw Source Data.
Designed for Trust
Our architecture is built on a "minimal retention" model. By focusing on verified human understanding rather than raw data storage, we ensure that your intellectual property remains under your control while providing the actionable insights needed to scale your organization.
Contact / Support
For security inquiries, contact us at privacy@ninchi.ai.