Overview
PursuitIQ is a GovCon decision-intelligence platform operated by Vecturae Consultants, LLC. This policy covers the PursuitIQ web application, the AURA reasoning engine, PursuitIQ Agents, and all related APIs (together, the "Service"), accessible at https://www.getpursuitiq.ai.
By creating an account or using the Service, you agree to the collection, use, and protection of information as described in this policy. If you are using the Service on behalf of an organization, you confirm authority to accept this policy on that organization's behalf.
This policy incorporates NDA-equivalent confidentiality protections (Section 5) that apply to all Customer Data from the moment of ingestion through deletion.
Data we collect
Account and company profile data
Name, work email, organization name, role, NAICS codes, capabilities, contract vehicles, past performance references, and billing information provided during signup or through Settings.
Pursuit and capture data
Saved searches, watchlists, pipeline notes, teaming records, uploaded proposal documents, bid/no-bid decisions, and any other content you create or input into the Service.
Usage and interaction data
Pages visited, features used, session duration, API calls made, AURA queries submitted, Agent interactions, click patterns, and device/browser metadata — collected automatically to operate and improve the Service.
API interaction data
Request payloads, response metadata, rate limit status, and error logs associated with your use of PursuitIQ APIs.
Cookies and similar technologies
Session cookies to maintain authentication, and first-party analytics cookies to understand product usage. We do not use third-party advertising cookies or cross-site tracking.
How we use data
We use collected data for the following purposes:
- Opportunity scoring and analysis. Processing your company profile, capabilities, and past performance to calculate Pursuit Score and deliver personalized opportunity recommendations.
- AI-powered analysis. Providing AURA-generated briefs, chat responses, competitive analysis, and capture intelligence based on your organizational context.
- Platform improvement. Analyzing aggregated, de-identified usage patterns to improve features, reliability, and user experience. Individual Customer Data is never used for this purpose.
- Service delivery. Authenticating accounts, enforcing entitlements, processing payments, and delivering notifications.
- Security and compliance. Detecting fraud, preventing abuse, maintaining audit logs, and fulfilling legal obligations.
- Support. Responding to support requests and providing onboarding assistance.
Data isolation
PursuitIQ operates a multi-tenant architecture with strict organizational-scope isolation:
- Tenant boundary. Each Workspace is an isolated tenant. All Customer Data is scoped to and accessible only within the owning Workspace.
- No cross-tenant data sharing. Data from one organization is never visible to, shared with, or used to benefit another organization. This includes pursuit data, AI outputs, scoring inputs, pipeline information, and any uploaded content.
- Infrastructure enforcement. Tenant isolation is enforced at the database, API, and application layers through row-level security, scoped access tokens, and organization-keyed data partitioning.
- Internal access controls. Company personnel access Customer Data only when necessary to provide support or maintain the Service, under strict role-based access controls and audit logging.
Confidentiality (NDA-equivalent protections)
The Company treats all Customer Data as Confidential Information, subject to the following binding commitments:
5.1 — Definition of Confidential Information
All non-public data uploaded to, created within, or processed by the Service on behalf of your organization constitutes "Confidential Information." This includes but is not limited to: company profiles, capabilities statements, proposal content, bid strategies, teaming arrangements, pricing data, pipeline notes, and organizational decisions.
5.2 — Non-disclosure commitment
The Company shall not disclose your Confidential Information to any third party except: (a) as strictly necessary for service delivery by bound sub-processors (Section 9); (b) as required by law, subpoena, or valid legal process, with advance notice to you where permitted; or (c) with your explicit written consent.
5.3 — Competitor protection
Confidential Information belonging to one subscriber is never shared with, disclosed to, accessible by, or used to derive insights for any competing subscriber. The Company maintains strict information barriers. No employee or system may access or cross-reference data between competing organizations.
5.4 — AI input/output isolation
All AI model inputs (prompts, context, documents) and outputs (responses, scores, analysis) are processed per-organization and are never: (a) shared across tenants; (b) used to train, fine-tune, or improve any foundation model; (c) stored in any shared embedding space or vector database accessible by other organizations; or (d) used for any purpose other than delivering the Service to the owning organization.
5.5 — Standard of care
The Company shall protect your Confidential Information with at least the same degree of care it uses for its own confidential information, and in no event less than reasonable care, including encryption, access controls, and audit logging.
5.6 — Duration
Confidentiality obligations survive termination of your subscription and continue for as long as the information remains non-public, including through the data retention and deletion period described in Section 8.
AI data handling
AURA and PursuitIQ Agents process Customer Data to deliver AI-powered features. The following commitments apply:
- No model training. Customer Data is NOT used to train, fine-tune, retrain, or improve any foundation model — whether operated by the Company, Amazon (Bedrock), Anthropic, or any other provider.
- Per-org processing. AI inference is scoped to your organization. Your data is never co-mingled with another organization's data during processing.
- AWS boundary. All AI processing occurs within the AWS environment. Customer Data does not leave the AWS boundary for AI inference. Model providers (via Amazon Bedrock) are contractually prohibited from retaining or training on request data.
- Ephemeral context. AI model context windows are ephemeral — populated per-request and discarded after response generation. No persistent memory is shared across organizations.
See our AI Usage Policy for additional details on AI systems, accuracy, and opt-out options.
Data storage & encryption
All Customer Data is stored and processed within the following security perimeter:
- Region. AWS us-east-1 (N. Virginia). All primary data storage, compute, and AI inference occur within this region.
- Encryption at rest. AES-256 encryption for all stored data, including databases, object storage, backups, and logs.
- Encryption in transit. TLS 1.2+ for all data in transit, including API calls, web sessions, inter-service communication, and connections to sub-processors.
- Key management. Encryption keys managed through AWS KMS with automatic rotation.
- Backup encryption. All backups are encrypted with the same AES-256 standard and stored within the same AWS region.
Data retention
- Active subscription. Customer Data is retained for the duration of your active subscription with no automatic purging.
- Post-cancellation. Following cancellation or termination, Customer Data is retained for thirty (30) days to allow export or account reactivation. After this window, data is permanently deleted from production systems.
- Backup purge. Residual copies in encrypted backups are purged within ninety (90) days of production deletion.
- Usage and analytics data. De-identified, aggregated usage data may be retained beyond account deletion for service improvement purposes. This data cannot be re-identified to any individual or organization.
- Legal holds. Data subject to a valid legal hold, regulatory requirement, or ongoing dispute may be retained beyond the standard deletion timeline as required by law.
Sub-processors
The following sub-processors may process Customer Data in connection with the Service:
| Provider | Purpose | Data boundary |
|---|---|---|
| Amazon Web Services (AWS) | Infrastructure, compute, storage, AI inference (Bedrock) | us-east-1 |
| Stripe | Payment processing and subscription billing | Billing data only |
| Anthropic (via Bedrock) | AI model inference (Claude) | Within AWS boundary — no data retention by Anthropic |
Key constraint: No Customer Data leaves the AWS boundary for AI inference. Anthropic model access is provisioned through Amazon Bedrock, which contractually ensures that request data is not retained, logged, or used for training by the model provider.
Stripe receives only billing-related information (name, email, payment method, invoice history) and does not have access to pursuit data, AI outputs, or organizational content.
We will notify account administrators at least 30 days before adding a new sub-processor that handles Customer Data.
Your rights (CCPA/GDPR)
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access
Request a copy of the personal data we hold about you and your organization.
Deletion
Request deletion of your personal data. We will comply within 30 days, subject to legal retention requirements.
Portability
Export your data in a structured, machine-readable format at any time from Settings, or by request.
Correction
Request correction of inaccurate personal data.
Restriction and objection
Object to or restrict certain processing activities.
Non-discrimination
We will not discriminate against you for exercising any of these rights.
How to exercise
Submit requests to [email protected]. We will verify your identity and respond within 30 days (or 45 days for complex requests, with notice). California residents may designate an authorized agent to make requests on their behalf.
CCPA-specific disclosures
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. In the preceding 12 months, we have collected the categories of information described in Section 2.
Security measures
The Company maintains a security program aligned with industry standards:
- SOC 2 alignment. Security controls aligned with SOC 2 Type II criteria (Trust Services Criteria). Formal audit in progress.
- CMMC posture. Security practices aligned with CMMC Level 2 requirements to support customers operating in the defense industrial base.
- Access controls. Role-based access control (RBAC) with least-privilege principles for all internal systems. Multi-factor authentication required for all Company personnel.
- Audit logging. Comprehensive audit trails for all data access, administrative actions, and security events. Logs are immutable, encrypted, and retained for a minimum of 12 months.
- Vulnerability management. Regular vulnerability scanning, dependency monitoring, and penetration testing.
- Incident response. Documented incident response procedures with defined escalation paths and communication protocols.
- Employee security. Background checks, security awareness training, and confidentiality agreements for all personnel with access to Customer Data.
For our full security posture, see the Trust & Security page.
Breach notification
In the event of a confirmed data breach affecting your Customer Data:
- Timing. We will notify affected account administrators within seventy-two (72) hours of confirming the breach.
- Content. Notification will include: the nature of the breach, categories of data affected, approximate number of records involved, measures taken to contain the breach, and recommended steps for affected users.
- Ongoing updates. We will provide timely updates as our investigation progresses and additional information becomes available.
- Regulatory notification. We will cooperate with you in meeting any regulatory notification obligations arising from the breach.
Children's privacy
The Service is intended for business use by adults and is not directed to children under 16. We do not knowingly collect personal data from children. If we learn that we have collected personal data from a child under 16, we will delete it promptly.
Changes to this policy
We will update the effective date above when this policy changes. For material changes, we will notify account administrators by email at least thirty (30) days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
Contact
Questions about this policy, data protection requests, or privacy concerns:
Vecturae Consultants, LLC
3801 N Capital of Texas Hwy, Ste E240-3267
Austin, TX 78746
(737) 377-6440