XeroRisk minimizes what it stores. New event writes keep path-only request URLs and hashed identifiers where designed. Raw bodies follow the retention window (24 hours unless you bought more).
Customer risk reports and chat tools must not receive API keys, connector secrets, raw event bodies, or Spike evidence payloads.
For legal terms, see the Privacy Policy and Terms on xerorisk.ai. Those pages are the contract. This article is product orientation only.
Privacy or legal requests (DSAR, ownership dispute, vulnerability report) go to a human at [email protected] — not to Fin.