Detectory

Privacy Policy

Last updated: July 3, 2026

1. Introduction

Detectory AI is a fraud detection product operated by Tactical Edge AI. In this policy, "Detectory," "we," "us," and "our" refer to Tactical Edge AI and the Detectory AI product. Detectory helps health insurance marketplaces, public-benefit programs, insurers, and regulated program integrity teams identify suspicious documents, synthetic identities, and coordinated fraud patterns.

This policy covers personal information collected through detectory.ai, demo requests, business communications, and related sales or support activity. Data processed inside the Detectory product on behalf of a customer is governed by that customer's agreement, data processing terms, and applicable program rules.

2. Information We Collect and Process

  • Prospect and contact data: name, work email, organization, role, message contents, and scheduling details when you contact us, request a demo, or ask for information.
  • Website and device data: IP address, browser, device type, referring page, approximate location, page views, and cookie preferences. Optional analytics or marketing cookies load only according to your choices.
  • Customer and user data: business contact details, account information, support communications, and product usage information for customer administrators and authorized users.
  • Customer-controlled program data: documents, case materials, application records, audit logs, and related signals that customers submit or connect to Detectory for fraud detection. We process this data as a service provider or processor under customer instructions.

3. Legal Basis for Processing

  • Contract: responding to your demo request or sales inquiry and performing agreements with customers.
  • Consent: analytics and marketing cookies, and email communications you opt into. You may withdraw consent at any time via the cookie preferences page.
  • Legitimate interest: securing our website, preventing abuse, improving our services, and protecting public programs from fraud, waste, and improper payments.
  • Legal obligation: preserving records, supporting audits, responding to lawful requests, and meeting regulatory or contractual requirements.

4. How We Use Information

  • Respond to demo requests, questions, and support needs
  • Operate, secure, monitor, and improve our website and services
  • Send service, security, and requested business communications
  • Provide fraud detection, document forensics, identity risk review, case workflow, and audit trail capabilities to customers
  • Comply with legal, contractual, security, and audit obligations

We do not sell personal information, and we do not share it with third parties for cross-context behavioral advertising.

5. Disclosures

We disclose personal information only as needed to operate Detectory, comply with law, or fulfill customer instructions. Recipients may include hosting providers, security and monitoring vendors, communication and scheduling tools, analytics providers, professional advisors, and government or legal authorities when required by law. Customer-controlled program data is not used for unrelated marketing.

6. Data Retention

  • Inquiry and demo request data: retained up to 24 months after last contact, then deleted or anonymized.
  • Analytics data: retained in aggregated form for up to 26 months.
  • Contract and billing records: retained as required by law and accounting standards.
  • Customer-controlled program data: retained under the customer agreement, customer instructions, and applicable program integrity or audit requirements.

7. Data Location and International Use

Detectory is intended for United States customers and public-program use cases. Our website and services are hosted in the United States. If you access the site from outside the U.S., your information may be transferred to and processed in the U.S.

8. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal information, restrict or object to processing, and withdraw consent.

  • GDPR (EU/EEA/UK): you may also lodge a complaint with your local supervisory authority.
  • CCPA (California): you have the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell personal information. You can exercise the opt-out on the cookie preferences page. We will not discriminate against you for exercising your rights.

To exercise any right, submit a request through the contact form. We respond within 30 days.

9. Security

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit (TLS), encryption at rest, access controls with least-privilege principles, logging, vulnerability management, and vendor review. Our product security program is designed to support customer reviews against SOC 2, CMS MARS-E, NIST 800-63, CMMC 2.0, StateRAMP, and FedRAMP-aligned requirements where applicable.

10. Contact

Privacy questions, rights requests, and general inquiries can be submitted through the contact form.