SHERIFF-AI EDR is not yet available for download or purchase — it is in pre-launch, while we raise the funds needed for proper hosting infrastructure and full compliance with Kenya's Data Protection Act. The only interaction most people can have with us today is joining the waiting list. This policy explains what that involves, and what the software itself will and won't collect once it is available.
Who we are
SHERIFF-AI EDR is a product of Pisoque Technologies. For any privacy question, contact us at hello@pisoque.co.ke or +254 713 487 160.
Regulatory status
Pisoque Technologies is not yet registered with the Office of the Data Protection Commissioner (ODPC) under Kenya's Data Protection Act, 2019 (No. 24 of 2019). Registration is in progress, and is one of the two things we are currently raising funds to complete. We state this plainly rather than imply a status we do not hold.
What we collect today — waiting list
- Sign-up details — your email address (required), and name and business type if you choose to give them.
- Google sign-in (optional) — if you use “Continue with Google” instead of typing an email, we receive your email address and name via a signed token that we verify directly with Google. We never see your Google password.
This is used only to notify you when SHERIFF-AI EDR becomes available, gauge demand while we plan, and respond if you contact us. We do not sell it or share it beyond the service providers that run the waiting list for us (email delivery, sign-in verification, and database hosting) — they act only on our instructions and do not use your data for their own purposes.
What the software will collect, once available
SHERIFF-AI EDR is built to run entirely on infrastructure you control. Once you install and deploy it, it will process:
- Endpoint telemetry — process activity, network connections, file-scan results, and trust scores from agents you deploy.
- Device metadata — hostname, operating system, agent version, and enrollment identifiers.
- Account data — administrator username, email, and authentication factors (passwords are stored only as salted hashes; TOTP secrets are stored encrypted).
- Operational logs — audit records of actions taken in the console, for security and compliance.
All of the above stays on your own infrastructure — we do not receive it. There are two honest exceptions: if the software crashes, an anonymized crash report goes to our error-monitoring vendor, automatically, so we can fix it; and if you use the optional AI Assistant, the content of that one query goes to our AI provider, only when you trigger it, never automatically. Nothing else phones home.
We do not collect the contents of your personal files, browsing history, keystrokes, or message bodies. Scanning inspects file fingerprints and security characteristics — not document contents.
How we use it
Once you deploy SHERIFF-AI EDR, it uses the data described above, on your own infrastructure, to:
- Detect, explain, and help you respond to threats on your endpoints.
- Calculate continuous trust scores that drive network access decisions.
- Authenticate administrators and maintain an audit trail.
We never see this data ourselves to improve our own product or for any other purpose, and we never sell it — because, in the local deployment, it never reaches us at all.
Human-in-command
SHERIFF-AI EDR never executes a remediation without an explicit approval, except for playbooks you have configured to auto-approve. AI suggestions always show their reasoning and an approve/deny choice. Your data is used to inform recommendations, not to act autonomously against you.
Where your data lives
Waiting-list sign-ups are stored in our own database and processed through our email-delivery vendor to send you confirmations — those are the only third parties involved today. Once SHERIFF-AI EDR is available, the version we launch first keeps everything on infrastructure you operate — the admin console and database run on your own machine or servers, and we do not receive your endpoint telemetry. A hosted version is planned for later, once funding and compliance are both in place; this policy will be updated with hosted-specific commitments before that version launches.
Retention
Waiting-list sign-ups are kept until launch plus a reasonable follow-up window, or until you remove yourself — every email we send includes a self-serve unsubscribe link, and you can also contact us directly. Once SHERIFF-AI EDR is available, retention of endpoint telemetry, alerts, and event records in the local deployment is entirely under your control, since that data never leaves your own infrastructure. If a hosted version launches later, its retention terms will be published here before it does.
Security
Credentials are hashed, secrets encrypted, and agent identity files are stored with restrictive permissions. Access to the console requires two-factor authentication. We follow the principle of least privilege throughout.
We are committed to encrypting your data both in transit and at rest across its full retention lifecycle.
Data breach notification
In the event of a breach affecting personal data we hold — today, that means waiting-list sign-ups — we will notify the ODPC within 72 hours of becoming aware of it, and affected data subjects without undue delay, as required by the Kenya Data Protection Act, 2019. This commitment extends to any product data we may hold under a future hosted arrangement.
Your rights
Today, this mainly means your waiting-list sign-up: you may request access to, correction of, or deletion of it at any time — use the unsubscribe link in any email from us, or contact us directly. Once you deploy SHERIFF-AI EDR, product data is under your direct control in the local deployment, so you can action most rights over it yourself in the console. Contact us for anything you cannot.
Changes
We will post any material change to this policy here and update the date above. Continued use after a change means you accept the revised policy.