Draft — pending operational and legal review. This page describes the current marketing-site data flow only. It is not a security policy, certification, or product-security commitment.
Security & Trust.
The current marketing site collects an access-request email and uses a small set of vendors to serve the site and send follow-up messages. Product security architecture is discussed in the Security overview, which describes intended controls and preview boundaries rather than a public compliance commitment.
// 01
What this site collects.
The praxys.co marketing site is deliberately minimal. Today it collects one thing: the email address you submit through a Request-access form. It's sent to our mailing-list provider so we can follow up about access — nothing else is tracked, and there's no separate analytics tool wired into the site. Standard web-request metadata (like IP address and user agent) is visible to our hosting provider as an inherent part of serving any web page — that's not a Praxys-specific tracker, it's how HTTP hosting works.
// 02
Subprocessors.
Third parties that handle data on our behalf to run this site:
Cloudflare
Hosting & edge network
Serves the site and its assets, and runs the /subscribe request handler. Sees standard request metadata (IP, user agent) as part of serving any HTTP request.
Loops
Email / access-list provider
Receives the email address you submit through a Request-access form so we can contact you about access. We don't send it anywhere else.
// 03
Disclosure process.
A public responsible-disclosure contact and response process have not been finalized. They will be published with an approved security policy before this page is treated as a trust or compliance reference.