SafeKey Lab privacy statement.
This website is static and carries no analytics, no advertising, and no third-party embeds. It is short because there is little to declare — but it is written to the same structure a reviewer would expect from any defense supplier.
Last updated: 19 August 2026
Who we are
SafeKey Lab (“SafeKey”, “we”, “us”) builds security software for autonomous systems. We are the controller of the personal data described in this statement.
Reach us at [email protected] for anything in this document, including a request to exercise your rights.
What this statement covers
This statement covers safekeylab.com and correspondence you send us. It does not cover any SafeKey product deployed inside a customer environment: where a customer runs our software, that customer is the controller of the data in it and their own policies and our contract with them govern.
It also does not cover sites we link to. Following an outbound link takes you somewhere with its own terms.
What we collect
Nothing you have not chosen to send. There are no accounts, no sign-up, no newsletter, and no forms that post to a server. The contact routes on this site open a message in your own email client; nothing reaches us until you press send.
Correspondence. If you email us, we hold your message, your address, and our reply, along with anything you choose to put in it.
Connection data, held by our providers. Serving a web page necessarily discloses your IP address, user agent, and the URL requested to the infrastructure carrying the request. Our hosting and content-delivery providers process and log that data to deliver the site, absorb attacks, and record network errors. We do not combine it with anything else or use it to build a profile of you.
Why and how we use it
To reply to you, to continue a conversation you started, and to meet obligations that arise from it — a non-disclosure agreement, an export-control eligibility check, or a contract.
To keep the site available and defend it against abuse, using the provider logs described above.
Where the law requires a basis: our legitimate interest in operating a website and responding to enquiries, and the performance of a contract where one exists. We do not rely on consent for anything on this site, because nothing here asks for it.
When we share it
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not disclose it for anyone else's marketing.
We use a small number of processors to run the site and our email, bound by contract to act on our instructions. We disclose information to a government or court where we are legally compelled to, and to professional advisers where necessary.
If our business is ever transferred, correspondence may transfer with it, subject to this statement.
Cookies and tracking technologies
This site sets no cookies. It loads no analytics, no advertising tags, no social widgets, no external fonts, and no third-party scripts of any kind. A content security policy blocks cross-origin requests outright, so visiting this site does not hand your visit to anyone else.
There is no consent banner because there is nothing to consent to. If that changes, this section changes first.
How long we keep it
Correspondence: for as long as the conversation is live, and afterwards where a contract, an export-control record, or a legal obligation requires it.
Provider logs: for the retention period each provider operates, typically days to a small number of weeks.
International transfers
We are based in the United States and our providers operate globally, so data may be processed outside your country, including in the United States.
Where data moves out of the United Kingdom, the European Economic Area, or Switzerland, we rely on the transfer mechanisms our providers put in place, including standard contractual clauses.
Children's data
This site is aimed at professional and government audiences and is not directed to children. We do not knowingly collect data from anyone under 16. If you believe we have, write to us and we will delete it.
Your rights
Subject to local law, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. We do not carry out automated decision-making that produces legal effects.
Write to [email protected]. We will respond within the period your law allows, and we will not charge you or treat you differently for asking.
United Kingdom, EEA and Switzerland
If you are in the UK, the EEA, or Switzerland, the rights above are your GDPR or UK GDPR rights, and our lawful bases are those set out under “Why and how we use it”.
You may complain to your national supervisory authority. We would rather you came to us first, and we will tell you plainly what we hold.
Additional disclosures for US residents
Residents of California and other US states with comprehensive privacy laws have rights to know, delete, and correct, and to opt out of sale, sharing, and targeted advertising.
The categories we may hold are limited to identifiers you send us — name, email address, employer, and the content of your message — plus the internet and network activity in provider logs described above. We collect no sensitive personal information through this site and we do not use it for profiling.
Do not sell or share
We do not sell personal data and we do not share it for cross-context behavioural advertising, and we have not in the preceding twelve months. There is nothing to opt out of. If that ever changes we will publish a mechanism before it does, not after.
Security
The site is served over TLS with a strict transport policy and a restrictive content security policy. Correspondence is held in access-controlled systems.
If you find a weakness, our disclosure policy is at /security and we would rather hear it from you than from an adversary.
Changes to this statement
We will update this page when our practices change and revise the date at the top. Material changes will be described rather than quietly folded in.
Ask a person, not a form.
Write to [email protected] and a person will answer. Security findings go to [email protected].