Privacy

Privacy Policy

This policy explains how Singulari Technologies, Inc. handles personal information — both for visitors to this website and for data processed through the Singulari platform. The two are treated differently, and this policy addresses each separately.
v1.0.0
Aug 11, 2026
What is included
  • 1. Who we are
  • 2. Two different roles
  • 3. Website visitors — what we collect
  • 4. Website visitors — why and on what basis
  • 5. Platform data — what is processed
  • 6. Platform data — what we do not do with it
  • 7. Service providers and subprocessors
  • 8. Retention
  • 9. Security
  • 10. International transfers
  • 11. Your rights
  • 12. Cookies
  • 13. Children
  • 14. Changes to this policy
  • 15. Contact

1. Who we are

Singulari Technologies, Inc. ("Singulari", "we", "us") is a Delaware corporation with its registered office at Newark, Delaware, United States.

Privacy enquiries: hello@singulariapp.com

2. Two different roles

Singulari handles personal information in two distinct capacities, and different rules apply to each.

As a controller. For visitors to this website and for people who contact us directly, we decide what information we collect and why. Sections 3, 4, 11 and 12 apply.

As a processor. When a carrier, MGA, or broker uses the Singulari platform, we process data on their instructions and on their behalf. They determine the purpose; we act under a written agreement with them. Sections 5 through 10 apply, and a data subject exercising rights in respect of that data should contact the organization that engaged us.

3. Website visitors — what we collect

Information you give us. If you complete a contact form or a walkthrough request, or email us, we collect the information you provide — typically your name, work email address, organization, role, and anything you write in a message field.

Information collected automatically. When you visit this website we collect standard technical information: IP address, browser type and version, device type, referring page, pages viewed, and time of visit.

What we do not collect through this website. We do not ask for and do not want confidential submission data, insured account details, or personally identifiable information about third parties. Please do not send it through a web form. Where a live account needs to be shared with us, we will agree confidentiality and data-handling terms in writing first.

4. Website visitors — why and on what basis

We use website information to:

Respond to enquiries and arrange walkthroughs
Understand which pages are read and how the site is used, so we can improve it
Maintain the security and availability of the site
Meet legal and regulatory obligations

Where a legal basis is required, we rely on our legitimate interest in operating and improving our business, on taking steps at your request before entering into a contract, and on your consent where consent is required — for example for non-essential cookies.

We do not sell personal information, and we do not share it with third parties for their own marketing.

5. Platform data — what is processed

Where an organization uses the Singulari platform, the following categories of data may be processed on their behalf.

Configuration data read from connected systems. Where an applicant authorizes a connection, Singulari reads control-relevant configuration from systems such as Microsoft 365, Google Workspace, Vanta, Drata, and JumpCloud. This is limited to what answers the underwriting question — for example whether multi-factor authentication is enforced, how many administrator accounts exist, and what proportion of devices carry an endpoint agent.

Connections are read-only. Singulari requests the narrowest scope that answers the question asked, and there is no write path back into a connected system. This is an architectural property of the platform, not only a policy commitment, and it is documented and available for security review.

Assessment responses. Answers given by an applicant in the Singulari assessment, together with the identity of the person who answered where a section is assigned to a named individual.

External scan results. Information observable from outside an applicant's network without credentials — such as exposed remote services, certificate and DNS posture, and end-of-life software visible externally.

Account and user data. Names, work email addresses, organization, and role for the people who use the platform.

Audit and access logs. Records of who accessed what and when, retained so that outputs remain traceable.

What we minimize. Inputs to the platform are structured control data, not raw system contents. Singulari does not read email bodies, document contents, files, or customer records held in a connected system.

6. Platform data — what we do not do with it

We do not use one customer's data to inform another. A carrier's appetite, thresholds, rules, and decisions are theirs alone and are not used to inform any other carrier's output.

We do not sell data. Not to carriers, not to brokers, not to data brokers, not to anyone.

We do not use customer data to train models. Where an AI provider is used (see section 7), inputs are not used by that provider to train its models, and Singulari does not train models on customer data.

Any future aggregated benchmarking would be opt-in. If we ever offer anonymized, aggregated market benchmarking, participation would be explicitly opt-in, revocable, and off by default. It is not offered today.

7. Service providers and subprocessors

Confirm this list against your actual stack before publishing. Remove anything not in use; add anything missing.

We use the following categories of service provider. A current list of named subprocessors is available on request and is provided to platform customers under their agreement.

Purpose Provider Data involved
Application hosting [Vercel] Platform data in transit and at rest
Database [Neon] Platform data at rest
Authentication [WorkOS] User account data
Encryption key management [AWS KMS] Encryption keys
Transactional email [Resend] Recipient email addresses
Error monitoring [Sentry] Technical diagnostics; scrubbed of sensitive fields
Uptime monitoring [Better Stack] Availability telemetry
Background job processing [Inngest] Job metadata
Document reading and narrative drafting [Anthropic] Structured control data; see below
Website hosting [Webflow] Website visitor data

On the AI provider. Singulari uses a third-party AI model for two purposes: reading carrier application forms to extract their question structure, and drafting the narrative summary of a completed assessment. Inputs are structured and minimized — control answers, flags, and category-level results — not raw applicant records. Model inputs are not used to train the provider's models. The mapping from control gap to coverage term is authored and deterministic and does not involve a model.

We require subprocessors to provide appropriate safeguards, and we notify platform customers of material changes to this list in accordance with their agreement.

8. Retention

Placeholder periods. Set against actual platform behaviour before publishing.

Data Retention
Website enquiries 24 months from last contact
Website analytics 14 months
Assessment and evidence data For the term of the customer agreement, then 30 days
Audit and access logs 1 years, to preserve traceability
Account data For the term of the customer agreement, then 30 days

Where we act as a processor, retention is governed by the customer's agreement and their instructions. On termination, data is returned or deleted as that agreement specifies.

9. Security

Measures in place include:

Encryption in transit and at rest, with field-level encryption for sensitive values
Tenant isolation enforced at the database layer
Read-only connector scopes with no write path
Access controls and audit logging on every access
Managed encryption keys held in a dedicated key-management service
Error and availability monitoring, with sensitive fields scrubbed from diagnostics

No system is perfectly secure. We do not represent that our measures are impenetrable, and we will notify affected customers and, where required, regulators and individuals, in accordance with applicable law and our customer agreements.

Security documentation is available for vendor review at hello@singulariapp.com

10. International transfers

We are based in the United States. If you access this website or the platform from outside the United States, your information will be transferred to and processed in the United States.

Where personal data originating in a jurisdiction with transfer restrictions is processed, we will implement an appropriate transfer mechanism as required by law.

11. Your rights

Depending on where you are located, you may have the right to access the personal information we hold about you, to request its correction or deletion, to object to or restrict its processing, to receive it in a portable format, and to withdraw consent where processing is based on consent.

To exercise a right in respect of information we hold as a controller — for example an enquiry you sent us — contact hello@singulariapp.com

Where the data was processed on a customer's behalf, please contact that organization. They determine the purpose of the processing, and we will support their response to your request.

We will not discriminate against you for exercising a right.

12. Cookies

Confirm against the cookies actually set. If Webflow analytics or any third-party script is enabled, list them and consider whether a consent banner is required.

This website uses:

Essential cookies, necessary for the site to function
Analytics cookies, to understand how the site is used

You can control cookies through your browser settings. Disabling essential cookies may affect how the site works.

13. Children

This website and the Singulari platform are intended for business use by professionals. They are not directed at children, and we do not knowingly collect personal information from anyone under 16.

14. Changes to this policy

We may update this policy. The version number and effective date at the top of this page indicate the current version. Where a change materially affects how we handle personal information, we will notify platform customers in accordance with their agreement.

15. Contact

Privacy enquiries: hello@singulariapp.com

Singulari Technologies, Inc. Newark, Delaware, United States