Privacy Policy

How Adversys collects, uses, and protects personal information when you use Maximus and related services.

Privacy PolicyEffective 2026Last updated 2026

Transparency notice

These policies describe our standard practices and are published for transparency. If your organization has a signed agreement with us (for example, an MSA, order form, or data processing addendum), that contract controls where it conflicts with this summary. Please share these documents with your legal counsel before relying on them for compliance decisions.

Adversys Inc. ("Adversys", "we", "our", or "us") publishes this Privacy Policy to explain—in plain language—what personal information we collect when you use Maximus, our websites (including https://adversys.ai), and related services (collectively, the "Services"), how we use it, and the choices you have. Maximus is a multi-tenant platform. Your employer or contracting organization ("Customer") typically controls the tenant where you work. In many cases, Customer is the data controller for security assessment data; Adversys processes personal information as described here and in agreements with Customer. By using the Services, you acknowledge this Privacy Policy. If you do not agree, do not use the Services.

1. Information we collect

We collect information in these categories: Personal information you provide • Name, work email address, job title, and account credentials • Organization and role within your tenant (for example, PM, SME, Admin) • Support and sales communications you send us Account and usage information • Subscription or deployment metadata, account settings, and billing contact details (where applicable) • Audit and activity logs (sign-in times, feature usage, administrative actions) needed to operate and secure the platform • Device and browser data: IP address, user agent, approximate location derived from IP, pages viewed, and session diagnostics Customer content • Threat models, engagements, findings, scans, reports, and files you upload — stored within your organization's tenant • Integration credentials and LLM API keys your administrator configures (stored encrypted; we do not display secrets after save) Cookies and similar technologies • Session cookies and analytics needed to keep you signed in and improve the Services • You can limit cookies in your browser; some features may not work without them

2. How we use information

We use collected information to: • Provide, operate, maintain, and improve Maximus • Authenticate users and enforce role-based access • Provide customer support and respond to inquiries • Send service announcements, security alerts, and (with consent where required) product updates • Monitor for abuse, fraud, and unauthorized access • Comply with legal obligations and enforce our Terms of Service • Generate aggregated, de-identified analytics that do not identify individuals or tenants

3. How we share information

We do not sell personal information. We may share information with: Service providers — Cloud hosting, authentication, email delivery, monitoring, and support tools that process data on our behalf under contractual confidentiality and security obligations. LLM providers — When your organization enables AI features and you use them, relevant prompts and context are sent to the provider your administrator selected, under that provider's terms. Customer administrators — Users within your tenant with appropriate roles can see membership and activity permitted by their role. Legal and safety — When required by law, court order, or to protect rights, safety, and integrity of the Services, including cooperating with law enforcement regarding unauthorized intrusion activity. Business transfers — In connection with a merger, acquisition, or asset sale, subject to continued protection consistent with this policy. We do not share tenant security assessment content with other customers.

4. Data security

We implement administrative, technical, and physical safeguards designed to protect personal information, including: • TLS encryption for data in transit • AES-256 (or equivalent) encryption for sensitive data at rest • Role-based access controls and multi-factor authentication for administrative access • Logging, monitoring, and periodic security assessments No method of transmission or storage is completely secure. We cannot guarantee absolute security.

5. Data retention

We retain personal information for as long as needed to provide the Services, meet legal obligations, resolve disputes, and enforce agreements. Retention of Customer content is governed by your organization's settings and contractual terms. When data is no longer required, we delete or de-identify it using reasonable measures.

6. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict, or port personal information, and to object to or withdraw consent for certain processing. • Work account data — Contact your organization administrator first; they control your tenant. • Direct requests to us — Email MarkC@adversys.ai. We may need to verify identity and coordinate with your organization. California residents may have additional rights under the CCPA/CPRA. We do not sell personal information as defined by California law.

7. International transfers

Adversys Inc. is based in the United States. If you access the Services from other countries, your information may be processed in the U.S. or other locations where we or our service providers operate. We use appropriate safeguards for cross-border transfers as required by applicable law.

8. Children's privacy

The Services are intended for business and professional use. We do not knowingly collect personal information from anyone under 16. Contact MarkC@adversys.ai if you believe we have collected such information.

9. Changes to this policy

We may update this Privacy Policy to reflect product, legal, or operational changes. We will post the revised policy at /docs/legal/privacy with an updated "Last updated" date. Material changes may be communicated by email or in-product notice where appropriate. Continued use after the effective date constitutes acceptance.

10. Contact us

Adversys Inc. Privacy inquiries: MarkC@adversys.ai Security inquiries: MarkC@adversys.ai Address: 6977 Navajo Rd, San Diego, CA 92119-1503, United States Phone: 1-858-228-8115 These policies describe our standard practices and are published for transparency. If your organization has a signed agreement with us (for example, an MSA, order form, or data processing addendum), that contract controls where it conflicts with this summary. Please share these documents with your legal counsel before relying on them for compliance decisions.

Effective date: 2026. Last updated: 2026.

Related legal documents