Data Governance Protocol
Operational compliance and data sovereignty for the generative era.
Mavorac operates on a principle of Zero-Trust Data Architecture.
In the generative AI landscape, the boundary between proprietary corporate data and public training models is the primary vector of enterprise risk. Standard privacy policies are insufficient for this paradigm.
No Sensitive Customer Data Required
Mavorac does not require customer records, household-level consumer data, confidential sales data, unreleased financials, or personally identifiable consumer data to conduct an SDI diagnostic. The work focuses on public, licensed, partner-controlled, and client-approved sources that shape answer-layer representation.
This protocol outlines our cryptographic standards, LLM isolation boundaries, and regulatory alignments designed to protect enterprise information while conducting answer-layer diagnostics and approved source-level remediation.
Designed to support compliance with EU and California data privacy frameworks, including GDPR and CCPA/CPRA obligations where applicable.
Security controls are designed with reference to AICPA Trust Services Criteria.
Every engagement is governed by mutual NDA prior to any diagnostic activity. Client identity, data architectures, and remediation strategies are never disclosed.
LLM Isolation Protocol
The primary concern of enterprise legal counsel is the inadvertent ingestion of proprietary data into public Large Language Models (e.g., OpenAI, Anthropic, Google). Mavorac enforces strict isolation protocols.
No Public Training: Client-provided internal data, strategy documents, and unreleased product roadmaps are never submitted to consumer-facing LLM endpoints.
Zero-Retention APIs: When commercial LLMs are used for analytical processing, Mavorac uses client-approved enterprise-tier API configurations with zero-retention or no-training commitments where available.
Scope of Collection
Mavorac practices data minimization. We collect only the data strictly necessary to execute our services.
Corporate Entity Data
Public and approved-private factual data regarding your organization (e.g., pricing structures, executive biographies, historical timelines) required to build semantic Knowledge Graphs.
Client Relationship Data
Standard B2B contact information (names, corporate emails, billing details) required for account management, invoicing, and secure communications.
Telemetry & Analytics
Anonymized interaction data from our digital properties, utilized strictly for security monitoring and performance optimization. We do not sell telemetry data to third-party brokers.
Infrastructure Security
Client data is secured using enterprise-grade cryptographic protocols.
Encryption at Rest: All proprietary client data is encrypted at rest using AES-256 encryption.
Encryption in Transit: All data transmitted between Mavorac systems and clients is secured via TLS 1.3 or higher.
Role-Based Access Control (RBAC): Access to client data is strictly limited to Mavorac personnel directly assigned to the client’s account, enforced via mandatory Multi-Factor Authentication (MFA).
Client Data Rights
Authorized client representatives may request access to, export of, or deletion of client-provided proprietary materials, subject to contractual retention, legal, and security obligations. Individual data subjects may exercise rights available under applicable privacy laws for personal information held by Mavorac.
For formal compliance inquiries, Data Processing Agreement (DPA) requests, or to contact our Data Protection Officer (DPO), please route communications through our secure legal channel.
compliance@mavorac.com