The principle
Corvidint exists so that organizations can defend themselves with evidence. It is built to observe sources an organization is authorized to access, and to keep the proof of what it saw.
It is not a tool for attacking, harassing, exposing or profiting from anyone. Everything on this page follows from that.
What the platform never does
- It never bypasses access controls or authentication on a source.
- It never compromises accounts and never exploits a site or its weaknesses.
- It never downloads leaked data. Leak sites are observed, and their files stay references.
- It never opens attachments in a browser. They are recorded with their name, size and hash.
- It never treats AI output as evidence. Analysis lives in its own labelled block and never overwrites what was captured.
- It never overwrites a capture. Edits to a post are kept next to the original.
What we ask of customers
By using Corvidint you commit to the following.
- Monitor only sources your organization is authorized to access.
- Use it for a legitimate purpose: protecting your organization, your clients, your employees or your supply chain.
- Have a legal basis for processing any personal data you find, and follow the data protection law that applies to you.
- Ask for credential monitoring only on domains your organization has verified.
- Give each person the narrowest role they need: viewer, analyst, operator or admin.
Uses we do not allow
We may refuse or end service for any of these.
- Targeting, tracking, harassing, threatening or exposing individuals.
- Buying, trading or redistributing stolen data, credentials or access.
- Extortion, retaliation or any attempt to attack the sources or people being observed.
- Profiling people on the basis of protected characteristics.
- Collecting from a source you are not authorized to access.
- Any use that breaks the law.
Safeguards built in
These rules are not only a promise. The platform enforces them.
- Roles per workspace, and workspaces isolated by the API on every request.
- Explicit confirmation before any high-impact action runs.
- An audit trail of every decision, attributable to a person, refusals included.
- Outbound traffic denied by default, with egress opened source by source.
- A retention limit for each class of data, with legal hold when a case needs it.
- Every collection run ends in a named outcome, so silence never hides a failure.
Personal data in what is collected
Material from underground sources can contain personal data about third parties, for example people whose details appear in a leak. The customer decides why and how that material is processed, and answers for it.
To reduce risk, indicators are defanged, files are never downloaded from leak sites, access is limited by role, and retention is set per class of data.
Reporting abuse
If you believe Corvidint is being used against this policy, write to [email protected] with what you saw. We review every report. Where the evidence supports it, we suspend access, and we cooperate with the authorities when the law requires it.
To report a security vulnerability instead, read the security page.
Changes
We will update this policy when the product or the law changes. The date at the top shows the latest version.