Access and security
How we get access, and how we handle it.
What we ask for, what we never ask for, and what happens to it afterwards.
Never through this website
The request form takes a description of how your system can be reached — “staging endpoint behind our VPN”, “MCP server over SSE in a sandbox tenant”. It does not take credentials, and our service rejects a submission that appears to contain one.
We will never ask you to paste an API key, token, password or private key into a web form or an email. If something claiming to be LogionACE does, it is not us. Forward it to info@logionace.com.
Secure handoff, after payment is confirmed
Access is arranged only once payment for the approved scope is confirmed. At that point we agree a handoff with your team — typically one of:
- a scoped, revocable key issued for the evaluation and nothing else;
- an account in a sandbox tenant you control;
- network access to a staging deployment for a defined window.
Whatever the mechanism, it is time-boxed and revocable by you. We ask for the least access that lets the evaluation run, and we tell you when we are done so you can revoke it.
Paying does not start an evaluation
There is no self-service evaluation, and no automatic run. A confirmed payment means an engagement is funded; a human on our side then arranges access and schedules the work. You will know when it starts because you will have been part of arranging it.
Your responsibilities
- Authority. Whoever submits the request must be entitled to have the system evaluated and to grant the access involved.
- Environment. If the system must not be tested in production, say so on the request and provide a sandbox. We will not decide that for you.
- No production personal data. Evaluation environments should not contain real customer data. Our batteries do not need it, and it should not be exposed to a third party that does not need it.
- Credential hygiene. Issue evaluation-specific credentials, and revoke them when the engagement ends.
What we keep, and for how long
- Evaluation logs and raw outputs: retained for 90 days, then purged.
- The report and its evidence package: retained so we can reissue it to you.
- Your request details: kept to scope the work, quote it, and answer you.
- Payment records: held by Stripe; we store a reference, never card data.
We do not use your evaluation data to train models, and we do not share it with third parties. Published results happen only under a public evaluation, through an approval workflow, after you have seen them. See our Privacy Policy and Trust & Security pages for the full detail.
Your status link
When a request is submitted we issue a status link containing a token. It is the
credential for that one request: anyone with the link can see that request's
status. It lives in the part of the URL after the #, which browsers
do not send to servers, and we keep it in your tab's session storage so a trip to
the payment provider does not lose it. Treat it like a password, and ask us to
reissue it if it has been shared more widely than you intended.
Questions
Security questionnaires, a data processing addendum, NDAs, or anything else procurement needs: info@logionace.com.