Skip to content
Legal

Privacy

Last updated 3 October 2026

Who we are

This policy covers namiq.io, the Lattice service at lattice.namiq.io (including the Lattice Analyst chat at lattice.namiq.io/chat and the installable app version of it), and the emails we send from them. The controller is NamiQ LLC, Austin, Texas, United States. Write to [email protected] about anything on this page. You do not need an account to read this site.

In short: we collect only what you type into our forms and what is needed to run and protect the services, we use a language model that runs on our own server and not an outside AI service, we do not sell your data or share it for advertising, and you can have it deleted. The detail follows.

What we collect

If you fill in a form on this site: your name, work email, company, and anything you chose to write in the message field. Four fields are optional and are blank unless you type in them — your role, a phone number, a ZIP or postal code, and, if you are asking about IT and security, a rough device count.

That is the complete list. The postal code is a postal code, not an address: it tells us your timezone and which rules apply, and we do not ask where you live. We do not buy contact data, and we do not enrich what you give us from third-party data brokers.

Lattice beta access

If you ask for access to the Lattice private beta we collect the same fields as the other forms, plus one sentence about what you want to use it for, and a record that the beta terms were shown to you: which version, and the date and time. If you later verify your account to raise your limits, we also keep your name, position, company and what you will use it for, and a record that you accepted the beta terms. If we approve your request and give you a key, we also keep a short identifier for that key and a log of the requests made with it: the tool or endpoint, the public identifiers asked about, timing, the client name and version it reports, and a salted one-way hash of the network address. We do not store the raw address in those logs, and you should not put personal data or secrets in your queries. We keep those request logs for 60 days and then delete them. We keep the record of a key, including the terms you accepted and the details you gave to verify your account, for six months after the key expires or is withdrawn, and then delete it. If you ask us to delete your details we also revoke your Lattice key and delete its records.

Why we are allowed to hold it

Consent, which you gave by ticking the box on the form. We record the date you gave it. You can withdraw it at any time and we will stop — see below.

We confirm the address before we use it

Ticking a box proves somebody typed an address. It does not prove it was yours — anyone can put a stranger’s address into a public form. So after a submission we send one email to that address and nothing else happens until someone clicks the link in it. The enquiry sits marked unconfirmed, and an unconfirmed enquiry is not worked and not marketed to.

That email carries a copy of everything that was submitted, so if it was not you, you can see exactly what someone entered in your name. It also carries a second button that says it was not you. Pressing it adds your address to our suppression list, which means nothing from us can reach it again — not that enquiry, not a newsletter, and not somebody typing it in again next month.

Ignoring the email is also an answer. The enquiry stays unconfirmed and we never write again.

Where it is held

In a CRM we host and operate ourselves, on our own hardware in Austin, Texas, United States. It is not in a third-party cloud CRM.

We state the location plainly because it matters: if you are in the EU or the UK, your data is processed outside it, in the United States. If that is a problem for your organisation, tell us before you send anything — we would rather have that conversation first than after.

How often we will contact you

At most once per company per 30 days. This is a limit built into our system, not a policy someone has to remember.

Getting rid of it

Use the unsubscribe page, or write to [email protected]. Two options:

  • Suppression — we stop contacting you. We keep a record of the address for the sole purpose of not contacting it again.
  • Erasure — we delete what we hold, in both the CRM and our login system, within 30 days.

Lattice Analyst (the chat)

To use the chat you give a name, work email, company, optionally your role, what you will use it for, and you tick two boxes: the beta terms (we record which version and when) and permission to contact you about the request. You then confirm your email by opening a link we send you. Only after that is a Lattice key issued to you.

Your questions.A question is read for public identifiers (CVE, ATT&CK technique, threat group, CWE). The graph is looked up for those identifiers with your key, and a language model that runs on our own server writes the answer. Nothing you type is sent to an outside AI provider. We do not store the text of your conversation. We do log that a lookup happened, with the public identifier looked up, so an identifier you mention appears in the request log described below. Do not put personal data, customer data, credentials or secrets into a question.

Cookies and similar technologies

One cookie, strictly necessary. After you confirm your email or enter a key, the chat sets a cookie named la_session. It is encrypted, marked HttpOnly and Secure so scripts on the page cannot read it, and lasts up to 30 days or until your key expires, whichever is first. It keeps you signed in on this browser, including after you close it, until you choose Sign out in the menu. Signing out deletes it.

Preferences.Your light or dark choice is kept in your browser’s local storage and never sent to us. If you install the chat as an app, your browser keeps a copy of the page’s files so it can open without a connection; it holds no conversation.

What we do not use. No advertising cookies, no analytics or tracking scripts, no social-media pixels, no cross-site tracking and no fingerprinting. Cloudflare, which delivers our sites, may set its own security cookie to tell people from bots.

Who handles data for us

We use two service providers, each only to do what we ask:

  • Cloudflare, Inc. delivers our sites and protects them from abuse, so it sees the network traffic to them, including your IP address.
  • Mailjet sends our transactional email, such as the link that confirms your address, so it handles your email address and the message.

Everything else, including the CRM, the key service, the graph and the language model, runs on our own hardware. We do not sell personal information, and we do not share it for advertising or cross-context behavioural advertising (the terms the California privacy law uses). We disclose it only to these providers, where the law requires it, or to protect our rights and users.

How long we keep it

  • Enquiries and sign-ups in the CRM: until you ask us to delete them, and an unconfirmed one is not worked or marketed to.
  • Request logs (tool or endpoint, public identifiers, timing, client name, key identifier, salted one-way hash of the network address): 60 days, then deleted.
  • The record of a key, with the terms you accepted and the details you gave: six months after the key expires or is withdrawn, then deleted.
  • The sign-in cookie: up to 30 days, or until you sign out.
  • Email addresses on our suppression list (people who asked us never to write again): kept, because deleting them would let us write to you again.

Your rights

Wherever you live you can ask us to tell you what we hold about you, correct it, delete it, or stop using it. If you are in the European Economic Area or the United Kingdom you also have the right to restrict or object to our processing, to receive your data in a portable format, to withdraw consent at any time (without affecting what was done before), and to complain to your data-protection authority. If you are a resident of California or another US state with a privacy law, you have the right to know, delete and correct, to opt out of the sale or sharing of personal information (we do neither), and not to be treated worse for using these rights.

Write to [email protected] from the address concerned. We may ask you to confirm it is yours so we do not give your data to someone else. We answer within 30 days. An authorised agent may write for you with your written permission. To have everything deleted, follow the steps on the data deletion page.

Children

These services are for working professionals and are not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has given us information, write to us and we will delete it.

How we protect it

Connections use HTTPS. The sign-in cookie is encrypted and unreadable to scripts. Keys are stored only as one-way digests, and network addresses in logs only as salted one-way hashes. The services run on hardware we control, and access to the CRM and key service is restricted. No system is perfectly secure; if a breach affects your data we will tell you as the law requires.

Google and Meta (Facebook, Instagram)

We do not offer sign-in with Google, Facebook or any other social account, so we receive no data from your Google or Meta account. We do not use Google Analytics, Google Ads, the Meta Pixel or any other advertising or measurement code from these companies on our sites. We do not use data from Google or Meta APIs. If that changes, we will say so here first and handle that data as their platform terms require, including Google’s Limited Use requirements. If you contact us through a Google or Meta product, that company’s own privacy policy governs what it holds; what you send us directly is covered here. To have your data deleted, see the data deletion instructions.

Changes to this policy

We will post any change here with a new date at the top. If a change materially affects how we use data you have already given us, we will tell you by email before it applies.

Contact

NamiQ LLC, Austin, Texas, United States. [email protected].

Product data is separate

If you become a customer, what our product observes in your environment — hosts, vulnerabilities, incidents, telemetry — is held in a separate system that our commercial and marketing tools have no read access to. That separation is enforced architecturally, not by policy.