Privacy Policy

How Aevum Security collects, uses, stores and protects personal data, in accordance with Singapore's Personal Data Protection Act 2012.

Last updated: 29 July 2026

Who we are and what this covers

This policy is issued by Aevum Security Pte. Ltd. ("Aevum Security", "we", "us"), a company incorporated in Singapore. It covers personal data we collect through aevumsecurity.com.sg, its agent surface at agents.aevumsecurity.com.sg, and direct correspondence with us.

It does not cover personal data we process on behalf of a client under a services agreement. In those engagements the client is the data controller and the relevant data protection agreement governs, not this page.

What we collect

When you use the contact form

We collect only what the form asks for, plus the minimum technical context needed to operate it safely:

  • Your name and email address — so we can reply.
  • The service or solution you selected and your message — so the reply is useful.
  • Your IP address and browser user-agent string, recorded with the submission — for abuse prevention, rate limiting and security investigation.
  • A timestamp of the submission.

We do not ask for, and you should not send us, government identifiers, financial account details, health information, or any sensitive personal data through this form.

When an AI agent submits an enquiry on your behalf

Our agent interface exposes a submit_enquiry action. When an agent calls it, the same fields above are recorded, together with the identity of the agent key used and a cryptographically signed receipt of the transaction. An agent should only call it with your consent; if you believe an agent submitted an enquiry without your authority, tell us and we will delete it.

The read-only agent tools (list_services, get_service_details) collect no personal data. They return our own published service catalogue.

When you simply browse

This website sets no advertising cookies, no analytics cookies and no tracking pixels. Our content delivery and bot-protection provider, Cloudflare, may set strictly necessary cookies to operate its security services and records standard request logs (IP address, timestamp, requested URL, user-agent) for that purpose.

How we use it

  • To respond to your enquiry and to carry on the resulting business conversation.
  • To provide, administer and support services you have engaged us for.
  • To protect this website and our clients — spam filtering, rate limiting, abuse and fraud investigation.
  • To comply with legal, regulatory and record-keeping obligations that apply to us in Singapore.

We do not use your personal data to train machine-learning models, we do not sell it, and we do not send marketing to anyone who has not asked for it.

Who else sees it

We share personal data only with the service providers needed to run this website and reach you, and only to the extent they need it:

ProviderWhy
CloudflareContent delivery, TLS termination, DDoS protection, and the Turnstile challenge that keeps bots out of the contact form
Microsoft (Microsoft 365 / Graph)Delivering the notification email to us and the acknowledgement email to you
TelegramAn internal operational alert that an enquiry has arrived (message content is included so we can triage promptly)

We may also disclose personal data where we are required to by law, by a court, or by a regulator with jurisdiction over us, and to our professional advisers where necessary.

We do not sell, rent, or trade personal data with anyone, for any purpose.

Where it is stored, and for how long

Enquiry records are stored in an encrypted-at-rest database on infrastructure we operate ourselves in Singapore. Email and alerting providers named above process data on their own global infrastructure, which may involve transfers outside Singapore; where that happens we rely on those providers' contractual data protection commitments, consistent with the PDPA's transfer limitation obligation.

We keep enquiry records for as long as needed for the purpose they were collected for, and then for as long as we are required to retain business records — as a rule, up to 24 months from your last contact with us, unless a longer period is required by law or by an ongoing engagement. After that they are deleted.

How we protect it

We are a cybersecurity firm and hold ourselves to the controls we recommend to clients. In particular: TLS in transit throughout, encryption at rest, least-privilege access with access limited to the personnel who need it, network-level isolation of the database from the public internet, rate limiting and bot verification on every submission path, structured audit logging, and a documented patching and vulnerability-management process.

No control set is absolute. If a data breach occurs that is likely to result in significant harm or is of a significant scale, we will notify the Personal Data Protection Commission and affected individuals as required by Part 6A of the PDPA.

Your rights

Under the PDPA you may:

  • Ask what we hold about you and how it has been used or disclosed in the past year (an access request).
  • Ask us to correct anything inaccurate or incomplete.
  • Withdraw consent to our continued use of your personal data. We will tell you the likely consequences — usually that we can no longer respond to your enquiry — and then stop.
  • Ask us to delete data we no longer have a legal or business reason to keep.

Write to [email protected]. We will acknowledge within 5 business days and respond substantively within 30 days; if we need longer, we will tell you why and when.

If you are not satisfied with our response, you may lodge a complaint with Singapore's Personal Data Protection Commission.

Data Protection Officer

Our Data Protection Officer can be reached at [email protected]. Please mark your message "DPO — PDPA request" so it is routed correctly.

Changes to this policy

We will update this page when our practices change, and revise the "last updated" date above. Material changes affecting how we use data you have already given us will be notified to you directly where we hold your contact details.

Aevum Security Pte. Ltd., Singapore. See also our terms of use and our AI agent interface.