Security
What we never store
Last updated · October 7, 2026
The categories of data that never reach Lutril at all.
What we never store
- The contents of your documents and files. The file exposure module opens a file to classify it and keeps only the verdict; the bounds are in content analysis.
- The body of your emails. Email discovery asks Gmail for three headers and Microsoft Graph for three fields. No call we make can return a message body.
- The text of prompts your employees type into AI tools. The browser extension analyses it on the device and sends a count of what it found, never the text.
- The sensitive values our detectors match. A card number, an IBAN or an API key is recognised, counted by category, and discarded.
- Your source code. Agent discovery records a file path, a line range and hashes, never the lines themselves.
- Private key material. For cloud service accounts we read key identifiers, ages and validity windows, never the keys.
- The URLs your employees visit. The browser extension reports the registrable domain of catalogued SaaS products, never a full URL, a path or a query string.
- Passwords of your end users in the systems you connect.