Legal
Effective: October 8, 2026
Measures
The Data Processing Addendum is the statement of the measures and of the refusal of a customer audit and a certification report.
Access
A Customer Admin or a Global Admin creates each User. That User belongs to one Company. A Customer Admin creates a User in that Customer Admin's Company.
Sign-in is Microsoft.
The session cookie is Secure, HttpOnly, and SameSite=Lax. The CSRF cookie is Secure. The browser is told to use HTTPS for one year, including subdomains, with preload.
A protected page runs only when the session already has a User.
Break-glass is Company-wide. A Customer Admin of that Company grants it, and only to a Global Admin. The default is 1 hour and the maximum is 24 hours.
Files and the database
A file download link is issued only after the access check, lasts 300 seconds, and allows reading that file. Stored files are not public. Shared-key access is off. Storage accepts HTTPS only, with TLS 1.2 as the minimum. Uploads are scanned for malware.
The database is not on the public network. Password sign-in to the database is off. Database connections require TLS. The database backup is kept for 7 days.
Microsoft encrypts stored files and the database at rest. Stored files use 256-bit AES. Oil Rag has not configured a customer-managed key.
The Sub-Processors list names who processes the material.
Primary Model
The Primary Model and its tools act as the Acting user and fail closed. The Sub-Processors list names the provider of the Primary Model.
Questions
Questions go to legal@oilrag.ai.
© 2026 Oil Rag, LLC