Legal

Effective: October 8, 2026

Measures

The Data Processing Addendum is the statement of the measures and of the refusal of a customer audit and a certification report.

Access

A Customer Admin or a Global Admin creates each User. That User belongs to one Company. A Customer Admin creates a User in that Customer Admin's Company.

Sign-in is Microsoft.

The session cookie is Secure, HttpOnly, and SameSite=Lax. The CSRF cookie is Secure. The browser is told to use HTTPS for one year, including subdomains, with preload.

A protected page runs only when the session already has a User.

Break-glass is Company-wide. A Customer Admin of that Company grants it, and only to a Global Admin. The default is 1 hour and the maximum is 24 hours.

Files and the database

A file download link is issued only after the access check, lasts 300 seconds, and allows reading that file. Stored files are not public. Shared-key access is off. Storage accepts HTTPS only, with TLS 1.2 as the minimum. Uploads are scanned for malware.

The database is not on the public network. Password sign-in to the database is off. Database connections require TLS. The database backup is kept for 7 days.

Microsoft encrypts stored files and the database at rest. Stored files use 256-bit AES. Oil Rag has not configured a customer-managed key.

The Sub-Processors list names who processes the material.

Primary Model

The Primary Model and its tools act as the Acting user and fail closed. The Sub-Processors list names the provider of the Primary Model.

Questions

Questions go to legal@oilrag.ai.

© 2026 Oil Rag, LLC