saspiBack to sign in

SASPI · Monitoring & Ownership Disclosure

Monitoring & Ownership Disclosure — SASPI Pilot (v0 DRAFT)

Status: DRAFT for legal review. Binds no one until published. Last updated: 27 August 2026 · Applies to: SASPI Cockpit and the Enigmo desktop runtime (pilot/staging)

SASPI is a governance product. Its job is to let an organization see and govern how work — human and AI — happens in its projects. Because observation is the product, we owe you a plain description of exactly what is observed, what is not, where the data goes, and who owns it. This document is that description.

1. The two pieces

  • SASPI Cockpit is the web application your organization's admins use: projects, people, grants, vaults, and the audit record.
  • Enigmo is the runtime installed on an enrolled machine. It is the only component that observes anything, and it only exists on a machine because that machine was deliberately enrolled.

2. When observation starts — and the confirmation gate

  • Nothing is observed before enrollment. Installing Enigmo does not enroll a machine; enrollment is an explicit, visible step tied to a person and an organization, and the enrollment terms your organization publishes are shown before it completes.
  • Nothing leaves a machine until you confirm it. Until enrollment is confirmed, Enigmo transmits nothing to the Cockpit. Records created on the machine stay on the machine.
  • Your organization may direct SASPI to ingest project history that predates governance (for example, repository history) to establish a baseline. That is project material your organization already holds — not new observation of you.

3. What Enigmo observes

Observation is scoped to governed work:

  • Work sessions in governed projects — sessions you initiate in a governed workspace are observed and attributed.
  • Governance probes — Enigmo may run short, headless checks it initiates itself to verify that the governed state is what it claims to be.
  • The AI channel — privileged actions by agents and AI tools flow through Enigmo; an agent cannot do what your organization has not permitted, and what it does is recorded.
  • Grants and secrets at the point of use — credentials are brokered at the moment of use and never land on the developer's machine. The use is recorded; the secret is not stored there.

4. What Enigmo does not do

  • No observation outside governed scope. Work outside governed projects and workspaces is not recorded.
  • No keystroke logging, no screen recording, no webcam or microphone access. [JULIA: confirm we want these stated as affirmative product commitments.]
  • No collection of personal files unconnected to governed project scope.
  • No sale of data. No advertising use. Ever.

5. Always-on, and what quitting means

Enigmo is designed to run continuously on an enrolled machine, because a governance record with silent gaps is not a record. You can still quit it: quitting is a deliberate, visible act, and the period while Enigmo is off is sealed in the record as ungoverned time — honestly marked, not silently ignored. Crash recovery restarts Enigmo automatically; a deliberate quit is honored and stays quit until you start it again.

6. Who owns what

  • Your work product is yours (or your employer's, per your employment terms). SASPI claims no ownership of code or work product it observes.
  • The governance record belongs to the organization that operates the tenant: grants, accesses, session records, and changes — attributed, timestamped, and exportable.
  • SASPI owns the software. We act on the organization's instructions for workspace data; we do not use the content of your governed work to build unrelated products. [JULIA: align wording with processor role in the Privacy Policy.]

7. Retention and deletion

Observation records are retained per the organization's configured clearance window, subject to a platform ceiling of 365 days. Pilot data lives in a staging environment and may be reset at pilot end with notice. Export of the organization's governance record is available on request and at termination.

8. Questions and requests

Observed developers can raise questions or data requests through their organization's admin, or directly to us: [privacy@saspi.ai — mailbox to be provisioned before publication].

— SASI COMUNICACAO AGIL LTDA · CNPJ 35.379.670/0001-45 [JULIA: confirm contracting entity; the legacy interface footer referenced "SASI Holdings Limited" — resolve which entity publishes this.]

Privacy·Terms·Monitoring