Operational context is used to serve the organization that supplied it.
SphynxOC minimizes personal information, separates tenant data, and avoids putting customer operational details into shared alerts or product analytics.
PUBLIC BETA DISCLOSURE · UPDATED SEPTEMBER 12, 202601 / INFORMATION USED
We process what is needed to operate the beta.
Account identity and organization membership come from Clerk. Organizations may provide client identifiers, locations, service dependencies, watchlists, and notification configuration. SphynxOC also records security and authorization audit events, delivery outcomes, and operational health telemetry.
Public upstream incident and advisory data is collected from identified provider and government sources and is kept separate from tenant-supplied inventory.
02 / PURPOSE
Tenant information supports exposure analysis and delivery—not advertising.
Organization data is used to match upstream conditions to relevant dependencies, produce exposure views, route requested notifications, secure the service, and provide support.
SphynxOC does not sell tenant information. Privacy-safe product measurements may count actions such as onboarding completion or feature use, but should not contain client names, dependency notes, webhook contents, or other sensitive inventory.
03 / VISIBILITY
People see data according to their organization and role.
Members can access only the active organizations to which they belong. Owners and administrators manage their organization according to role; platform administration is limited to operating and securing SphynxOC and does not create unrestricted tenant-inventory access.
04 / SERVICE PROVIDERS
A small set of providers supports delivery.
Cloudflare supplies DNS, edge runtime, security, and structured storage. Clerk supplies identity and organization authentication. Slack or another destination receives only notifications an authorized organization or platform administrator configures. Official source operators provide the public incident data SphynxOC monitors.
05 / CHOICES
Beta participants can request access, correction, export, or deletion.
Requests are handled through the participant’s onboarding contact or authenticated Support control and require identity and organization-ownership verification where appropriate. Some security and recovery records may remain for a limited operational or backup period before expiration.