Design-Partner Programme — founding teams get founder pricing & help shape the roadmap. Talk to us →
Get Started

What Each Edition Sends, and to Whom

Read it here. Then check it in the extension’s code.

In TorchTiger Engineer, the Community edition sends nothing to TorchTiger: your browser talks only to your ServiceNow instance and your own Anthropic account. The Team edition also sends TorchTiger sign-ins, seat checks, a 15-minute check-in and a record of each AI change.

At a Glance: Community and Team

Last updated 2 October 2026

What each TorchTiger Engineer edition sends, where it goes, and who sees it.
Topic Community Team
Sent to TorchTigerNothing: no TorchTiger backend, no telemetry.Sign-ins, seat checks, a 15-minute check-in and a record of each AI change. What each carries.
Your chatsStraight to Anthropic, under your key.To your AI provider, not to TorchTiger, once a member’s seat is verified.
Change recordsLogged on your device only.Also sent to TorchTiger, with the record’s name as written, not redacted (for an incident, its short description or number).
Who sees change recordsNobody at TorchTiger.Owners, admins, billing admins and read-only auditors, with the member’s email, in the Engineer web app.
Can you turn them off?Nothing is sent.No. There is no setting to turn change records off.
How long TorchTiger keeps themNothing is kept.Append-only, and not deleted automatically today.
If TorchTiger is unreachableNo effect.A browser that cannot reach TorchTiger for 72 hours falls back to Community rules until it can.
In both editions
What each chat carries

Your messages, the ServiceNow results it reads and the record you have open (up to 40 fields).

Personal data in chats

Replaced before sending, when detected. Not detected: UK National Insurance numbers, postcodes and UK-format phone numbers. Not redacted: attached images and PDFs.

Your AI key

Stays on the device, encrypted under your passphrase, which is never saved.

The local change log

Not encrypted. It keeps undo copies of changed records and survives Reset.

Third-party analytics or fingerprinting

None.

Production instances

Locked out: no chat, no AI reads, no writes, including on any instance it cannot confirm is non-production.

For security reviewers: what each Team event carries, what is never sent, and why each permission is needed.

Read the Data Handling Details

Browser Permissions

Asked For at Install

  • storage
  • activeTab
  • scripting
  • identity
  • alarms
  • storage.managed_schema
  • api.anthropic.com
  • *.service-now.com instance pages

Never Asked For

  • cookies or broad tabs
  • <all-urls> at install. Other hosts are asked for on your click, one address at a time; the manifest lists them as optional, including https://*/*.
  • Remotely hosted code
  • chrome.storage.sync

Why each permission is needed

For Your Security Review

Documents and commitments for a security review.
DPA

Available on request. Community is serverless and accountless, so TorchTiger is not a data processor for it.

SOC 2

Not yet certified. We never present it as a current attestation.

Source code

Our own code ships unminified, so you can read the shipped files. Full source under NDA, acknowledged within 3 business days. Not open source: all rights are reserved.

Vulnerabilities

Report privately to security@torchtiger.com. Reports are acknowledged within 3 business days, with coordinated disclosure and good-faith safe harbour.

Common Questions

Does Claude see my ServiceNow data?

Yes. Your messages, the ServiceNow results it reads and the record you have open (up to 40 fields) go to your AI provider. Detected personal data is replaced in your browser first. On Team, once a member’s seat is verified, chats go to your AI provider, not to TorchTiger.

Can it touch production?

No. On production the AI is locked out: no chat, no AI reads, no writes. It also stays off on any instance it cannot confirm is non-production; the extension only reads the instance’s settings to tell production apart. Elsewhere, nothing is written until you approve.

Do you proxy or mark up our Claude usage?

No. You bring your own Claude and pay your provider directly; Community is free and Team is a flat per-seat fee. There is no token markup, and the extension calls your provider directly, with no TorchTiger-hosted model in its path. We never proxy, store or resell your prompts.

Bring Your Security Team

Got a questionnaire, review, or data-flow question? We'll walk your security team through exactly how it works.

Request a Security Review
  • Community collects no data
  • Readable extension code
  • Source access under NDA
  • DPA on request