Data Handling Details
The full detail behind the Security page.
For security reviewers: what Team sends to TorchTiger and when, what is never sent, what stays on your device, and why each permission is needed. In TorchTiger Engineer, the Community edition sends TorchTiger nothing: no TorchTiger backend, no telemetry.
How Data Flows
Last updated 2 October 2026
Your Browser
TorchTiger Engineer runs here, only on your ServiceNow instance pages. It keeps your key encrypted and replaces detected personal data in chats before they are sent.
-
Both editions
Your ServiceNow Instance
It reads with your own session and permissions. Nothing is written until you approve.
Production is locked out: no chat, no AI reads, no writes. The same applies to any instance it cannot confirm is non-production; the extension only reads the instance’s settings to tell production apart.
-
Both editions
Your AI Provider
Community: Anthropic, under your own key. Team: once a member’s seat is verified, the Anthropic API, Amazon Bedrock or your gateway, per your team’s AI profile. With an Anthropic key, Claude may also run web searches, which Anthropic carries out.
-
Team only
TorchTiger’s Servers
api.torchtiger.com receives sign-ins, seat checks, check-ins and change records. Your team sees the results in two web apps at app.torchtiger.com. The Engineer web app shows the change log and change dashboard; the Hub manages members, seats and billing.
What Team Sends to TorchTiger
Community sends TorchTiger nothing. On Team, the extension sends these to TorchTiger’s servers at api.torchtiger.com, which also hold your team’s members, roles, policies and the instances you register.
| Sent | What it carries |
|---|---|
| Sign-inWhen a member signs in | Your work email and password, and an emailed one-time code (on by default). TorchTiger’s servers record each sign-in’s IP address and browser. |
| Seat checkWhen you sign in, unlock, open the panel or return to a ServiceNow tab | An install ID with your session. Opening the toolbar popup also fetches the team policy. |
| Check-inEvery 15 minutes | The same install ID. |
| Change recordAbout 3 seconds after each AI write | The instance address and environment, table, record ID, action, update-set name and ID, and time. The update-set name is a short title the AI writes for the plan. It also carries the record’s name as written, such as a business rule’s name, up to 200 characters and not redacted. If the AI changes a data record such as an incident, its short description or number is sent instead. It also names the record’s type and the chat turn that made the change. If a change is undone, a short revert record follows. TorchTiger’s servers add who made it. |
- Switching it off
- There is no setting to turn change records off.
- Who sees it
- In the Engineer web app, owners, admins, billing admins and read-only auditors see every member’s change records, including the member’s email.
- How long it’s kept
- Change records are append-only and are not deleted automatically today.
- Offline
- A browser that cannot reach TorchTiger for 72 hours falls back to Community rules until it can.
What Stays on Your Device
Your Key, Sealed
Your key is stored encrypted under your passphrase (PBKDF2 and AES-GCM), and the passphrase is never saved. Unlocked, the key sits in memory-only session storage and never reaches the page.
Personal Data, Replaced First
Personal data it detects in your messages and ServiceNow results is swapped for placeholders in your browser before sending. The map back stays on your device.
A Local Change Log
Every AI change is logged in your browser, with the undo copies needed to revert it. It stays on this device, with no sync.
The log is not encrypted, and it survives Reset.
What Redaction Catches
- Detected
- Emails, card numbers, IP addresses, North American phone numbers and many names.
- Not detected
- UK National Insurance numbers, postcodes and UK-format phone numbers.
- Not redacted
- Attached images and PDFs, and Team change records.
Browser Permissions
Asked For at Install
storageactiveTabscriptingidentityalarmsstorage.managed_schemaapi.anthropic.com*.service-now.cominstance pages
Never Asked For
- No
cookiesor broadtabs. It cannot read your logins or see your other tabs. - No
<all-urls>at install. It holds only api.anthropic.com and ServiceNow instance pages. TorchTiger’s servers and your AI provider are asked for on your click, one address at a time. The manifest lists them as optional, includinghttps://*/*. The grant for TorchTiger’s servers stays after sign-out. - No remotely hosted code. Every line ships in the reviewed package, under a strict Manifest V3 content security policy.
- No
chrome.storage.sync. Nothing syncs through your browser account. - No third-party analytics or fingerprinting.
Why Each One Is Needed
| Permission | Why |
|---|---|
storage | Your encrypted key and chats, settings, the instances you’ve opened and the local change log, on this device only, with no sync. On Team, also your install ID and seat token. |
activeTab | Label the ServiceNow instance you’re on, and scope write mode to it. |
scripting | Inject the “What’s redacted” editor, only on your click, on the active tab. |
identity | On Team, get a short-lived token from your identity provider for a keyless Amazon Bedrock connection. It also opens the sign-in page for an organisation set up with single sign-on. |
alarms | Re-lock your key when the unlock window ends; on Team, schedule the 15-minute check-in. |
storage.managed_schema | Let your IT pre-set your organisation’s name and Hub link by browser policy. Read-only, and read on every install. |
api.anthropic.com | Direct calls to your Anthropic account, under your key (Community). |
| Content scripts | On |
Check It Yourself
Readable Code
Our own code ships unminified, with no build step, so your team can read the shipped files. Two third-party PII (personal data) libraries are minified.
Checked on Every Build
Our CI fails the build if code adds third-party analytics or fingerprinting, or hard-codes a host outside a fixed list.
Readable, Not Open Source
Being readable does not make it open source: all rights are reserved. The full source is available to security teams under NDA.
Procurement & Compliance
DPA on Request
A DPA is available on request. Community is serverless and accountless, so TorchTiger is not a data processor for it. On Team, TorchTiger processes your members’ account and billing details, sign-ins, install IDs and change records, including record names as written.
SOC 2 — Not Yet Certified
TorchTiger is not SOC 2 certified yet. We say so plainly and never present it as a current attestation.
Source Access Under NDA
Security teams can read the source under NDA: a named owner (the TorchTiger Engineer maintainer), acknowledged within 3 business days.
Responsible Disclosure
Report vulnerabilities privately to security@torchtiger.com — acknowledged within 3 business days, coordinated disclosure, and good-faith safe harbour.
Bring Your Security Team
Got a questionnaire, review, or data-flow question? We'll walk your security team through exactly how it works.
Request a Security Review- Community collects no data
- Readable extension code
- Source access under NDA
- DPA on request