01 Overview & Purpose
XKRISK (“we,” “our,” or “us”) provides high-performance credit risk data pipelines, credit default swap (CDS) analytics, financial filings, and AI-ready Model Context Protocol (MCP) integrations to institutional professionals.
This Privacy Policy explains how we collect, use, disclose, and safeguard personal and organizational information when you visit our website (xkrisk.com), submit inquiries, or utilize our institutional data delivery platforms. We are committed to maintaining the confidentiality, integrity, and security of all client and visitor interactions.
02 Information We Collect
We collect information to provide and improve our services, facilitate enterprise communication, and safeguard our technical infrastructure. The information we collect falls into three general categories:
A. Information You Provide Directly
- Contact & Inquiry Details: When you submit a contact form, request sample data, or email us directly, we collect your name, institutional email address, organization name, phone number, and any notes regarding your data requirements.
- Client Account Information: For authorized institutional clients, we maintain administrative contact details, billing identifiers, and authorized point-of-contact information.
B. Authentication & Platform Credentials
- Access Credentials: Usernames, API access keys, and SFTP public keys issued to authorized institutional personnel to access licensed data feeds and client portals.
C. Automatically Collected Technical Data
- System Logs & Telemetry: Standard web server logs including your IP address, browser type, device specifications, operating system, referring URL, and timestamps of page requests. This information is processed exclusively for performance monitoring, network security, and infrastructure reliability.
03 How We Use Information
We use the information we collect solely for standard business, technical, and operational purposes:
- Delivering Services: Provisioning and delivering requested credit data feeds, API endpoints, and institutional analytics.
- Responding to Inquiries: Answering technical questions, scheduling demonstrations, and delivering evaluation data samples.
- Security & Authentication: Verifying client credentials, protecting against unauthorized data scraping, and maintaining SOC2-aligned access controls.
- Service Optimization: Analyzing platform load, identifying latency bottlenecks, and improving our delivery infrastructure.
- Compliance: Satisfying legal, regulatory, or audit obligations applicable to commercial financial data providers.
04 Data Sharing & Non-Sale Commitment
XKRISK does not sell, rent, monetize, or trade contact information, personal data, or client usage patterns to any third parties or advertisers.
We only share information with third parties in the following limited circumstances:
- Trusted Service Providers: Specialized infrastructure partners who assist us in operating our web services, hosting secure servers, or sending transactional communications, strictly subject to confidentiality and security obligations.
- Legal & Regulatory Mandates: Where required by valid subpoenas, regulatory authorities, court orders, or applicable financial compliance statutes.
- Protection of Rights: When necessary to enforce our service agreements, investigate security breaches, or protect the integrity of XKRISK assets.
05 Security & Institutional Safeguards
We implement industry-standard physical, organizational, and technical safeguards designed to protect your data against unauthorized access, loss, or alteration:
- Data Encryption: All web traffic, REST API communication, and portal logins are encrypted in transit using current TLS 1.3 encryption protocols.
- Access Control: Administrative access is restricted by role-based authorization, hardware multi-factor authentication (MFA), and isolated production networks.
- Secure Credential Storage: Client passwords and API secret hashes are stored using cryptographic hashing standards.
While no electronic transmission over the internet can be guaranteed 100% secure, we continuously monitor and refine our infrastructure to uphold institutional standards.
06 Cookies & Browser Preferences
We maintain a minimal cookie and tracking footprint:
- Essential Preferences: We use your browser's local storage solely to retain interface preferences (such as your chosen Dark or Light color mode).
- Session Management: Temporary session identifiers are used strictly when authorized institutional clients sign in to access client portals.
- No Third-Party Ad Trackers: We do not load third-party behavioral advertising networks or commercial tracking pixels on this website.
07 Your Rights & Inquiries
Depending on your jurisdiction, you may have rights under applicable privacy laws (such as GDPR, CCPA, or related frameworks) to access, correct, update, or request deletion of the personal contact information you have provided to us.
If you have any questions regarding this Privacy Policy, wish to exercise your privacy rights, or wish to update your contact preferences, please contact our privacy and data governance team:
Email: info@xkrisk.com
Subject: Privacy Policy Inquiry