ShieldVUE Logo IconShieldVUE

Legal Documentation

ShieldVUE Privacy Notice

By ApMoSys Product Private Limited  •  Last updated: June 30, 2026


Introduction

This Privacy Notice explains how ApMoSys Product Private Limited ("APPPL", "ApMoSys", "Company", "we", "our", or "us") collects, processes, stores, protects, and manages information through ShieldVUE®, an enterprise Software Supply Chain Security and Governance Platform.

ShieldVUE® enables organizations to discover software components, generate and manage Software Bills of Materials (SBOMs) and Cryptography Bills of Materials (CBOMs), identify software vulnerabilities, monitor cryptographic assets, enforce governance policies, support regulatory compliance, and provide enterprise-wide software supply chain visibility.

ShieldVUE® is a proprietary software platform owned by ApMoSys Product Private Limited and supported by ApMoSys Technologies Private Limited.

Information We Collect

To provide, secure, and continuously improve ShieldVUE services, we may collect the following categories of information.

Account Information

  • Full Name
  • Business Email Address
  • Contact Number
  • Organization Name
  • Designation
  • Department
  • User Role and Access Permissions

Platform Usage Information

ShieldVUE collects operational information necessary for platform administration, governance, and security monitoring, including:

  • User login activities
  • Authentication events
  • Dashboard interactions
  • Project activities
  • Repository connections
  • Policy configuration history
  • Audit logs
  • Workflow execution history
  • Report generation history
  • Administrative activities

Software Metadata

During software discovery and analysis, ShieldVUE may process metadata related to customer software assets, including:

  • Software component names
  • Package versions
  • Dependency relationships
  • Build artifacts
  • Container image metadata
  • Binary metadata
  • Repository references
  • Software inventory information
  • Application identifiers
  • Dependency trees

ShieldVUE analyzes software metadata solely for software supply chain visibility and governance purposes.

Vulnerability & Security Information

To provide vulnerability intelligence, ShieldVUE may process:

  • Known vulnerability references (CVEs)
  • Security advisories
  • Component risk scores
  • Dependency risk information
  • Vulnerability severity classifications
  • Security policy violations
  • Software exposure assessments

Cryptographic Asset Information (CBOM)

Where CBOM capabilities are enabled, ShieldVUE may identify and catalog:

  • Encryption algorithms
  • Cryptographic libraries
  • Certificates
  • Hashing algorithms
  • Key management metadata
  • Initialization vectors
  • Cryptographic implementations
  • Cryptographic policy information

ShieldVUE does not access or store customer encryption keys or confidential cryptographic secrets unless explicitly configured as part of an approved deployment.

Technical Information

For platform security and operational purposes, we may collect:

  • IP addresses
  • Browser information
  • Device identifiers
  • Operating system details
  • Session identifiers
  • Access timestamps
  • Network diagnostic information
  • API request metadata

Customer Content

Customers may upload or connect software-related information including:

  • SBOM documents
  • CBOM records
  • Security policies
  • Compliance reports
  • Software inventory records
  • Repository configurations
  • Build pipeline metadata
  • Vulnerability reports
  • Governance documentation
  • Supporting audit evidence

Purpose of Processing

Information collected through ShieldVUE may be processed for the following legitimate business purposes:

  • Deliver and operate the ShieldVUE platform
  • Authenticate authorized users
  • Discover software components
  • Generate and maintain SBOMs and CBOMs
  • Perform software composition analysis
  • Identify known software vulnerabilities
  • Correlate dependencies with threat intelligence
  • Monitor cryptographic assets
  • Enforce governance and security policies
  • Generate compliance reports
  • Maintain audit trails
  • Provide customer support
  • Improve platform functionality
  • Monitor service availability and performance
  • Comply with applicable legal, regulatory, and contractual obligations

Data Ownership

Customers retain full ownership of all customer-provided information processed within ShieldVUE, including but not limited to:

  • Source code references
  • Software inventories
  • SBOMs
  • CBOMs
  • Security policies
  • Vulnerability reports
  • Compliance documentation
  • Repository metadata
  • Configuration information
  • Uploaded files and business records

ApMoSys acquires no ownership rights over customer data except as necessary to provide contracted services and fulfill platform operations.

AI and Analytics

Where AI-powered capabilities are available within ShieldVUE, information such as software metadata, vulnerability insights, governance recommendations, compliance observations, prompts, inputs, generated outputs, and associated metadata may be processed solely to deliver requested platform functionality and improve customer experience.

Customer information is not used to train publicly available Artificial Intelligence models without explicit written customer authorization.

Data Security

ShieldVUE is designed with security-by-design principles and employs industry-standard security controls to protect customer information. Security measures include:

  • Role-Based Access Control (RBAC)
  • Multi-level authentication and authorization
  • Encryption of data in transit
  • Encryption of stored platform data where applicable
  • Comprehensive audit logging
  • Secure API communication
  • Continuous platform monitoring
  • Vulnerability management processes
  • Security event logging
  • Controlled administrative access

Data Retention

Information processed by ShieldVUE is retained only for legitimate:

  • Business purposes
  • Customer contractual obligations
  • Security investigations
  • Operational requirements
  • Regulatory compliance
  • Audit requirements
  • Legal obligations

Retention periods may vary based on customer agreements, applicable laws, or organizational policies.

Disclosure of Information

ApMoSys does not sell, rent, or commercially distribute customer information. Information may be disclosed only under the following circumstances:

  • Where required by applicable law
  • Regulatory investigations
  • Court orders or legal process
  • Contractual obligations
  • Customer-authorized service delivery
  • Security incident investigations
  • Approved service providers supporting ShieldVUE operations under appropriate confidentiality obligations

International Data Processing

Where customer deployments involve multiple geographic regions or cloud environments, information may be processed in accordance with applicable contractual commitments and relevant data protection regulations.

Appropriate safeguards are implemented to protect customer information during cross-border processing where applicable.

Customer Responsibilities

Customers are responsible for:

  • Maintaining appropriate user access controls
  • Protecting account credentials
  • Configuring repositories securely
  • Reviewing governance policies
  • Ensuring uploaded information complies with applicable laws and internal policies

Changes to This Privacy Notice

ApMoSys may update this Privacy Notice periodically to reflect changes in legal requirements, platform capabilities, or operational practices.

The updated version will be published on this page together with the revised "Last Updated" date.

Contact Us

For questions regarding this Privacy Notice or ShieldVUE's privacy and data protection practices, please contact:

Email: sales@apmosys.com

ShieldVUE® is a proprietary Software Supply Chain Security platform owned by ApMoSys Product Private Limited and supported by ApMoSys Technologies Private Limited.

Copyright © 2026 ApMoSys Product Private Limited. All rights reserved.