Security, Privacy, and AI Principles
IB-DOC-003Icebreaker Security, Privacy & AI PrinciplesDocument ID: IB-DOC-003Version: 1.0Effective Date: July 14, 20261. Purpose
Section titled “1. Purpose”Icebreaker is committed to providing a secure platform for evaluating enterprise data while respecting customer ownership, privacy, and security requirements.
This document describes Icebreaker’s current operational security practices, privacy principles, and approach to artificial intelligence during customer evaluations.
This document is intended to provide transparency into how Icebreaker is designed and operated. It supplements the Icebreaker Evaluation License Agreement (IB-DOC-001) and the Icebreaker Privacy Policy (IB-DOC-002) but does not create additional contractual obligations.
2. Our Principles
Section titled “2. Our Principles”The Icebreaker Platform is designed around several core principles.
Customer Ownership Customers retain ownership of their data at all times.
Icebreaker does not acquire ownership rights to Customer Data through operation of the Platform.
Customer Control
Customers determine:
- what data is processed;
- where their data resides;
- which AI services are used;
- who may access the Platform.
Secure by Design
Icebreaker seeks to minimize unnecessary movement of data while providing customers with the ability to evaluate the Platform in environments appropriate to their security requirements.
Transparency
We believe customers should understand how their information is handled.
This document is intended to provide that transparency.
3. Shared Responsibility
Section titled “3. Shared Responsibility”Security is a shared responsibility.
Icebreaker is responsible for securing the Platform and the services we provide.
Customers remain responsible for securing:
- their cloud environments;
- identity providers;
- user accounts;
- permissions;
- network configurations;
- data governance;
- regulatory compliance;
- backup and recovery.
Customers should evaluate the Platform within the context of their own security policies and compliance requirements.
4. Customer Data Ownership
Section titled “4. Customer Data Ownership”Customer Data belongs to Customer.
Customer Data may include:
- structured datasets;
- metadata;
- prompts;
- queries;
- reports;
- dashboards;
- configuration information;
- analytical results;
- documents;
- business information.
Icebreaker does not claim ownership of Customer Data.
Customer remains responsible for determining what information is appropriate to process during an evaluation.
5. Data Residency
Section titled “5. Data Residency”Icebreaker is designed to support deployment models that minimize unnecessary movement of Customer Data.
Depending upon the evaluation architecture, Customer Data may remain within Customer-controlled cloud environments.
Where Customer chooses a hosted evaluation environment provided by Icebreaker, Customer Data is processed only as necessary to provide the requested services.
Icebreaker encourages customers with specific regulatory or data residency requirements to discuss deployment options before beginning an evaluation.
6. Identity and Authentication
Section titled “6. Identity and Authentication”Access to the Platform is controlled through authenticated user accounts.
During the evaluation program, authentication may be provided through trusted third-party identity providers.
Current authentication options may include:
- Google authentication
Additional enterprise authentication methods may be introduced over time, including support for Microsoft Entra ID, SAML, OpenID Connect (OIDC), and other enterprise identity providers.
Icebreaker does not store passwords managed by third-party identity providers.
7. Access Controls
Section titled “7. Access Controls”Icebreaker seeks to limit access to Customer information based upon the principle of least privilege.
Administrative access is restricted to authorized personnel with legitimate operational responsibilities.
Customers are responsible for managing access within their own organizations and ensuring that only authorized users participate in the evaluation.
8. Encryption
Section titled “8. Encryption”Icebreaker is designed to protect information during transmission using industry-standard encryption technologies.
Where supported by the deployment architecture, Customer information may also be protected through encryption while stored.
Customers remain responsible for the encryption and protection of information maintained within their own cloud environments.
9. Operational Logging
Section titled “9. Operational Logging”To maintain the reliability and security of the Platform, Icebreaker may maintain operational logs relating to:
- authentication events;
- system performance;
- software errors;
- infrastructure health;
- platform diagnostics;
- administrative activities.
Operational logs are used to:
- investigate technical issues;
- improve reliability;
- maintain platform security;
- support customer evaluations.
Operational logging is not intended to monitor Customer business activities or analyze Customer business data beyond what is necessary to provide the Platform.
10. Artificial Intelligence Principles
Section titled “10. Artificial Intelligence Principles”Icebreaker is designed to help customers integrate artificial intelligence with enterprise data while maintaining appropriate control over Customer information.
As a matter of principle:
- Customer selects the AI services used during the evaluation.
- Customer retains ownership of Customer Data.
- Icebreaker does not use Customer Data to train foundation models or generative AI systems.
- Icebreaker does not sell Customer Data.
- Icebreaker does not intentionally disclose Customer Data except as necessary to provide requested services.
Where AI integrations are used, Icebreaker seeks to minimize the amount of information transmitted to external AI providers by limiting transmitted context to information reasonably necessary to complete Customer requests.
Customers remain responsible for evaluating the privacy, security, and contractual commitments of any third-party AI providers they choose to use.
11. Security Monitoring
Section titled “11. Security Monitoring”Icebreaker continuously monitors the operational health of the Platform using technical telemetry and diagnostic information. Monitoring activities may include:
- infrastructure monitoring;
- platform availability;
- error detection;
- performance analysis;
- operational troubleshooting.
Monitoring is intended to maintain Platform reliability and support Customer evaluations.
12. Incident Response
Section titled “12. Incident Response”Icebreaker maintains procedures for identifying, investigating, and responding to suspected security incidents affecting the Platform.
If Icebreaker determines that a security incident has materially affected Customer information under Icebreaker’s control, Icebreaker will notify affected customers within a commercially reasonable period, subject to applicable legal requirements.
Icebreaker may also take reasonable actions necessary to contain or mitigate the effects of a security incident, including temporarily restricting access to portions of the Platform where appropriate.
13. Continuous Improvement
Section titled “13. Continuous Improvement”Icebreaker continuously evaluates opportunities to improve the security, reliability, and functionality of the Platform.
As the Platform evolves, Icebreaker may introduce additional security capabilities, authentication options, deployment models, monitoring capabilities, and operational controls.
This document reflects Icebreaker’s practices at the time of publication and may be updated as those practices evolve.
14. Contact Information
Section titled “14. Contact Information”Questions regarding Icebreaker’s security program or operational practices may be directed to:
Icebreaker Data LLC
Security Inquiries
security@icebreakerdata.com
Version HistoryVersion 1.0Effective Date: July 14, 2026Initial publication.