RAMP 90S
ReviewAlignMobilizeProveSustain
RAMP 90S

Privacy Policy

Effective and last updated: September 20, 2026

This Privacy Policy explains how RAMP 90S handles information when authorized users access the RAMP 90S web application, upload or review documents, use RAMP 90S Analysis, use hosted reasoning features, receive application communications, or submit a public inquiry. RAMP 90S is designed for organizational and professional use, not consumer or personal use.

On this page 1. Scope2. Information We Handle3. Local Browser Processing4. Hosted Analysis and AI Processing5. How Information Is Used6. Sharing and Service Providers7. Security8. Retention and Deletion9. Organizational Controls and Requests10. Changes to this Policy11. Contact

1. Scope

This Policy applies to the RAMP 90S web application and the controlled services used to authenticate users and provide RAMP 90S Analysis. Your organization may also have an order form, pilot agreement, subscription agreement, data-processing agreement, or other written agreement that contains additional privacy and security terms. If there is a conflict, the written agreement with your organization controls to the extent of that conflict.

2. Information We Handle

RAMP 90S may handle the following categories of information:

  • Account information. Email address, display name, role, organization or tenant identifier, and authentication information needed to provide authorized access.
  • Review content. Contracts, solicitations, operating reports, spreadsheets, text, images, source locations, extracted tables, evidence records, corrections, findings, decisions, plans, and other material an authorized user chooses to process in RAMP 90S.
  • Analysis information. Canonical RAMP 90S Analysis Records, evidence citations, reasoning requests, adjudication status, confidence, missing-information flags, and approved reasoning overlays.
  • Communication and inquiry information. Recipient email addresses, message subjects and content, delivery status, and the name, email address, subject, and message provided through the public contact form.
  • Technical information. Information needed to operate, secure, diagnose, and protect the service, which may include timestamps, request metadata, server logs, error information, session status, and security events.
Do not upload information you are not authorized to use. Unless your organization has expressly authorized it in writing, do not upload classified information, payment-card data, Social Security numbers, protected health information, export-controlled data, or other regulated or highly sensitive data that RAMP 90S has not been approved to process.

3. Local Browser Processing

The current RAMP 90S web application reads supported documents in the user's browser. Extracted document content and document files may be stored in the browser's IndexedDB, while compact review state is stored in local browser storage so an authorized user can continue a review. This browser-resident information remains on the device unless the user exports it, clears browser storage, removes the review, or uses a hosted feature that expressly sends authorized analysis records to the server.

Because browser storage is device-specific, users are responsible for using RAMP 90S only on devices and browser profiles approved by their organization and for preventing unauthorized access to those devices.

4. Hosted Analysis and AI Processing

RAMP 90S uses a controlled reasoning architecture. When an authorized user runs hosted reasoning, the application sends a bounded package of authorized RAMP 90S Analysis Records and source-bounded evidence to the RAMP 90S server-side reasoning service. The design is intended to avoid sending unrestricted raw document collections to the hosted model when only controlled analysis records are required.

Hosted reasoning may use an external AI service provider configured by RAMP 90S. Where OpenAI is the configured provider, OpenAI states that business/API inputs and outputs are not used to train its models by default unless the customer explicitly opts in, and that API retention depends on endpoint and account data-control settings. RAMP 90S will use the provider settings approved for the deployed environment.

AI-assisted outputs are subject to RAMP 90S's deterministic adjudication and evidence controls, but no automated system is error-free. Authorized users remain responsible for reviewing material decisions and conclusions.

5. How Information Is Used

RAMP 90S uses information to authenticate authorized users; isolate organization or tenant access; read and structure source documents; create evidence, requirements, findings, decisions, plans, and analysis records; provide hosted reasoning when requested; preserve user-directed review state; protect the service from misuse; send authorized application messages and announcements; receive and respond to public inquiries; diagnose errors; maintain security; and comply with legal obligations.

RAMP 90S does not claim ownership of your organization's source documents merely because they are processed by the service.

6. Sharing and Service Providers

Information may be disclosed only as reasonably necessary to operate and secure RAMP 90S, including to hosting, infrastructure, authentication, logging, email delivery, and AI service providers; to authorized personnel or administrators for your organization; to professional advisers under confidentiality obligations; or when required by law, legal process, or to protect rights, safety, and security.

RAMP 90S does not sell organizational review content or uploaded documents to advertisers.

7. Security

RAMP 90S uses administrative and technical controls appropriate to the controlled-access service. In the current web build, user passwords are verified against salted cryptographic password hashes, session cookies are marked HttpOnly, Secure, and SameSite=Strict, and service credentials used for hosted reasoning remain on the server rather than being sent to the browser. Tenant identifiers are checked before hosted reasoning requests are forwarded.

No system can guarantee absolute security. Authorized users must protect credentials, use approved devices, report suspected compromise promptly, and comply with their organization's security requirements.

8. Retention and Deletion

Browser-resident review information remains until removed through the application, browser storage is cleared, or the browser/device is otherwise reset. Authentication sessions are time-limited. Server-side logs, reasoning results, communication and inquiry records, backups, and provider-held information may be retained for operational, support, security, audit, contractual, or legal purposes according to the deployed environment and applicable organizational agreement.

Where a third-party AI provider processes authorized records, that provider's approved account-level data controls and retention settings also apply. RAMP 90S will not state a shorter provider retention period than the deployed configuration actually supports.

9. Organizational Controls and Requests

Access to RAMP 90S is organization-controlled. Requests concerning account information, access, correction, deletion, export, retention, or organization-specific privacy requirements should be directed first to your organization administrator or to the RAMP 90S contact identified in your organization's agreement. RAMP 90S may need to verify authority before acting on a request.

10. Changes to this Policy

RAMP 90S may update this Policy as the service, deployment architecture, legal requirements, or service-provider relationships change. Material changes will be reflected by a revised effective date and, where appropriate, notice through the service or your organization administrator.

11. Contact

For privacy questions or requests, contact your organization administrator, use the RAMP 90S Contact form, or contact the RAMP 90S representative identified in your organization's order form, pilot agreement, subscription agreement, or other written access agreement.

This policy is designed to describe the current controlled-access architecture. Organization-specific legal, retention, regulatory, and data-processing requirements should be confirmed in the applicable written agreement.

Back to Sign InTerms of Use