Tool inputs stay in the browser
Readiness, learning-plan, and career-mapper selections, incident notes, procurement selections, ROI assumptions, integration selections, career choices, and prompt-workbench text are processed by JavaScript in your browser. This MVP does not send those values to a server, AI model, analytics provider, vendor, or advertiser.
Avoid entering personal data, credentials, live vulnerabilities, camera or device locations, floor plans, evidence, or confidential incident details. Browser-local processing reduces transmission but does not make a shared or unmanaged device appropriate for sensitive information.
Saved reading progress stays on your device
When you open a guide, learning path, or free tool, the page records the public
route name and a timestamp in browser local storage under
psai.progress, together with any guide you mark complete and your
last use-case filter selection. This powers the “Continue where you left off”
panel on the homepage and the progress markers on learning paths. No account is
created, and the data is never transmitted to physicalsecurity.AI or any third party.
Older versions of the site stored briefing preferences under
physicalsecurity.ai.briefing-preferences; that feature is retired.
Clearing site data in your browser removes both keys.
Third-party requests and outbound links
Each page requests the Inter, Newsreader, and IBM Plex Mono font files from Google Fonts. Google can receive ordinary web-request information such as IP address, browser information, and referring page. Links to ASIS, SIA, NIST, BLS, Google Trends, ONVIF, and other sources leave this site and are governed by those sites' privacy practices.
Membership waitlist
If you submit the waitlist form on the access page, we collect the email address, optional name, and role you provide so we can notify you when membership enrollment opens. That information is not used for advertising, vendor sharing, or analytics events. It is sent only to the waitlist destination configured for this site: a database we operate, plus an optional private automation webhook that notifies the site operator if one is configured. Duplicate submissions are matched by normalized email address.
We also store the time you consented, a coarse network prefix (never the full IP address), and a hashed browser signature to detect abuse. You receive one confirmation email with a one-click unsubscribe link. Unsubscribing removes your consent immediately and places a hashed copy of your address on a suppression list so we do not email you again by mistake. Network prefixes are removed from activity records after 180 days. You can ask us to delete your waitlist record at any time.
Email communications
Waitlist announcements, the optional practitioner newsletter, and member notices are sent through Resend, our email delivery processor, which receives your address and the message content. Each message states which consent it relies on: enrollment announcement (everyone on the waitlist), newsletter (only if you ticked the newsletter box), or member notice (account holders).
Every marketing email carries a one-click unsubscribe header and a footer link that works without signing in. Delivery failures and spam complaints reported by the mail provider suppress further sends to that address. We do not embed tracking pixels; only delivery outcomes are recorded.
Member accounts and billing
When membership opens, sign-in uses a single-use link emailed to you rather than a password. A signed-in
session is kept in a secure cookie named __Host-psai_member that is not readable by scripts
and is not shared with third parties. We record the time of each sign-in and a coarse network prefix so you
can review account activity.
Payments are processed by Stripe. Card details are entered on Stripe-hosted pages and never reach our servers. We store the Stripe customer and subscription identifiers, plan, billing status, and renewal date needed to grant access. Deleting an account removes personal details and keeps only the anonymized billing history required for accounting.
Analytics, advertising, and affiliates
This site now uses Google Analytics 4 for aggregate traffic and navigation trend analysis. A pageview is captured for each page load and linked to non-sensitive metadata such as path, referrer, and device class. Raw utility inputs, prompt text, local tool values, and incident notes are not sent as analytics events. Advertising and affiliate tracking are still not active.
Read the commercial-separation policyRFP builder inputs
The RFP Requirements Builder runs entirely in your browser. Project names, site counts, scope selections, and generated schedules are not transmitted to physicalsecurity.AI, stored on a server, or sent to an AI model. Avoid entering sensitive facility details or personal information, and review downloaded output under your organization's records rules.
Updates
Last updated September 1, 2026. This page describes the site's current data-handling configuration.