No items found.
Platform
Use Cases
Company
Partners
Resources
Request Demo
Optimize
Coming Soon

Universal Security Layer for Agentic AI

Offering a single control and observability plane across your agentic ecosystem.

View Platform
Discover

Map every AI agent instantly

Observe

Real-time agent behaviour monitoring

Enforce

Run-time guardrails at tool execution

Optimize

AI-driven policy refinement

Enterprise-ready Agentic Security

Technical and industry insights into AI security challenges.

Discovery of Agents and Tools

Effective agentic AI security and governance starts with knowing what exists.

Visibility and Baseline Control over AI

In-tenant and on-premise observability and enforcement.

Securing the Synthetic Workforce

Full Guardrails for Agent-driven environments.

Building Trust in Agentic AI

Founded on the principles of innovation and excellence to provide Agentic AI security.

Contact Us

Get in touch with us

Securing Agentic AI in partnership

We partner with industry leaders in agentic AI security to deliver enterprise grade value to our customers.

GTM Partners

Bring Agentic AI Security to Your Customers

Integration Partners

Connect Outerlimit to the Tools You Already Use

Marketplace Partners

Available on AWS and Microsoft Azure Marketplaces

Become a Partner

Sign up to our Global Partner Program today

Insights and Research into Agentic AI

Research, guides, and expert perspectives to stay ahead of the agentic AI threat landscape.

Blog

Insights on agentic AI security

Solutions & Whitepapers

Deep-dive solution briefs and technical research papers

Security & Compliance

Security & Compliance Information for Outerlimit

Glossary

Agentic AI security terminology explained

PRIVACY NOTICE (UK)

AT A GLANCE – PRIVACY HIGHLIGHTS

A short summary of how we handle your data. The full notice below is what governs – please read it for the detail.

What we collect: contact details you give us and technical data from your device.

Why: to reply to you, send communications you ask for, run and secure our site, and meet legal duties.

Your control: we do not sell your data; non-essential cookies need your consent; you can change choices anytime.

Your rights: access, correction and deletion – contact our Privacy team (section 15).

1. Who We Are

This notice is published by Outerlimit. Depending on where you are and how you interact with us, the controller of your personal data is:

  • Outerlimit Group Limited - a company registered in England & Wales (company number 15915710), registered office 9th Floor, 107 Cheapside, London, EC2V 6DN. Controller for UK and EEA visitors.
  • Outerlimit Inc. - incorporated in Delaware, with offices at 135 Madison Ave Suite 06-118, New York, NY 10016, United States. The business responsible for the personal information of US visitors.

The two entities share limited data for management, security and legal-compliance purposes (see section 8). Together we are “Outerlimit”, “we”, “us” or “our”. Outerlimit provides the Outerlimit Solution, which offers visibility, security and risk management for AI agents deployed across customer organisations.

2. About This Notice

This notice explains what personal data we collect when you visit our website or otherwise interact with us as a member of the public, and what we do with it.

It applies to the personal data we collect when you:

  • visit our website at outerlimit.com and any of its subdomains;
  • complete a form, request a demo, or contact us by email, phone or chat;
  • sign up to receive updates, content or event invitations from us;
  • register for, attend or take part in our webinars and events;
  • interact with our branded social-media pages; or
  • apply for a role or express interest in working with us.

It does not cover:

  • personal data we process as a processor on behalf of our customers under our customer agreements and Data Processing Addendum;
  • the personal data of our own personnel, which is covered by the Employee Privacy & Workplace Monitoring Notice.

We process personal data in accordance with the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and PECR in the UK; the EU GDPR where it applies; and applicable US federal and state privacy laws (including the CCPA/CPRA and equivalents in Colorado, Connecticut, Virginia, Texas and other states, and the NY SHIELD Act and Delaware DPDPA).

3. What Personal Data We Collect

We collect only what we need for the purposes set out below. The categories include:

  • Contact and enquiry data - name, business email, telephone number, company, job title and the content of messages you send us through forms, email or chat.
  • Marketing data - your contact details and preferences where you sign up for updates, events or content, and your engagement with our communications.
  • Recruitment data - where you apply for a role or express interest in working with us: CV, work history, qualifications and the details you provide.
  • Technical and usage data - IP address, device and browser type, approximate location, pages viewed and referring source, collected automatically through cookies and similar technologies (see section 6).

We do not seek to collect special category data (such as health, racial or ethnic origin, or biometric data) through our website, and ask that you do not send it to us unsolicited.

We may also create aggregated or de-identified data (for example, website statistics) that does not identify you. We may use and share this data freely, and we will not attempt to re-identify it.

4. Where We Get It From

  • Directly from you - when you complete a form, email or call us, apply for a role, or sign up for communications.
  • Automatically - from your device and browser via cookies and analytics when you use our website.
  • From third parties - recruiters, business-contact data providers, and publicly available professional sources such as LinkedIn, where lawful.

5. Why We Process It and Our Lawful Basis

Under the UK/EU GDPR we rely on a lawful basis under Article 6. In the US we process consistently with the legal bases shown.

Purpose UK/EU lawful basis US legal basis
Responding to your enquiries and requests, including demo requests Art. 6(1)(b), steps prior to contract; Art. 6(1)(f), legitimate interests Legitimate business interest
Sending marketing communications you have asked for Art. 6(1)(a), consent; Art. 6(1)(f) for existing business contacts (soft opt-in, PECR) Consent / CAN-SPAM opt-out
Operating, securing and improving our website and analytics Art. 6(1)(f), legitimate interests; consent for non-essential cookies under PECR Legitimate business interest; consent where required
Considering recruitment applications Art. 6(1)(b) / Art. 6(1)(f) Legitimate business interest
Meeting legal, regulatory and security obligations and defending legal claims Art. 6(1)(c), legal obligation; Art. 6(1)(f), legitimate interests Legal obligation; legitimate interest

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights. Where we rely on consent, you can withdraw it at any time without affecting prior processing.

6. Cookies, Email Tracking and Similar Technologies

We use cookies, pixels, web beacons and similar technologies on our website and in some of our communications. These fall into the following categories:

  • Strictly necessary - required for the website to function including remembering your cookie choices. These are always on and do not need your consent.
  • Performance - help us understand how the site is used so we can improve it by using Google Analytics. Set only with your consent.
  • Targeting - used by us and our advertising partners to build a profile of your interests and show you relevant content on other websites. You can withdraw consent at any time through our cookie settings or directly with the relevant provider, and US visitors can also use our "Do Not Sell or Share My Personal Information" control (see section 11).
  • Functionality - allow the website to remember choices you make, such as your region, to provide a more personalised experience. Set only with your consent.

Email tracking. Our marketing emails may contain pixels that tell us whether the email was opened and which links were clicked, so we can measure and improve our communications. You can prevent this by disabling images in your email client or by unsubscribing.

You can accept, reject or change your cookie choices at any time through our cookie settings, and you can also control cookies through your browser settings. The table below provides details of the cookies currently used on our website, including their provider, purpose and duration.

7. Who We Share Your Data With

We share personal data only with those who need it. All processors are bound by written contracts requiring them to protect your data and to process it only on our instructions. We do not sell your personal data for money. We do allow our advertising partners to set cookies that track your activity across websites so we can show you relevant ads. Under some US state privacy laws (such as the CCPA/CPRA) this may count as "selling" or "sharing" personal information. You can opt out at any time through our cookie settings, and US visitors can also use our "Do Not Sell or Share My Personal Information" control described in section 11.

Recipient Why
Service providers acting as our processors Website hosting, CRM, email and marketing platforms, analytics, IT and cloud providers, including Microsoft 365 / Azure, and recruitment platforms.
Professional advisers Lawyers, accountants, auditors and insurers, where confidentiality applies.
Regulators and law-enforcement bodies The ICO, courts and any other body where disclosure is required by law or court order.
A buyer or successor entity In the event of a merger, acquisition, financing or restructuring, subject to confidentiality.

A current list of the sub-processors used in connection with our products is maintained in our Sub-Processor List and made available to affected customers.

8. International Transfers

We operate in the UK and US and use cloud services that may transfer data internationally, including between Outerlimit Group Limited and Outerlimit Inc. Where data leaves the UK or EEA, we rely on a lawful transfer mechanism, such as:

  • an adequacy regulation, including, where applicable, the UK Extension to the EU–US Data Privacy Framework (the “UK–US Data Bridge”) for transfers to certified US recipients;
  • the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses with the UK Addendum, supplemented where necessary by additional safeguards such as encryption; or
  • another mechanism permitted under Articles 46–49 of the UK/EU GDPR.

You can request a copy of the relevant transfer safeguard by contacting us using the details in section 12.

9. How Long We Keep Your Data

We keep personal data only for as long as we need it for the purposes above, then securely delete or anonymise it. Indicative periods:

Data Retention period Basis
Enquiry / pre-contract data not proceeding to a relationship 12 months after last contact UK GDPR Art. 5(1)(e)
Marketing consent and opt-in / opt-out records Duration of consent plus 6 years PECR; UK GDPR Art. 7
Unsuccessful recruitment applications 6 months after the decision, unless you consent to longer ICO guidance
Website / system logs 12 months, unless an investigation requires longer UK GDPR Art. 5(1)(e)
Records of privacy rights requests 3 years from resolution UK GDPR Arts. 15–22

10. How We Protect Your Data

We apply appropriate technical and organisational measures, including encryption of data in transit (TLS) and at rest (AES-256), access controls and multi-factor authentication, logging and monitoring, and a documented incident-response process. Our security programme is aligned with ISO/IEC 27001, SOC 2 and Cyber Essentials / Cyber Essentials Plus.

11. Your Rights

Subject to applicable law and certain exceptions, you have the following rights.

Under UK/EU GDPR Under US state privacy laws, where you reside in a covered state
Access a copy of your data; rectification of inaccurate data; erasure; restriction of processing; data portability; objection to processing; and rights relating to automated decision-making. Right to know / access; right to correct; right to delete; right to opt out of the sale or sharing of personal information—we do not sell personal information; right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising your rights.

Some rights are not absolute and may be subject to exceptions - for example where we are required to keep data by law or for the establishment, exercise or defence of legal claims. Where a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse it, as permitted by law. You may use an authorised agent under applicable US state law; we may verify the agent’s authority and your identity.

12. Children

Our website and services are directed at businesses and are not intended for children. We do not knowingly collect personal data from children under 16 (UK) or under 13 (US, COPPA). If you believe a child has provided us with personal data, please contact us and we will delete it.

13. Automated Decision-Making and AI

We do not make decisions producing legal or similarly significant effects about website visitors using solely automated processing. Where AI tools are used in connection with our website or communications, they are governed by our AI Governance & Ethics Policy and applicable data-protection requirements, including data protection by design and default.

14. Third-Party Links

Our website may link to third-party sites we do not control. This notice does not apply to those sites; please review their own privacy notices.

15. How to Exercise Your Rights and Contact Us

To exercise any right, ask a question, or raise a concern, contact our privacy team:

  • Email: privacy@outerlimit.com
  • Post (UK): Privacy Team, 50 York Way, London N1 9AB, United Kingdom.
  • Post (US): Privacy Team, Outerlimit Inc. 135 Madison Ave Suite 06-118, New York, NY 10016, United States.

We will respond within the time limits required by applicable law - within one month under the UK/EU GDPR, and generally within 45 days under US state privacy laws (extendable where permitted). We may need to verify your identity before responding.

16. Complaints

We would prefer the chance to address any concern first. If you remain unsatisfied, you may complain to the relevant regulator:

  • UK - the Information Commissioner’s Office (ICO), www.ico.org.uk, 0303 123 1113.
  • EEA - your local data protection supervisory authority.
  • US - your state Attorney General’s office, or the relevant state privacy agency (e.g. the California Privacy Protection Agency).

17. Changes to This Notice

We review this notice at least annually and update it where the law, our processing, or our website changes. The “Last Updated” date at the bottom of the page shows when it was last revised.

Last Updated: 10/09/2026
Accelerate your Agentic AI
request a demo
Outerlimit is extending Zero Trust to the agent action layer, binding identity, authorization, and action into a single operation at the moment of tool execution. Meeting Enterprise customers where they are today, Outerlimit guides organizations from discovery and observability to deterministic enforcement.
Follow us on LinkedIn
Platform
Discover Observe Enforce Optimize [Coming Soon]
Company
Contact
Partners
GTM PartnersIntegration PartnersMarketplace PartnersBecome a Partner
Use Cases
Discovery of Agents and ToolsVisibility and Baseline Control over AISecuring the Synthetic Workforce
Resources
BlogSolutions & WhitepapersSecurity & ComplianceGlossary
© 2026 Outerlimit Ltd
Privacy NoticeTerms of Use