sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

On this page

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

RiskMandate — privacy: what this site collects, and how to check

riskmandate.ai runs no analytics, sets no cookies, loads nothing from a third-party CDN and has no account to create. This page says what happens when you read it, when you write to us and when you buy, and what we never ask for.

Source: https://riskmandate.ai/privacy.html↗


What this site collects, and how to check.

Nothing on riskmandate.ai is measured, tracked or stored about you. There is no analytics, no tag manager, no advertising pixel and no cookie set by this site. That is a claim you do not have to take on trust: every page is plain HTML in a public repository ↗, and your browser’s network tab is the audit.

No analytics, no cookies, and one thing in your browser.

The site is static files. It runs no server of its own, holds no database, and has no account to create.

WhatWhether this site does it
Analytics, product analytics or a tag managerNone. No Google Analytics, no Plausible, no Segment, no pixel of any kind.
Cookies set by this siteNone. Nothing on this site writes a cookie.
Browser storageOne key. The behaviour-policy pages remember how wide you dragged the side panel, under rm-abp-panel-w. It stays in your browser, it is a number, and clearing site data removes it.
Fonts and scripts from somebody else’s serverNone. The typeface is served from this site, and every script is inline in the page it belongs to.
An account, a sign-up or a newsletterNone. There is nothing to create and no list to join.
Forms that post to a serverNone. The one form on the site, on which behaviour policy next↗, opens your own mail client with the text in it. You decide whether to send it, and it goes to us as an ordinary email.

Two things do happen that are not ours, and it would be dishonest to leave them out. The site is hosted on GitHub Pages, so GitHub’s servers see the ordinary request information any web server sees, including your IP address, and handle it under GitHub’s privacy statement ↗. We have no analytics dashboard, no log access and no way to see who read what. And a page that embeds a live vault — the demos, and the reading app on a behaviour-policy page — loads that vault from vault.sgraph.ai, so opening those pages contacts SGraph the way opening any embedded page contacts its host. Everything in the vault is decrypted in your browser.

An email is an email, and a person reads it.

The cart is not ours, and neither is your card.

Payment happens at store.sgit.ai↗ on the payment provider’s own pages. This site never takes a payment, never sees a card number, and issues no order reference. The boundary between the two sites↗ is published.

Ask what we hold. It is a short answer.

If you have never written to us and never bought anything, the answer is nothing at all: there is no profile, no identifier and no record of your visit anywhere we can reach. If you have, write to dinis.cruz@owasp.org and ask for a copy of it, a correction to it, or its deletion. UK and EU readers have those rights in law and you do not need to cite the law to use them here.

RiskMandate is operated from London, United Kingdom. This page is written by the people who run the site rather than by a solicitor, and it describes what the site actually does rather than what a template says a site might do. If something here is wrong, tell us: it will be corrected on the page with a dated note, which is how every other correction on this site is handled. Last reviewed 24 September 2026.

A claim you can check beats a claim you must believe.

Every page here is in a public repository, every published policy has its read key printed, and this page tells you what to look for in your own browser. That is the whole method, applied to ourselves.