Skip to content
🔒 Privacy

DLP Privacy Notice

What the AstraLink DLP endpoint agent and browser extension collect, what never leaves the device, and how employer-managed data is handled.

6 min read
v1.0
Updated July 27, 2026

Scope

This notice covers AstraLink DLP, our data-loss-prevention offering for employer-managed computers. It consists of two components installed by an organization (the “employer”) on devices it owns or manages:

  • the AstraLink DLP endpoint agent, a program installed on the computer; and
  • the AstraLink DLP browser extension, installed into managed browsers.

It supplements our general Privacy Policy, which continues to govern our website and network security services. Where the two differ for the DLP offering, this notice controls.

AstraLink DLP is developed and maintained by SKS Solutions LLC, an affiliated company under majority-common ownership with AstraLink Connect, LLC. AstraLink Connect, LLC is the entity your organization contracts with and the provider of the service; macOS installer packages are code-signed by SKS Solutions LLC.

The browser extension does not transmit data off your device

This is the most important fact in this notice, so it comes first.

The AstraLink DLP browser extension makes no network requests and sends no data to AstraLink, SKS Solutions, or any other remote server. Its only communication channel is native messaging to the AstraLink DLP agent installed on the same computer. It contains no analytics, no telemetry, no advertising or tracking code, and loads no remote code.

What the extension does, entirely locally:

  • tells the local agent which site is active in the browser, so the employer’s policy can be applied to the correct destination;
  • reports to the local agent that a paste occurred on a policy-scoped site — without the pasted content;
  • when a file is selected for upload to a policy-scoped site, passes the file to the local agent so it can be scanned on the device.

Its browser permissions exist solely for these functions: nativeMessaging (the local channel to the agent), tabs and webNavigation (identify the active site), scripting (detect paste and upload events on policy-scoped pages), alarms (keep the local connection alive), and broad host permissions (because the employer’s monitored destinations are configured at runtime, not known when the extension is built).

Roles: your employer is the data controller

AstraLink DLP is deployed by employers on devices they manage, to enforce their own data-handling policies. In privacy-law terms, the employer is the data controller — it decides which destinations are monitored, which categories of sensitive data are enforced, and how strictly. AstraLink Connect, LLC processes data on the employer’s behalf and instructions. SKS Solutions LLC acts as an affiliated development and support entity under the same obligations.

If you are an employee using a device with AstraLink DLP installed, questions about why it is deployed, what your organization’s policy covers, and your rights regarding the data it produces should be directed to your employer, who controls that data. We act on the employer’s instructions and do not use employee data for our own purposes.

What is processed only on the device

Policy enforcement happens on the endpoint. The following are processed in memory, on the device, and are not transmitted to us:

  • Clipboard contents. Text you copy or paste is scanned locally to detect sensitive-data categories. The text itself is never sent to our servers.
  • File contents. Files selected for upload to monitored destinations are read and scanned locally, including local text extraction and optical character recognition. File contents are never sent to our servers. Where policy calls for redaction, a sanitized copy is produced on the device.
  • Keyboard input. On macOS, the agent uses the Input Monitoring permission to detect the paste keyboard shortcut (⌘V) so enforcement happens at the moment of pasting. It detects that shortcut only; it does not record, store, or transmit keystrokes. It is not a keylogger.
  • Screen and page content. The agent does not capture screenshots and the extension does not read or transmit page contents. Browsing history is not collected; the active site is used on-device for policy decisions.

What is reported to the employer’s dashboard

When a policy-relevant event occurs (for example, sensitive data was detected in a paste to a monitored AI service and was redacted), the agent records an event describing the event, not the content, and reports it to the employer’s tenant in our fleet service. An event contains:

  • timestamp, and the sensor and moment that produced it (copy, paste, upload, submit);
  • the category of data detected (e.g. “social security number”, “credit card”), the action taken (logged, redacted, blocked, allowed), a confidence score, and the policy rule that applied — never the matched text itself;
  • the destination involved: an application identifier (such as a macOS bundle ID) or a website hostname;
  • for file uploads: the file’s name, size, type, and a cryptographic hash (SHA-256) of its content — not the content;
  • device identifier and enrolled employee identifier, so the employer can attribute the event;
  • policy and configuration version stamps, and integrity-chain fields that make the log tamper-evident.

The agent also reports operational records: agent start/stop and health, sensor status, policy changes, and enrollment. At enrollment the device reports basic inventory — operating system version, hardware model, and network hardware (MAC) address — bound to the employee the employer issued the enrollment token for.

We do not sell any of this data, use it for advertising, or use it to train machine-learning models. It is available to the employer’s authorized administrators and to our personnel only as needed to operate and support the service.

Retention and deletion

Event and audit records are retained under the employer’s configuration and its agreement with us, and are deleted or returned at the end of the engagement in accordance with that agreement. Employees seeking correction or deletion should contact their employer; we will act on the employer’s verified instructions.

Security

Data in transit between the agent and our service is encrypted using TLS. Devices are enrolled with single-use, employee-bound tokens and authenticate with device-bound credentials created at enrollment. Access to tenant data is restricted per-tenant and logged.

Changes to this notice

We will update this notice as the DLP offering evolves and revise the “last updated” date above. Material changes will be communicated to contracting organizations directly.

Contact

Questions about this notice: legal@astralinkconnect.com. Questions about your organization’s monitoring policy: your employer’s IT or compliance team.