Skip to content

Privacy Policy

← ratatouille.dev

Last updated: August 2026.

Ratatouille is operated by [TODO: legal entity name] (“Ratatouille”, “we”). This policy covers ratatouille.dev, the hosted console, the demo core, and the Ratatouille agent and CLI.

We collect the minimum needed to tell you whether your machines are in the state you approved. We do not collect the contents of your files, your data, or your users’ data. We do not sell anything to anyone, and we do not run advertising or third-party analytics trackers on this site.

When you enroll a machine in the managed service, the agent transmits:

  • Device identity — the machine’s Ratatouille UUID, hostname, and the TPM’s Attestation Identity Key public key and Endorsement Key certificate.
  • TPM quotes — signed PCR values (including PCR 7 and PCR 10) and the nonce for each attestation cycle.
  • IMA measurement log entries — the path and SHA-256 hash of each executable, kernel module, and shared library measured since the last cycle. This reveals what software runs on the machine and where it lives on disk. It does not include file contents, user data, or anything the kernel did not measure.
  • Attestation verdicts — TRUSTED/FAILED status, timestamp, and which policy version was checked against.

The agent makes outbound HTTPS connections only and never accepts inbound connections. See the architecture notes.

Self-hosted deployments send us none of this. If you run your own registrar, verifier, and Core, attestation data never leaves your infrastructure.

  • Email address and authentication identity for console access.
  • Any email you send us, kept as long as it is useful to the conversation.
  • If you connect a repository, the Ratatouille GitHub App reads the policy files and Sigstore bundles from it. We read; we never write to your repository. We do not read source code outside the policy paths the App is scoped to.
ProviderWhat it handles
VercelWebsite hosting and request logs
Google Cloud PlatformHosted Core, verifier, registrar, and attestation database
CloudsmithPackage distribution (download requests and IP addresses)
GitHubPolicy repository access via the Ratatouille GitHub App
Sigstore / RekorPolicy signing. Note: Rekor is a public, permanent transparency log. The identity you sign a policy with, and the fact of the signature, become public and cannot be deleted. This is intentional and is how signature attribution works.

This site loads Google Fonts, which means Google receives the requesting IP address. There is no analytics script, no advertising pixel, and no cross-site tracker. [TODO: update this section if you add analytics.]

Attestation records are retained for the life of your account plus [TODO: retention window — 12 months is a common default and works for CJIS/audit evidence], because the value of the record is that it is a continuous history. You can request export or deletion at any time. On account closure we delete attestation data within 30 days, except where a customer contract or legal obligation requires longer.

Rekor entries cannot be deleted by us or by anyone else.

Email logan@ratatouille.dev to access, export, correct, or delete your data. We will respond within 30 days. If you are in the EEA or UK, GDPR rights apply; if you are in California, CCPA rights apply — the same address handles both.

We will require valid legal process, will narrow overbroad requests, and will notify you unless legally prohibited from doing so.

Report a suspected vulnerability to logan@ratatouille.dev and we will respond directly.

Material changes will be announced by email to account holders before they take effect, and the date at the top of this page will change.

Questions: logan@ratatouille.dev.