Privacy and data handling
Do not send real customer or employee email until your organization has approved the applicable legal basis, data processing terms, retention configuration, regions, subprocessors, and operational controls.
Your responsibilities
- Confirm you are authorized to submit the message and attachments.
- Minimize unnecessary personal data before capture when that does not compromise analysis.
- Define who can submit messages and read results.
- Keep development, test, and production credentials and data separate.
- Apply your own retention, deletion, audit, and incident-response policies.
Hermes public response
The v1 response is minimized to identifiers, bounded classifications, signal codes, warnings, and timestamps. It does not return the original message, extracted content, tenant IDs, internal scores, prompts, or model output.
Information not published by this portal
This portal does not claim a universal retention period, processing region, subprocessor list, deletion timeline, or contractual service level. Those terms can vary by approved deployment and agreement.
Before production use, request current privacy, retention, security, and contractual information from info@phishinghermes.com.
The technical documentation can be reviewed before these disclosures are finalized, but this page must not be treated as approval for public production use.