Privacy Policy
Last updated: August 18, 2026Salus Solutions, Inc. ("Salus", "we", "us") provides a Clery Act and campus safety compliance platform to colleges, universities, and public safety departments. This policy explains what information we collect, how we use and protect it, and the choices available to you.
1. Our Role and Scope
Most of the information in Salus does not come from you directly. It comes from the institutions that use our platform, who send us incident records and related data so that we can help them meet their compliance obligations. Our role differs depending on the type of information involved.
- Institutional data. When an institution uses Salus to process incident reports, campus security authority rosters, travel records, and similar material, the institution determines what is collected and why. We act as a service provider and processor on that institution's behalf and handle the data only as instructed under our agreement with them. For education records, we act as a school official with a legitimate educational interest under the Family Educational Rights and Privacy Act.
- Account and website data. When you create a Salus account, contact us, or visit our website, we handle that information as the controller, and this policy governs it directly.
If you are a student, employee, or other individual whose information appears in an institution's records, please direct privacy requests to that institution. We will support them in responding.
2. Information We Collect
Information you provide directly
- Account information, including name, work email address, job title, department, and either a password stored in hashed form or an identifier from your institution's single sign-on provider
- Communications with us, including support requests, feedback, and correspondence
- Billing and contract contact information for institutional customers
Institutional data processed on our customers' behalf
- Incident records ingested from a customer's records management system, student conduct system, computer aided dispatch, report forms, or email, including case numbers, dates, locations, narratives, dispositions, and attached documents or evidence files
- Personal information contained within those records, which may include names, contact details, affiliation, and descriptive details about reporting parties, involved parties, and responding personnel, as written by the reporting institution
- Campus security authority rosters, including names, work contact details, department, designation status, training completion, and attestations
- Institutional travel records used for law enforcement outreach, including destinations, dates, and organizing departments
- Correspondence with municipal and other law enforcement agencies conducted through the platform, and the responses received
- Campus geography and property records
Customers choose which fields are ingested during implementation and may exclude categories of data from processing.
Information collected automatically
- Device and connection information, including IP address, browser type, and operating system
- Usage and audit information, including pages visited, features used, and a record of actions taken in the platform such as creating, editing, approving, publishing, or exporting a record
- Log data, including error reports and performance metrics
- Cookies and similar technologies, as described in Section 10
3. How We Use Information
We use information to:
- Provide the platform, including incident classification, crime log preparation, statistical compilation, campus security authority management, training delivery, and law enforcement outreach
- Maintain the audit trail that our customers rely on to demonstrate compliance, including who took which action and when
- Authenticate users, enforce role based access, and secure the platform against unauthorized access, fraud, and abuse
- Send transactional and service messages, including notifications about records requiring review
- Provide support, diagnose problems, and improve the reliability and performance of the platform
- Meet our legal, contractual, and regulatory obligations
We do not sell personal information, we do not share it for cross context behavioral advertising, and we do not use institutional data for advertising of any kind.
4. AI Processing
Salus uses artificial intelligence to analyze incident records against Clery Act criteria and to assist with related tasks such as identifying potential duplicate reports and drafting documents for human review.
- Where processing happens. All AI inference runs through Amazon Bedrock within our own Amazon Web Services environment in United States regions. We do not send institutional data to consumer AI products.
- No training on customer data. Institutional data is never used to train or fine tune the underlying foundation models, and it is not used to build a model shared with other customers.
- Human decision making. AI output is advisory. Classifications, publication to a public crime log, timely warning decisions, and similar determinations are made and recorded by authorized institutional personnel. Salus does not make disciplinary, criminal, or other consequential decisions about individuals.
- Institution specific context. When a customer's staff approve or adjust a determination, that guidance may be stored as configuration scoped to that customer's environment and applied to their future analysis only. It is stored as data, not as model weights, and administrators can review, edit, or remove it.
- Transparency. Each analysis records the reasoning and the facts relied upon so that a reviewer can evaluate it.
5. How We Share Information
We share information only as needed to operate the platform, and each provider below is bound by contractual confidentiality and data protection obligations.
- Amazon Web Services. Cloud hosting, storage, key management, and AI inference through Amazon Bedrock, in United States regions.
- Email delivery providers. Amazon Simple Email Service and Resend, used to send platform notifications and outreach correspondence and to process email sent to platform mailboxes.
- Google Maps Platform. Geocoding of location descriptions to determine whether an incident falls within a customer's Clery geography.
- PostHog. Product analytics and error monitoring for our web application.
- Payment processing. If a customer pays by card, a third party payment processor handles the transaction. We do not store full payment card numbers.
We may also disclose information when required by law, subpoena, or valid legal process, to protect the rights, safety, or property of Salus or others, or in connection with a merger, acquisition, or sale of assets, in which case the acquiring party remains bound by this policy. We will notify the affected institution of a legal demand for their data unless prohibited from doing so.
A current list of subprocessors is available on request as part of a security review.
6. Data Security
Salus has completed a SOC 2 Type I examination and undergoes independent penetration testing. Our controls include:
- Encryption in transit using TLS 1.2 or higher
- Encryption at rest using AES-256
- Logical tenant isolation, with row level controls so that an institution's data is accessible only to that institution's authorized members
- Role based access control, multi factor authentication, and least privilege access for our own personnel
- Field level access restrictions and redaction capabilities for sensitive record types
- Immutable audit logging of access and changes
- Continuous monitoring, vulnerability scanning, and a documented incident response plan
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affecting personal information occurs, we will notify affected institutions and comply with applicable breach notification laws.
7. Data Retention and Deletion
We retain institutional data for as long as the customer's agreement requires. Because Clery Act records must generally be kept for seven years, retention periods are typically set to meet that obligation and any longer period the institution specifies.
Account information is retained while an account is active. Logs and audit records are retained for the period needed to support security and compliance review.
At the end of a customer agreement, data is made available for export and is then deleted from our systems and backups according to documented procedures, unless retention is required by law.
8. Your Rights and Choices
If your information appears in records an institution processes through Salus, your rights run through that institution, which controls the records. We will assist our customers in responding to access, correction, and deletion requests.
For information we hold directly, including your Salus account and website interactions, you may:
- Request access to, correction of, or deletion of your information
- Update your account details and notification preferences
- Opt out of non essential email by using the unsubscribe link
- Control cookies through your browser settings
Contact us at privacy@trysalus.com to exercise these rights. We will not discriminate against you for doing so.
9. State Privacy Rights
Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, and other states with comprehensive privacy laws may have additional rights, including the right to know what personal information is collected, to request deletion or correction, to obtain a portable copy, and to opt out of sale, targeted advertising, or certain profiling.
We do not sell personal information and do not share it for cross context behavioral advertising, including as those terms are defined under the California Consumer Privacy Act and under Nevada law. With respect to institutional data, we act as a service provider or processor and use that data only to perform services for the institution.
To submit a request, contact us at privacy@trysalus.com. We will verify your identity before responding and will respond within the period required by applicable law. You may designate an authorized agent to submit a request on your behalf.
10. Cookies and Tracking Technologies
We use cookies and similar technologies that are necessary to operate the platform, including maintaining your authenticated session and remembering preferences. We also use first party product analytics to understand how the application is used and to detect errors.
We do not use advertising cookies or third party advertising pixels. You can block or delete cookies in your browser, although the platform may not function correctly without essential cookies.
Because there is no common industry standard for interpreting them, we do not currently respond to Do Not Track browser signals.
11. Student Records and Children's Privacy
Records processed through Salus may include education records governed by the Family Educational Rights and Privacy Act. We handle those records as a school official acting under the institution's direct control, use them only for the purposes the institution authorizes, and do not redisclose them except as the institution directs or the law requires.
Our website and platform are intended for institutional staff and are not directed to children. We do not knowingly collect personal information directly from children under 13. Incident records supplied by an institution may contain information about individuals under 18, and we process that information solely on the institution's instructions.
12. Changes to This Policy
We may update this policy from time to time. When we do, we will revise the date at the top of this page, and for material changes we will provide notice to institutional customers in advance. Continued use of the platform after an update constitutes acceptance of the revised policy.
13. Contact Us
Questions about this policy, or requests relating to your information, can be sent to:
Salus Solutions, Inc.
New York, New York, United States
privacy@trysalus.com
Institutional customers may also raise privacy questions through their implementation or support contact, and security related questions can be directed to security@trysalus.com.